Digital & Technology Team (D&T)is an integral division of HEINEKEN Global Shared Services Center. We are committed to making Heineken the most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and innovative teams and have a direct impact on building the future of Heineken!
Would you like to meet the Team, see our office and much more? Visit our website: Heineken (heineken-dt.pl)
The Cyber Security Officer actionizes the strategic direction, policies, and governance designed by GIS and controls to ensure the effective delivery of a high-quality Information Security service for HEINEKEN. As a member of the TP&S Hub Information Security team, the Cyber Security Officer will be the subject matter expert for all matters around information security, be a member of the incident response team in the event of a security breach and be one of the main contacts for OpCo stakeholders. In addition, the role holder has joint responsibility for Control processes, including audit, security, business continuity and regulatory compliance across D&T.
Your responsibilities would include:
- coordinating cybersecurity activities across assigned Operating Companies/Divisions and acting as a bridge between global and local teams
- implementing global security strategies, standards, and solutions while adapting them to local requirements
- managing and assessing cybersecurity risks, including conducting risk reviews and defining mitigation or acceptance plans
- monitoring compliance with security policies and overseeing audit processes while ensuring timely remediation of findings
- coordinating end‑to‑end incident response, including communication with stakeholders and collaboration with technical teams
- advising and supporting IT and business teams on security controls such as patching, vulnerability management, and antivirus
- contributing to the design and continuous improvement of security standards, controls, and processes
- monitoring effectiveness of security controls and analyzing deviations or exceptions from policies
- supporting investigations of security incidents and potential breaches
- driving cybersecurity awareness initiatives and supporting capability development across local teams.
You are a good candidate if you have:
5+ years of working experience in the Cyber Security area
5+ years of experience working in agile teams in multi-cultural environments
5+ years of working with senior business stakeholders, influencing and working with Operating Companies/Divisions
Bachelor's or Master’s degree in Information Security or a relevant subject
a strong technical background with experience in one or more IT areas
experience of technical disciplines in relation to Information and Cyber Security management
experience of working with relevant standards such as ISO 27001, COBIT, and relevant laws and regulations, such as privacy laws, including GDPR
experience of managing audit and control processes within a technology context
ability to work in a cross-functional environment and preferably experience in FMCG
ability to manage multiple conflicting priorities and deadlines in a matrix environment with rapid change
good interpersonal skills, oral and written communication skills, relationship management and influencing skills
ability to build and leverage personal and professional networks
working within a local and global matrix context
strong attention to detail, independent judgment and decision-making
experienced in self-development through continuous learning, sharing best practices, knowledge, and expertise
- fluent English level, both written and spoken.
You are a perfect match if you also have:
- certification in relevant IT Security discipline (e.g. CISA, CISM, CISSP, CEH).
At HEINEKEN Kraków, we take integrity and ethical conduct seriously. If someone has concerns about a possible violation of legal regulations indicated in Polish Whistleblowing Act or our Code of Business Conduct, we encourage them to speak up. Cases can be reported to global team or locally (in line with the local HGSS Whistleblowing procedure) by selecting proper option in this tool or by communicating it on hotline.
