Information Security Officer
Len pár hodín
SYNOT Games SK s. r. o.
Kalinčiakova, Bratislava, Slovakia
Vzdialenosť od teba uvidíš po zadaní adresy vo výpise ponúk.
Plat
od 2 500 € hrubého
Úväzok
Práca na plný úväzok
Vzdelanie
Vysokoškolské II. stupňa
Jazyky
Angličtina (Pokročilá), Slovenčina (Výborná)
Zaradené
Informačné technológie, Špecialista IT bezpečnosti
O pozícii
Náplň práce, právomoci a zodpovednosti:
We are looking for a Security Officer to own security governance, standards, and risk management across SYNOT Games. In this role, you help ensure that our systems, infrastructure, data, and operations are protected against security threats in line with our ISO/IEC 27001-certified ISMS, and applicable regulatory obligations across the markets we operate in.
Responsibilities
Define and maintain security policies and standards company-wide, monitor adherence and report security posture to management.
Set information security goals and objectives and drive continuous improvement of security posture against them - plan the improvements, measure progress and report to management.
Own ISMS / ISO 27001 governance and audit evidence; commission the pre-certification internal audit (with external auditor) and support the certification audit.
Own information security risk management and the security incident lifecycle.
Coordinate regulatory notification of security incidents and data breaches (MGA, UKGC, GDPR) with the DPO.
Provide security review and support for technology initiatives - new tools, platforms and use cases, including AI.
Define access control and RBAC standards - roles, privileged access, access reviews and segregation of duties - and audit compliance.
Define vulnerability severity classification, remediation SLAs, and monitor CVE closure across all systems.
Define penetration testing requirements, scope, and review findings and remediation.
Define security requirements for development - code review, security scanning and pipeline gates - and review compliance.
Own cryptographic control review and conformance decisions - key rotation, certificates, algorithm baselines and exceptions.
Define physical security standards for all offices - access zones, visitor management, CCTV and safes - and monitor compliance.
Define security awareness requirements and monitor completion and effectiveness.
Zamestnanecké výhody, benefity:
Flexible working hours
Hybrid work model
2 extra vacation days
Informal and friendly working environment
Team buildings and company events
Fruit days
Discounts and additional benefits (SK, CZ)
Bike storage with showers ️
English language courses
MultiSport Card
Contribution to the 3rd Pillar (DDS)
Referral Bonus
Požiadavky na zamestnanca:
Candidate Requirements
At least 5 years in information security governance, ISMS operation or security risk management, preferably in a regulated, multi-jurisdiction environment.
Demonstrated ownership of an ISO/IEC 27001 ISMS through certification or surveillance audits - controls, evidence, internal audit and management review.
Track record in security incident management and vulnerability governance across both infrastructure and application estates.
Ability to hold an independent, single-incumbent mandate: set standards other teams must follow, make the risk call and stand behind it, without line-management authority.
Experience working with auditors, certification bodies and regulators; exposure to gaming regulators (MGA, UKGC) is an advantage.
Strong governance writing - policies, directives, standards and audit-ready evidence packs.
Comfortable in a distributed-execution model: define requirements and standards, then monitor and audit compliance by IT Ops, product delivery teams and HR.
Technical and Tool Experience
ISMS and risk-register tooling, control mapping and evidence management.
Access management and RBAC/PAM - identity providers, privileged access, access reviews and segregation of duties.
Vulnerability management and scanning tools, CVE triage and remediation tracking, penetration test findings.
Nice - to - have
Experience in online or land-based gaming, or another licensed and audited industry.
Familiarity with ISO 22301 business continuity and ICT disaster recovery exercising.
Experience collaborating with a DPO on DPIAs, records of processing and breach notification.
AI governance experience - tool and use-case assessment, data-leakage and confidentiality risk review.
Cryptographic controls - certificate lifecycle, key management and algorithm baselines.
Preferred Qualifications
Prior standalone or single-incumbent security officer / CISO-adjacent role reporting to C-level.
Experience presenting security posture and risk decisions to executive management or a board.
Internal audit experience or lead-auditor training.
Experience defining security requirements for third-party suppliers, integrations and APIs.
Experience governing physical security across multiple office locations.
Certifications or licenses
The following certifications (or similar qualifications) are beneficial for the successful candidate:
CISSP, CISM or CISA
ISO/IEC 27001 Lead Implementer or Lead Auditor
CRISC or an equivalent information risk certification
CEH, OSCP or comparable offensive-security qualification
CIPP/E or a comparable data-protection qualification
Alebo skús mobilnú apku
Uvidíš ponuky vo svojom okolí a všetky svoje odpovede budeš mať vždy poruke
Naskenuj kód
V Práci za rohom máš najväčšiu šancu nájsť si prácu blízko domova a prestať dochádzať. Vyberaj z voľných miest a brigád po celom Slovensku, napríklad v lokalitách Bratislava, Košice, Prešov, Žilina, Banská Bystrica, Nitra, Trnava, Trenčín a mnohých ďalších.
Používame cookies, pozri Podmienky služby. A tiež chránime tvoje osobné údaje, pozri Zásady ochrany súkromia. Viac o reklame na portáloch Alma Career a transparentnosti si môžete prečítať na našej Informačnej stránke. Tu je naša Technická špecifikácia.