Technology Risk & Security Manager (SCAR)

Workplace
Remote ok
Compensation
PLN 28k – PLN 30k

About this role


Technology Risk & Security Manager (SCAR)

In Poland - Warsaw or fully remote from Home

This role serves as the bridge between business demand, IT architecture, cybersecurity, SOC, audit, compliance, procurement, privacy, and implementation teams - operating within the company’s Technology Demand Intake Process, which is closely connected to implementation and lifecycle governance. This individual will focus on reviewing technical concepts, stand-alone products, services, and AI-enabled solutions that the company plans to implement or integrate into its complex global enterprise technology landscape, including SaaS, PaaS, SAP, and AI-enabled platforms. You will be responsible for assessing and governing new technology demands, services, platforms, and AI-enabled solutions through the organization’s technology intake process. The role ensures that security, compliance, architecture, operational, and business risks are identified, clearly documented, and addressed through effective and practical mitigation measures.

The salary for this position ranges from PLN 28 00 to PLN 30 000 gross per month under an employment contract (UoP), depending on the candidate’s relevant experience, skill set, level of expertise and overall fit for the role. Additional factors such as industry background, technical competencies and interview performance may also influence the final offer. The compensation package at Simon-Kucher CBS consists of a gross base salary, a monthly remote work allowance and an annual bonus. The bonus is paid in December and is based on the results of a 360-degree performance evaluation.

Please remember to submit your application in English. Other applications will not be considered. The candidate should have an EU work permit, we do not offer visa for this position.

What makes us special:
  • Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive-ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks.
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive-facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross-functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities and tight timelines.
How you will create an impact:
  • Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive-ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive-facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross-functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities and tight timelines.
Your profile:
  • Experience in a complex global environment, comparable consulting or service industries is preferred.
  • Bachelor’s Degree required – preferred in the area of Technology, MIS, Cybersecurity, etc.
  • 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting.
  • Strong knowledge of cybersecurity, technology risk management, compliance, enterprise IT governance, and emerging AI-enabled technologies.
  • Experience assessing SaaS, cloud, third-party, and AI-enabled solutions, with the ability to identify risks, mitigation strategies, and implementation requirements.
  • Experience improving governance processes, workflows, standards, and risk management practices.
  • Knowledge of security and governance frameworks such as ISO 27001, SOC 2, ITIL, or similar.
  • Experience with security controls, risk assessments, compliance, audit support, and governance approval processes.
  • Ability to evaluate platform architecture, integrations, identity and access management, data flows, encryption, logging, monitoring, and operational security.
  • Understanding of enterprise architecture, cloud security, vendor risk management, and secure technology implementation.
  • Strong stakeholder management skills with experience working across IT, Security, Architecture, Compliance, Privacy, Legal, Procurement, Audit, and business teams.
  • Experience preparing executive-level presentations, risk reports, and decision-ready documentation, and presenting recommendations to senior leadership.
  • Experience evaluating third-party vendors, cloud platforms, SaaS solutions, and managed services within global IT environments.
  • Experience supporting technology onboarding, vendor risk assessments, procurement, RFPs, and cross-functional technology initiatives.
  • Ability to manage risks, remediation activities, project dependencies, and implementation progress across the technology lifecycle.
  • CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent certification (or comparable hands-on experience).

If you’re interested, and if you’d like to offer your skills and commitment to our international team, then we would be pleased to receive your application.

Hit the ‘Apply Now’ button to begin your application

About Simon-Kucher
Simon-Kucher is a global consultancy with more than 2,200 employees in 30+ countries. Our sole focus is on unlocking better growth that drives measurable revenue and profit for our clients. As a trusted commercial advisor, we combine deep consulting expertise, growth specialization, and technology to scale impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, sales, and digital – based on deep insights into what customers value and are willing to pay for. With over 40 years of experience in monetization, we are regarded as the world’s leading commercial growth and pricing specialist. simon-kucher.com

We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.

Your personal contact:
Karolina Ratajczyk
[email protected]

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?

Top Benefits

  • Remote work allowance
  • Annual bonus