Digital & Technology Team (D&T) is an integral division of HEINEKEN Business Services Poland. We are committed to making Heineken the most connected brewery by digitalizing and integrating processes, ensuring best-in-class technology, and embedding a data-driven culture.
The Cybersecurity Chapter in the D&T Support Functions department is a cross-functional security enablement team that helps D&T Support Functions Product Teams build, operate, and maintain secure and compliant platforms through security governance, risk management, standardization, awareness, and operational assurance.
Technology Specialist – Security will operate as a member of the D&T Support Functions Cybersecurity Chapter, support the D&T Procurement team, and work closely with architects, technical specialists, suppliers, TS&O Global Information Security partners, Global P&CI, and Global Audit to ensure Security by Design principles are applied.
Responsibilities
- Coordinate D&T Procurement domain product security activities in accordance with the HEINEKEN Cybersecurity Policy and Security by Design principles.
- Support D&T domain product functional and technical streams in performing work in accordance with the HEINEKEN Cybersecurity Policy.
- Oversee IT control activities to keep Procurement systems secure and compliant with the HEINEKEN Security Standard, and report them to D&T stakeholders.
- Manage Central IT Audits and Security Control Effectiveness Assessments.
- Drive remediation and mitigation activities based on audit, assessment, and control findings.
- Ensure D&T Support Functions Procurement follows the security roadmap defined by the TS&O Global Information Security team.
- Ensure operational user management and monitoring across D&T Procurement systems, including access-role mapping, user and role attestations, and segregation-of-duties reviews.
- Challenge D&T and business stakeholders at technical and functional levels in cases of potential security breaches.
- Escalate imminent or actual security breaches to D&T management.
- Align with global security governance bodies, Global Audit, P&CI, and external auditors on security governance, ownership, and assurance topics.
- Translate general security requirements into practical Procurement-level solutions.
Requirements
- Bachelor’s or master’s degree in business information technology or a related field.
- Relevant security knowledge and certifications, such as CISSP, CCSP, CISM, CISA, CRISC, ISO 27001, or COBIT 5.
- At least 5 years of experience in IT security.
- Experience with IT suppliers and vendor management, including teamwork coordination.
- Strong stakeholder management, relationship-building, and reporting skills.
- Ability to translate technical security concepts into business-related terms.
- Practical experience with GRC, IAM, and SIEM solutions.
- Functional knowledge of Procurement business processes and their relationship with application security.
- Knowledge of the NIST Cybersecurity Framework and its application to application security.
- Experience working with auditors and knowledge of audit procedures, phases, techniques, and risk management.
- Excellent consulting and communication skills across varied stakeholder levels.
- Strong software and landscape architecture skills.
- Fluent English.
At HEINEKEN Kraków, integrity and ethical conduct are taken seriously. Concerns about possible violations of legal regulations or the Code of Business Conduct can be reported through the available global or local channels.
This role allows you to apply 50% copyright tax-deductible costs up to 80% of your tasks.