Lead Analyst - Cybersecurity (SITRM)
Offer summary

(Summary generated by AI based on the full job description)

The project involves a global Cybersecurity Supplier IT Risk Management program. Required skills include supplier risk assessment, Shared Assessment methodology, Archer tool, and experience in application, network, and cloud security assessments. Responsibilities cover executing assessments, collaborating with global teams, training, and reporting. Required certifications include CISSP, CISM, CISA among others.

from: 17 August 2026
to: 16 September 2026
salary not specifiedcontract of employment (full-time)
Offer parameters
level:lead
working mode:hybrid
location:Kraków, Lesser Poland
Kraków, Lesser Poland

Requirements

Operating system

Windows

Our requirements

  • ​​Bachelor’s Degree in Information Technology, Information Systems, Computer Science or a related technical field of study. ​Related experience may be considered in lieu of required education.​​
  • ​​6 or more years of experience in IT audit, supplier IT risk, vendor, or third-party security risk management.
  • ​Solid experience in process improvement and re-engineering, business requirements capturing, and process flowcharts.
  • ​Solid experience in application, network, and cloud security domains and assessments.
  • ​Working experience third party security risk assessment methodologies and industry frameworks.
  • ​Working experience with third party security assessment and management tools (Archer preferred)
  • ​Knowledge of Shared Assessment Third-Party Risk Management practices and questionnaires.
  • ​Strong critical thinking and planning skills.
  • ​Experience in large enterprise environments.
  • ​Excellent oral and written communication and ability to engage with stakeholders across the enterprise.​
  • Licenses/Certifications Required: Certified Information on Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Shared Assessments Certified Third Party Risk Professional (CTPRP) or Certified Third Party Risk Assessor (CTPRA), Information Systems Security Architecture Professional (ISSAP), or Information Systems Security Engineering Professional (ISSEP)​
  • Strong verbal and written communication, negotiation, analytical, time management, organizational, and relationship management skills.
  • ​Comfortable dealing with ambiguity, making decisions with sub-optimal/incomplete information.
  • ​Ability to analyze and challenge current working methods to create improvements in processes and result.
  • ​Experience working with cross functional teams.
  • ​Ability to work independently within a geographically dispersed team.
  • ​Understand and comply with all applicable company policies.​

Your responsibilities

  • ​​Execute security risk assessment and analysis of suppliers across all stages of the supplier lifecycle and act as the primary point of contact for international supplier assessments and partner with global vendor management teams, technology, and business functions to educate and communicate cyber risk.​
  • Collaborate with stakeholders to review Cybersecurity terms in supplier agreements
  • ​​​​​Support implementation and operation of program enhancement efforts including assessment process and technical requirements. Train team members and stakeholders on updated program and processes changes.​​​​
  • ​​Prepare and communicate monthly program metrics and reporting to appropriate stakeholders. ​
  • ​​Provide input on third party security controls, exceptions, and remediation plans to continuously improve assessment process to reduce cyber risk. ​
  • ​​​​​​Support implementation and operation of program enhancement efforts including assessment process and technical requirements. Train team members and stakeholders on updated program and processes changes.​​​​​

About the project

This role is responsible for executing and supporting Sysco’s global Cybersecurity Supplier IT Risk Management (SITRM) Program
Shift: 9 am to 5.00 PM local Poland time

This is how we organize our work

This is how we work

agile
1. A recruiter will review your application and have an initial conversation with you.
2. You will meet with the Hiring Manager and/or team to discuss the role and your experience.
3. You will meet with the relevant leads to discuss your technical expertise and behavioral
competencies.
4. If successful, we will discuss the final offer and next steps with you.
Company

What we offer

  • Be part of a global cybersecurity team protecting a dynamic enterprise environment.
  • Opportunity to work with modern security technologies and drive tool innovation.
  • Collaborative culture with professional development opportunities.
  • Hybrid work model with our Kraków office as the primary location.

Recruitment stages

  • 1.
    Initial recruiter screening
  • 2.
    Hiring Manager/Team interview
  • 3.
    Technical/Behavioral interview
  • 4.
    Final offer

SYSCO SERVICE CENTRE POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ

Sysco is the global leader in selling, marketing and distributing food products to restaurants, healthcare and educational facilities, lodging establishments and other customers who prepare meals away from home. Its family of products also includes equipment and supplies for the foodservice and hospitality industries. With more than 71,000 colleagues, the company operates 333 distribution facilities worldwide and serves approximately 700,000 customer locations. For fiscal year 2022 that ended July 2, 2022, the company generated sales of more than $68 billion. Information about our Sustainability program, including Sysco’s 2022 Sustainability Report and 2022 Diversity, Equity & Inclusion Report, can be found at www.sysco.com.

This is how we work

Lead Analyst - Cybersecurity (SITRM)
I apply to:
SYSCO SERVICE CENTRE POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Kraków, Lesser Poland
Pracodawca zbiera zgłoszenia przez swój system.
Przejdziesz na zewnętrzny formularz.

By clicking "Aplikuj" you confirm that you've read and accepted our Terms and Conditions.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Need more information?

  • Make sure the body of the offer doesn’t already include what you’re looking for.
  • Ask a question if you need more information you’re interested in.
  • We’ll forward your question to the employer and aim to provide a response within 3 business days.

Share this offer