I&T GRC Information Security Specialist

dssmith· IP Polska
Apply Now ↗
📍 KrakowFull time

About this role

Location – Krakow

Why is this job for you:

The I&T GRC function supports the CISO and IT leadership across a range of information security, cybersecurity and technology risk controls, in support of IT, business, regulatory and customer requirements.


Reporting to the Head of I&T GRC or direct report thereof, the role provides internal information security control consultancy and assessment, supports business and IT stakeholder third party risk management arrangements and operates agreed I&T GRC operated processes or controls.

You will:

  • Support creation information and cybersecurity documentation (standards, processes, or guidance) in support of certification and compliance goals in the context of external certification and regulatory compliance requirements (e.g., ISO27001 and EU NIS2 implementation)

  • Own or support assigned agreed information security controls operated by I&T GRC e.g., aspects of information security management, risk process management, training and awareness in collaboration with wider team, support desktop simulations

  • Respond to customer security assurance requirements, and supplier security schedule / assurance

You have:

  • Good working knowledge of recognised information and cybersecurity domains, and standards such as the NIST CSF, ISO27001 or similar

  • Experience in:

  • delivering and working within frameworks such as ISO27001, NIST CSF or similar

  • information security controls design and documentation, assessment and/or assurance

  • information security customer questionnaires, supplier assurance and third-party risk management

  • facilitating risk and control processes, or cyber scenario desktop simulations

  • planning and delivering information security awareness campaigns

  • Working knowledge /  practical experience of GRC platforms and/or use of Microsoft tooling, training and awareness or simulated phishing tools

  • Strong analytical and problem-solving skills

  • Effective time management skills and ability to plan against multiple competing demands

  • Ability to build effective working relationships across technology and business stakeholders providing GRC advice and support

  • Ability to communicate IT, information security or cybersecurity concepts to non-IT stakeholders.  

  • Professional or academic qualification in relevant subject e.g., Computer Science, Information Security and/or goals to work toward certifications such as ISO27001 lead, ISC2 certifications, CISM, CRISC would be advantageous

  • Fluency in English

  • The role may include occasional planned travel (‘on-site’ visits) to DS Smith sites (international) in support of the business engagement outlined.  Ability to travel up to 20%

Frequently Asked Questions

Is the salary disclosed for the I&T GRC Information Security Specialist position at dssmith?
The salary for this I&T GRC Information Security Specialist role at dssmith is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the I&T GRC Information Security Specialist position at dssmith located?
This I&T GRC Information Security Specialist role at dssmith is based in Krakow. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the I&T GRC Information Security Specialist role at dssmith full-time or part-time?
This is listed as a Full time position. It is posted as a I&T GRC Information Security Specialist role in the IP Polska department at dssmith.
Which team or department does the I&T GRC Information Security Specialist at dssmith belong to?
This I&T GRC Information Security Specialist position is part of the IP Polska department at dssmith. See the full job description for more information about the team structure and responsibilities.
How do I apply for the I&T GRC Information Security Specialist position at dssmith?
Click the "Apply Now" button on this page. You will be redirected to dssmith's official application portal hosted on workday where you can submit your application directly.
When was the I&T GRC Information Security Specialist job at dssmith posted?
This I&T GRC Information Security Specialist position at dssmith was posted on Aug 31, 2026. Apply as soon as possible — early applications are often reviewed first.
I&T GRC Information Security Specialist
dssmith
Apply for this role ↗

You'll be redirected to dssmith's official application page on Workday.