Doświadczenie zawodowe
Information Security Policy and Standards SME
• Creating information security policies, and standards according to business and security needs in 100 000 plus employees organization
• Managing document implementation according to the process and with respective governance bodies.
• Rolling-out new and revised documents.
• Review policies and standards to ensure its effectiveness and alignment with changing business needs, environments, legal requirements, and organization risk appetite
• Establishing communication path with different ABB’s organizational units concerning new, revised, and withdrawn documents
• Supporting security awareness activities including training around information security documents.
• Acting as a single point of contact for inquiries on documents.
• Supporting audits conducted against information security.
• Managing document implementation according to the process and with respective governance bodies.
• Rolling-out new and revised documents.
• Review policies and standards to ensure its effectiveness and alignment with changing business needs, environments, legal requirements, and organization risk appetite
• Establishing communication path with different ABB’s organizational units concerning new, revised, and withdrawn documents
• Supporting security awareness activities including training around information security documents.
• Acting as a single point of contact for inquiries on documents.
• Supporting audits conducted against information security.
Internal Security Department Director, Security Officer
Duties:
• Maintain Information Security Management System
• Information security risk analysis
• Analysis and reports security incidents breach
• Approval security policies, procedures and guidelines
• Supervision of conducts IT security audits, physical security audits, and compliance audits
• Cooperation with creating business continuity plans (member of BCP Steering Committee)
• Represents company on internal security audits
Knowledge:
• Security management
• ISO 27001, ISO 27002
• Maintain Information Security Management System
• Information security risk analysis
• Analysis and reports security incidents breach
• Approval security policies, procedures and guidelines
• Supervision of conducts IT security audits, physical security audits, and compliance audits
• Cooperation with creating business continuity plans (member of BCP Steering Committee)
• Represents company on internal security audits
Knowledge:
• Security management
• ISO 27001, ISO 27002
Security Officer
Duties:
• Maintain ISO 27001 certificate
• Conduct security risk analysis
• Conduct security incidents analysis
• Develop and maintain security procedures and security guidelines
• Execute IT and physical security audits,
• Develop business continuity plans
• Manage department (since February to September 2008) as director deputy
Knowledge:
• Security management
• Management by objectives
• ISO 27001, ISO 27002
• Internal audits
• Cryptography
• Law: Protection of Classified Information Act, Personal Data Protection Act, Delivering Electronic Services Act
• Maintain ISO 27001 certificate
• Conduct security risk analysis
• Conduct security incidents analysis
• Develop and maintain security procedures and security guidelines
• Execute IT and physical security audits,
• Develop business continuity plans
• Manage department (since February to September 2008) as director deputy
Knowledge:
• Security management
• Management by objectives
• ISO 27001, ISO 27002
• Internal audits
• Cryptography
• Law: Protection of Classified Information Act, Personal Data Protection Act, Delivering Electronic Services Act
Security systems and network engineer
Duties:
• Develop and maintain security procedures and security guidelines
• Conduct IT and physical security audits,
• Security consulting for employees
• Maintain security policy
• Develop and conduct security awareness program
• Support PKI implementation and progress
• Conduct security risk analysis
• Prepare and give security trainings
• Evaluation of software and hardware security solutions
Knowledge:
• BS 7799:1/ISO 17799, BS 7799:2/ISO 27001
• Public Key Infrastructure
• Protection of Classified Information Act
• Personal Data Protection Act
• Internal audits
• Cryptography
• Develop and maintain security procedures and security guidelines
• Conduct IT and physical security audits,
• Security consulting for employees
• Maintain security policy
• Develop and conduct security awareness program
• Support PKI implementation and progress
• Conduct security risk analysis
• Prepare and give security trainings
• Evaluation of software and hardware security solutions
Knowledge:
• BS 7799:1/ISO 17799, BS 7799:2/ISO 27001
• Public Key Infrastructure
• Protection of Classified Information Act
• Personal Data Protection Act
• Internal audits
• Cryptography
Specjalizacje
IT - Administracja
Bezpieczeństwo/Audyt
Grupy
Akademia Górniczo-Hutnicza im. Stanisława Staszica w Krakowie
Akademia Górniczo-Hutnicza to jedna z najlepszych i najbardziej renomowanych polskich uczelni, od lat zajmująca czołowe miejsca w rankingach szkół wyższych. Przoduje w dziedzinie nowocze