Skús vyladenú mobilnú aplikáciu

rating

Information Security Officer

Len pár hodín

SYNOT Games SK s. r. o.

Kalinčiakova, Bratislava, Slovakia

Vzdialenosť od teba uvidíš po zadaní adresy vo výpise ponúk.


Plat

od 2 500 € hrubého

Úväzok

Práca na plný úväzok

Vzdelanie

Vysokoškolské II. stupňa

Jazyky

Angličtina (Pokročilá), Slovenčina (Výborná)

Zaradené

Informačné technológie, Špecialista IT bezpečnosti


O pozícii

Náplň práce, právomoci a zodpovednosti:

We are looking for a Security Officer to own security governance, standards, and risk management across SYNOT Games. In this role, you help ensure that our systems, infrastructure, data, and operations are protected against security threats in line with our ISO/IEC 27001-certified ISMS, and applicable regulatory obligations across the markets we operate in.

Responsibilities

  • Define and maintain security policies and standards company-wide, monitor adherence and report security posture to management.

  • Set information security goals and objectives and drive continuous improvement of security posture against them - plan the improvements, measure progress and report to management.

  • Own ISMS / ISO 27001 governance and audit evidence; commission the pre-certification internal audit (with external auditor) and support the certification audit.

  • Own information security risk management and the security incident lifecycle.

  • Coordinate regulatory notification of security incidents and data breaches (MGA, UKGC, GDPR) with the DPO.

  • Provide security review and support for technology initiatives - new tools, platforms and use cases, including AI.

  • Define access control and RBAC standards - roles, privileged access, access reviews and segregation of duties - and audit compliance.

  • Define vulnerability severity classification, remediation SLAs, and monitor CVE closure across all systems.

  • Define penetration testing requirements, scope, and review findings and remediation.

  • Define security requirements for development - code review, security scanning and pipeline gates - and review compliance.

  • Own cryptographic control review and conformance decisions - key rotation, certificates, algorithm baselines and exceptions.

  • Define physical security standards for all offices - access zones, visitor management, CCTV and safes - and monitor compliance.

  • Define security awareness requirements and monitor completion and effectiveness.

Zamestnanecké výhody, benefity:

  • Flexible working hours

  • Hybrid work model

  • 2 extra vacation days

  • Informal and friendly working environment

  • Team buildings and company events

  • Fruit days

  • Discounts and additional benefits (SK, CZ)

  • Bike storage with showers ‍️

  • English language courses

  • MultiSport Card

  • Contribution to the 3rd Pillar (DDS)

  • Referral Bonus

Požiadavky na zamestnanca:

Candidate Requirements

  • At least 5 years in information security governance, ISMS operation or security risk management, preferably in a regulated, multi-jurisdiction environment.

  • Demonstrated ownership of an ISO/IEC 27001 ISMS through certification or surveillance audits - controls, evidence, internal audit and management review.

  • Track record in security incident management and vulnerability governance across both infrastructure and application estates.

  • Ability to hold an independent, single-incumbent mandate: set standards other teams must follow, make the risk call and stand behind it, without line-management authority.

  • Experience working with auditors, certification bodies and regulators; exposure to gaming regulators (MGA, UKGC) is an advantage.

  • Strong governance writing - policies, directives, standards and audit-ready evidence packs.

  • Comfortable in a distributed-execution model: define requirements and standards, then monitor and audit compliance by IT Ops, product delivery teams and HR.

Technical and Tool Experience

  • ISMS and risk-register tooling, control mapping and evidence management.

  • Access management and RBAC/PAM - identity providers, privileged access, access reviews and segregation of duties.

  • Vulnerability management and scanning tools, CVE triage and remediation tracking, penetration test findings.

Nice - to - have

  • Experience in online or land-based gaming, or another licensed and audited industry.

  • Familiarity with ISO 22301 business continuity and ICT disaster recovery exercising.

  • Experience collaborating with a DPO on DPIAs, records of processing and breach notification.

  • AI governance experience - tool and use-case assessment, data-leakage and confidentiality risk review.

  • Cryptographic controls - certificate lifecycle, key management and algorithm baselines.

Preferred Qualifications

  • Prior standalone or single-incumbent security officer / CISO-adjacent role reporting to C-level.

  • Experience presenting security posture and risk decisions to executive management or a board.

  • Internal audit experience or lead-auditor training.

  • Experience defining security requirements for third-party suppliers, integrations and APIs.

  • Experience governing physical security across multiple office locations.

Certifications or licenses

The following certifications (or similar qualifications) are beneficial for the successful candidate:

  • CISSP, CISM or CISA

  • ISO/IEC 27001 Lead Implementer or Lead Auditor

  • CRISC or an equivalent information risk certification

  • CEH, OSCP or comparable offensive-security qualification

  • CIPP/E or a comparable data-protection qualification

Alebo skús mobilnú apku

Uvidíš ponuky vo svojom okolí a všetky svoje odpovede budeš mať vždy poruke

Naskenuj kód

V Práci za rohom máš najväčšiu šancu nájsť si prácu blízko domova a prestať dochádzať. Vyberaj z voľných miest a brigád po celom Slovensku, napríklad v lokalitách Bratislava, Košice, Prešov, Žilina, Banská Bystrica, Nitra, Trnava, Trenčín a mnohých ďalších.

Používame cookies, pozri Podmienky služby. A tiež chránime tvoje osobné údaje, pozri Zásady ochrany súkromia. Viac o reklame na portáloch Alma Career a transparentnosti si môžete prečítať na našej Informačnej stránke. Tu je naša Technická špecifikácia.