CrawlJobs Logo

Head of Information Security

Poland, Kraków · Job Posted March 05, 2026
Apply Position
Job Link Share

Job Description

The Head of Information Security is a senior technical leadership role. The role reports into the CISO and is accountable for the technical cybersecurity posture of the organization. Governance, Risk and Compliance (GRC) responsibilities are owned by a separate function. This role is accountable for how security is technically designed, implemented, and operated. The Head of Information Security leads all technical aspects of cybersecurity, including security architecture, engineering, operations, and incident response. The role ensures that security capabilities are effective, scalable, and resilient, supporting business and regulatory requirements through strong technical controls.

Job Responsibility

  • Own the enterprise security architecture across network, endpoint, cloud, identity, and application domains
  • Define technical security standards, reference architectures, and engineering patterns
  • Lead the selection, deployment, and lifecycle management of security platforms and tooling
  • Embed security-by-design into infrastructure, cloud, and application initiatives
  • Lead Security Operations (SOC / SecOps), including detection, response, and operational resilience
  • Own vulnerability management, threat intelligence, and security telemetry
  • Drive continuous improvement in detection, automation, and response effectiveness
  • Lead the Cybersecurity Incident Response Team (CIRT)
  • Act as technical incident commander during major security incidents
  • Own investigation, containment, eradication, and recovery activities
  • Provide senior technical leadership across IAM, cloud, infrastructure, endpoint, network, and application security
  • Translate technical risks into business-relevant impact for technology leadership
  • Partner with GRC to ensure technical controls support policy and compliance objectives
  • Lead and develop a global team of security engineers, architects, and operations professionals
  • Set technical direction, priorities, and engineering standards for the security organization

Requirements

  • Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Engineering, or related field
  • 5+ years of experience in technical cybersecurity roles
  • Proven experience leading enterprise-scale security engineering and operations teams

What we offer

  • Private healthcare including dental care
  • Life and long-term disability insurance
  • MyBenefit Cafeteria system
  • Multisport Card
  • Social Fund Subsidies
  • Home Office allowance
  • Tuition reimbursement
  • Referral awards
  • Internal career development opportunities in multiple business areas
  • Day off to celebrate your birthday
  • Up to 3 additional days of vacation by length of service in the company

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

Head of Information Security

8 matching positions

Head of Information Security

We’re looking for a Head of Information Security who can help turn that foundati...
Location
Location
Czechia , Prague; Brno; Ostrava
Salary
Salary:
115000.00 - 130000.00 CZK / Month
sportvision.cz Logo
Sport Vision Czechia s.r.o.
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Experience implementing and operating ISO 27001-based security practices (or similar frameworks) in real-world product or technology organizations
  • Strong understanding of modern product and engineering environments, including secure development practices, vulnerability management, and cloud-based services
  • Hands-on experience working with development teams on topics like dependency management, application security, penetration testing, and security tooling
  • Understanding of regulatory and compliance frameworks such as GDPR, NIS2, DORA, and how to translate them into practical operational controls
  • Experience building or improving ISMS and security governance models that support everyday development work — not just audits
  • Ability to create documentation that is clear, usable, and grounded in operational reality
  • Interest or experience in AI-assisted tooling, automation, and the security implications of AI-driven product development
  • Excellent communication skills — you can explain technical and security concepts clearly to both engineers and business stakeholders
  • Fluent English
Job Responsibility
Job Responsibility
  • Drive collaboration between security, product development, business, and compliance stakeholders
  • Lead the implementation and continuous improvement of our ISMS across the organization
  • Turn strategic goals into clear, actionable security plans
  • Build clear, usable security documentation and support customer security and compliance inquiries
  • Improve practical security capabilities across engineering and product development
  • Champion a "security by design" mindset
  • Translate regulatory and compliance requirements into practical operational controls
  • Lead and support our Information Security team while helping shape security capabilities across the organization
  • Report directly to the Technology Director and contribute as a member of the Technology Management Team
What we offer
What we offer
  • Salary range: 115 000 Kč - 130 000 CZK/month
  • Access to internal and external courses and conferences
  • Free access to Seduo
  • 5 weeks of vacation
  • Unlimited "Happy Days" — extra days off
  • Flexible working hours and home office
  • Mobile tariff with 100 GB of data
  • Mental health support through Hedepy
  • Multisport card contribution (250 CZK)
  • Support during long-term illness
  • Fulltime
Read More
Arrow Right

Head of Information Security

This is a strategic leadership role which is responsible for leading the transfo...
Location
Location
United Kingdom , Milton Keynes or London
Salary
Salary:
Not provided
triarecruitment.com Logo
TRIA
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Significant leadership experience in enterprise information and cyber security roles, ideally within complex or regulated environments
  • Proven success in leading strategic reviews and transformations of security toolsets, platforms, and operating models
  • Deep technical knowledge of security controls across hybrid cloud, infrastructure, endpoint, and user environments
  • Practical experience delivering cyber security best practices across network, infrastructure, BYOD, web, and cloud services
  • Strong working knowledge of governance and compliance frameworks including ISO 27001, NIST CSF, GDPR, and Cyber Essentials+
  • Demonstrable ability to communicate complex security concepts to non-technical audiences, including board-level stakeholders
Job Responsibility
Job Responsibility
  • Lead the transformation and modernisation of the cyber and information security capabilities
  • Shape and execute a security strategy that aligns with the companies' digital ambitions and evolving risk landscape
  • Lead a complete strategic review of the security landscape, including tools, processes, risk postures, and cultural readiness
  • Report to the board and advise on cyber risk, threats, and mitigation strategies
  • Translate security insights into executive-level communications, influencing investment and change roadmaps
  • Fulltime
Read More
Arrow Right

Head of Information Security, Risk and Compliance

Senior leadership position within the IT Operations team. The primary mission is...
Location
Location
United Kingdom , Thame
Salary
Salary:
110000.00 GBP / Year
travelodge.co.uk Logo
Travelodge Hotels Limited
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Certifications: CCSP, CISSP-ISSMP, or CISM
  • Methodologies: ITIL v4 Foundation
  • FAIR Risk Modelling
  • experience in Project Management or Business Change
  • Advanced Tech: Experience defining Zero Trust Architecture (ZTA) and implementing security controls within public cloud environments (IaaS/PaaS)
  • pragmatic, hands-on leader
  • master of communication
  • self-starter
  • technical expertise rooted in securing critical B2B and B2C eCommerce platforms, particularly within hosted and SaaS-heavy environments
  • expert-level knowledge of perimeter, cloud, network, and data security
Job Responsibility
Job Responsibility
  • Strategic Leadership: Develop a continuously evolving security roadmap and "defence in depth" strategy
  • manage both internal teams and strategic third-party partners
  • Operational Management: Oversee 24x7x365 security operations, including continuous monitoring, threat assessment, incident response (CIRT)
  • Risk & Compliance: Develop and maintain an industry-standard Risk Management framework
  • ensure compliance with PCI-DSS, GDPR, and NIST frameworks
  • Governance & Policy: Maintain Information Security policies and conduct regular audits of processes and controls
  • Technical Oversight: Coordinate vulnerability management, penetration testing, and code reviews
  • provide "Secure by Design" architectural guidance for all new initiatives
  • Supply Chain & Budget: Manage a portfolio of security vendors to ensure value and responsiveness
  • oversee the OPEX and CAPEX budgets that enable your function to operate and continuously improve
What we offer
What we offer
  • Annualise Bonus
  • Car Allowance
  • Contributory pension scheme
  • 50% personal discount for hotel bookings and great friends and family discounts too
  • 25 days holiday + bank holidays, increasing with length of service
  • A focus on learning and career development
  • Fulltime
Read More
Arrow Right

Head of Security Engineering

My client are looking for a senior security engineering leader to shape and scal...
Location
Location
Portugal , Lisbon
Salary
Salary:
100000.00 EUR / Year
signifytechnology.com Logo
Signify Technology
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years’ experience in security engineering or broader information security roles
  • Experience leading and developing technical security teams
  • Strong hands-on background in cloud security (AWS, Azure or GCP)
  • Solid understanding of identity and access management concepts and controls
  • Experience with detection, monitoring, or security operations tooling
  • Knowledge of modern infrastructure (containers, cloud-native environments)
  • Experience working closely with engineering and DevOps teams
  • Ability to design and implement scalable security solutions
  • Strong communication skills in English
Job Responsibility
Job Responsibility
  • Lead, mentor and grow a team of security engineers across multiple domains
  • Set priorities and drive delivery against a defined security engineering roadmap
  • Promote a culture of ownership, pragmatism, and continuous improvement
  • Partner with senior stakeholders to align security initiatives with business risk
  • Own and evolve the organisation’s security architecture and core tooling
  • Design secure, scalable solutions across cloud-native and hybrid environments
  • Evaluate and rationalise security technologies, ensuring effectiveness and simplicity
  • Contribute directly to technical problem-solving and key design decisions
  • Define and enforce security standards across cloud platforms and infrastructure
  • Support secure design of containerised and distributed systems
Read More
Arrow Right

Head of Security and Compliance

The Head of Security and Compliance will be responsible for building and leading...
Location
Location
United States
Salary
Salary:
Not provided
eightsleep.com Logo
Eight Sleep
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 8-10+ years of experience in security engineering, with deep expertise in mobile app security, IoT device security, or cloud infrastructure security
  • Proven expertise in cybersecurity, cloud infrastructure security (AWS), IoT device security, and corporate risk management
  • Experience in consumer technology, health tech, or regulated industries is highly desirable
  • Strong knowledge of compliance standards (SOC 2, ISO 27001, HIPAA, GDPR, etc.)
  • Excellent communication and stakeholder management skills
  • Ability to balance risk with business agility in a fast-paced startup environment
Job Responsibility
Job Responsibility
  • Oversight and implementation, operation and monitoring of information security tools and processes in customer production environments
  • Responsible for conducting IT risk assessments, documenting identified threats and maintaining risk register
  • Communicates information security risks to executive leadership
  • Reports information security risks annually to Eight Sleep leadership and gains approvals to bring risks to acceptable levels
  • Define and own Eight Sleep’s end-to-end security strategy across cloud, product, corporate, and customer environments
  • Serve as the primary security advisor to the executive team—translating risk into clear business decisions and helping set the company’s security posture and risk tolerance
  • Build and scale Eight Sleep’s security program, including roadmap, processes, metrics, and future team structure
  • Oversee security architecture and practices for software, cloud infrastructure, connected devices (IoT), and data storage
  • Ensure compliance with security frameworks (e.g., SOC 2, GDPR, HIPAA)
  • Lead vulnerability management, threat detection, and incident response
What we offer
What we offer
  • Equity participation
  • Periodic equity refreshments based on performance
  • Every Eight Sleep employee receives a Pod
  • Fulltime
Read More
Arrow Right

Head of Information Technology (Digital Workplace)

Digital Workplace's mission is to enable PPRO colleagues to do their best work b...
Location
Location
Germany , Munich
Salary
Salary:
Not provided
ppro.com Logo
PPRO GmbH
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Track record of designing and implementing an integrated digital workplace experience in a technology leadership role with both project and operational responsibilities
  • Experience in bringing product and software engineering best practices to the digital workplace (problem understanding, solution and system design, platform as code, etc.)
  • Experience in implementing and maintaining robust security controls in a user-friendly way, ensuring compliance and security awareness without hindering productivity
  • Strong collaboration skills to work with business leaders on all levels to understand requirements and translate them into technical capabilities
  • Excellent written and verbal communication skills
  • Experience leading globally distributed team members
  • Efficient budget management by making informed investment decisions that are aligned with the overall business budget and objectives
Job Responsibility
Job Responsibility
  • Work with stakeholders and the team to design the target digital workplace experience to maximise colleague productivity
  • Define the strategy to achieve the target experience, quantify success and clearly articulate areas for investment
  • Establish operational and project cycles within the team to deliver strategic results and support our colleagues around the world
  • Driving the technology culture to simplify and automate routine tasks and increase productivity
  • Work with external vendors and partners to enhance our colleague offering and ensure a seamless experience
  • Take ownership of security and compliance within the team and beyond, enabling colleagues to do their jobs efficiently and safely
What we offer
What we offer
  • Hybrid working with a 3 days / week on site expectation
  • 30-day holiday allowance
  • Work from abroad policy, enabling employees to work remotely for up to another 30 days per year
  • €1,000 annual learning and development budget
  • Leadership cafés, on-the-job training
  • Accident insurance, disability insurance, direct insurance (bAV) and travel insurance
  • Enhanced family leave
  • Gym membership contribution
  • Mental Health Platform access
  • Pet-friendly office
  • Fulltime
Read More
Arrow Right

Head of Security Governance, Risk & Compliance

We’re looking for a dynamic, experienced Head of GRC to lead our global governan...
Location
Location
Luxembourg , Luxembourg
Salary
Salary:
Not provided
ppro.com Logo
PPRO GmbH
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • A proven track record transforming traditional GRC frameworks (ISO27001, PCI DSS, SOC2) into modern, automated, developer-friendly control assurance programmes
  • Solid grounding in financial services regulation, payments, operational resilience, outsourcing/cloud guidelines etc.
  • Strong experience interacting with regulators and auditors (CSSF, FCA, etc.) and implementing regulatory requirements
  • Proven ability to run risk management processes, control frameworks and audit cycles
  • Experience evaluating technology, cyber and operational risks in a cloud-native environment
  • Engineering-first mindset, with an understanding of cloud-native architectures (AWS preferred) and how GRC requirements fit into engineering workflows
  • Experience with GRC tooling, workflow automation or process optimisation
  • Ability to translate regulatory requirements into practical, technical control expectations
  • Excellent communicator, capable of influencing executives, engineers, auditors and regulators
  • Pragmatic, commercially-minded, empathetic and customer-focused
Job Responsibility
Job Responsibility
  • Lead PPRO’s global Security GRC strategy and team, to support our international regulatory and compliance footprint
  • Oversee and enhance our ISO27001:2022 and PCI DSS v4.0 programmes, building a culture of continuous compliance through automation and control transformation
  • Partner with relevant functions to ensure ongoing DORA compliance, including security risk management, incident reporting, operational resilience testing and governance
  • Define and deliver a strategy for a pragmatic, high-value 2nd line automated control assurance programme, underpinned by relevant business metrics
  • Own and manage regulatory expectations on security topics by the CSSF in Luxembourg, FCA in the UK and other international bodies as relevant
  • Maintain and enhance PPRO’s security risk register, defining and delivering cross-organisation improvement and remediation roadmaps
  • Lead security control testing, issue management, KRI monitoring, SLA reporting and Board-level reporting
  • Act as Information Security Officer for PPRO’s local Luxembourg entity
  • Own third party security risk management and oversight for PPRO across the full procurement lifecycle
  • Partner closely with Engineering to build shared understanding and transform controls via thoughtful automation, streamlining evidence collection and control monitoring
What we offer
What we offer
  • Hybrid working with a 3 days / week on site expectation
  • Work from abroad policy, enabling employees to work remotely for up to another 30 days per year
  • €1,000 annual budget for professional growth
  • Leadership cafés, on-the-job training
  • Lunch Vouchers - 12,80euros x 18 / month
  • Enhanced family leave
  • Travel Insurance
  • Gym membership contribution
  • Mental Health Platform
  • Pet-friendly office
  • Fulltime
Read More
Arrow Right

Head of Cyber Security

Evaluate, test, recommend, develop, coordinate, monitor and maintain information...
Location
Location
Czech Republic , Praha
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven track record of shaping and executing cyber security strategy in a complex, multi-stakeholder environment, with clear linkage to business priorities
  • Strong grasp of current threat landscape and the ability to translate emerging risks into actionable business decisions and investments
  • Experience operating at senior leadership level, including regular interaction with executive committees and risk/audit bodies
  • Ability to drive security-by-design principles into products, services, and technology architecture—not just enforce controls post-delivery
  • Demonstrated ownership of cyber risk management frameworks, including defining risk appetite and ensuring transparent, decision-ready reporting
  • Hands-on experience with incident leadership in high-impact situations, including coordination across technical teams, business leadership, and external parties
  • Deep understanding of regulatory and certification environments, with practical experience maintaining compliance in a changing legal landscape
  • Strong judgement in balancing risk, cost, and operational impact—especially when priorities conflict or information is incomplete
  • Ability to simplify complex technical topics into clear, business-relevant narratives that influence decision-making
  • Experience building and evolving cyber defence capabilities, including standardisation across multiple markets or organisational units
Job Responsibility
Job Responsibility
  • Manage, motivate and develop Security teams, ensure people have clear priorities and direction. Influence and develop people and change behaviour. Inspire and create the right working climate. Ensure safety of crisis management team so that the company remains operational under all circumstances
  • Develop and implement mid-term Cyber Security strategy, cyber security baseline and align to local priorities
  • Manage Cyber Security Risk in line with Vodafone and Local Market tolerance. Lead a proactive spear of the business to advise and develop security solutions – secure by design products and services. Provide regular and transparent security risk reporting to the Technology leadership, Executive Committee and local audit risk committee
  • Within clearly defined company policies, principles and specific objectives and with understanding of local security laws and regulations deliver cyber security improvements and projects to ensure effective controls. Proactively manage and maintain local certifications
  • Manage local security incidents and event to minimise the impact to customers, services, data and people
  • Act as a positive and active member of the Vodafone Cyber Security Leadership Team and Technology Leadership team. Build strong and effective relationships with Corporate Security, local security authorities and key business stakeholders
  • Design and maintain cyber defence capability with the best synergies across EU7 markets. Establishing common processes, methodology, and ways of working in cyber defence domain
  • Perform other job-related duties or tasks defined by the supervisor or resulting from assigned agendas
What we offer
What we offer
  • Annual bonus
  • 5 weeks of vacation
  • 5 personal days
  • 16 weeks vacations for new parents
  • Mobile phone and unlimited tariff
  • 24 000 benefit points per year for vacations, educational courses, or cinema
  • uLékaře.cz service
  • Headquarters located at metro line with nearby amenities
  • Bike rental
  • Gym located in the building
Read More
Arrow Right