Overview

Head of Information Security Jobs in Poland at LT Harper Recruitment Group

Title: Head of Information Security

Company: LT Harper Recruitment Group

Location: Poland

*** ONLY FOR CANDIDATES BASED IN POLAND ***

Head of Information Security (CISO-level | Cloud | SOC 2 / ISO 27001 | Regulated Enterprise)

Poland | Full-time, embedded

Join a fast-growing global technology organisation building enterprise-grade infrastructure for demanding, highly regulated clients. This is a hands-on leadership role for someone who wants to own, mature, and operate a security programme day to day – not advise from the outside.

We are looking for a Poland-based security leader who has personally built or materially improved a security programme, can pass enterprise diligence, and speaks equally well to executives and engineers. This is a builder/operator role, not a fractional, advisory, or audit-only one.

Head of Information Security – Responsibilities:

  • Owning, maturing, and operating the enterprise information security programme end to end
  • Establishing security policies, standards, governance processes, control ownership, and evidence repositories
  • Leading risk assessments, audits, security reviews, remediation programmes, and management reporting
  • Owning security responses and supporting evidence for client diligence reviews, cyber assessments, and control validations
  • Maintaining audit-ready documentation supporting SOC 2, ISO 27001, and enterprise client reviews
  • Partnering with Engineering to embed security into cloud infrastructure, applications, APIs, and emerging technology initiatives
  • Owning identity and access management across employees, contractors, applications, and production systems (least privilege, MFA, PAM, access reviews, joiner/mover/leaver)
  • Establishing data-classification, retention, encryption, key-management, and data-loss-prevention controls
  • Owning secure SDLC requirements, security testing, penetration testing, and a risk-based vulnerability-management programme
  • Maintaining security monitoring, logging, alerting, endpoint protection, and threat detectio.
  • Maintaining incident-response procedures, tabletop exercises, business continuity, and disaster-recovery readiness
  • Owning third-party and vendor security oversight, due diligence, and ongoing monitoring

Head of Information Security – Requirements:

  • 10+ years of information security experience, including leadership responsibility for an enterprise security programme or function
  • Proven experience building and operating security programmes within regulated enterprise, SaaS, cloud, or financial-services technology environments
  • Strong working knowledge of SOC 2, ISO 27001, NIST CSF, CIS Controls, cloud-security frameworks, and third-party-risk assessment
  • Experience supporting SOC 2 Type II audits or equivalent independent assessments
  • Experience responding to enterprise-client security reviews, cyber assessments, and DDQs
  • Strong technical breadth across cloud security, network security, IAM/PAM, encryption, secure SDLC, vulnerability management, monitoring, incident response, resilience, and data protection
  • Ability to produce clear policies, remediation plans, security narratives, executive reporting, and audit-ready evidence
  • Excellent written and verbal English communication skills.

Head of Information Security – Tech Stack / Environment:

  • Cloud-native infrastructure, applications, and APIs
  • SOC 2, ISO 27001, NIST CSF, CIS Controls
  • IAM / PAM, encryption and key management, DLP
  • Secure SDLC, penetration testing, vulnerability management, security monitoring and threat detection

Head of Information Security – BONUS POINTS:

  • Prior experience as a CISO, Deputy CISO, or Head of Security
  • Familiarity with distributed systems, APIs, and AI/GenAI governance
  • Relevant certifications such as CISSP, CISM, CISA, CCSP, or CRISC (or equivalent practical experience)

This role prioritises communication, accountability, executive presence, and the ability to operate independently. We can train around specific technologies; we will not compromise on the ability to own execution and work directly with engineers.

If you're a security leader who enjoys building durable programmes and staying close to execution rather than delegating it – this is a strong opportunity to own a security function end to end.

Questions? Please, feel free to reach out: [email protected]

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.