yandex
boxinc
Страна
Польша
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
ГибридПолная занятость

Security and Compliance Manager (Third Party Risk)

Оценка ИИ

Box — стабильная публичная компания с сильной корпоративной культурой и фокусом на современные технологии (AI). Вакансия предлагает отличный баланс между операционной работой и стратегическим развитием в международной среде.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует более 4 лет опыта в информационной безопасности или аудите, а также глубокого понимания стандартов SOC 2 и ISO 27001. Основная сложность заключается в необходимости совмещать операционную оценку рисков со стратегическими инициативами по трансформации процессов.

Анализ зарплаты

Медиана20 000 PLN
Рынок16 000 PLN – 25 000 PLN
Оценка ИИ

Зарплата для данной позиции в Варшаве соответствует рыночным стандартам для специалистов уровня Middle/Senior в области GRC. В международных технологических компаниях уровня Box компенсация обычно находится в верхней границе указанного диапазона, дополняясь бонусами и акциями (RSU).

Сопроводительное письмо

I am writing to express my strong interest in the Security and Compliance Manager (Third Party Risk) position at Box. With over 4 years of experience in Information Security and GRC, I have developed a keen eye for identifying vulnerabilities within supply chains and implementing robust mitigation strategies. My background aligns perfectly with Box's mission to secure critical content while fostering innovation through AI-driven workflows.

In my previous roles, I have successfully managed complex risk assessments and navigated frameworks such as SOC 2 and ISO 27001. I am particularly drawn to Box's 'AI-first' approach and am eager to leverage my analytical skills to enhance your Third Party Risk Management processes. I am a proactive collaborator who thrives in dynamic environments and is committed to translating business requirements into secure, technical solutions.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в boxinc уже сейчас

Присоединяйтесь к лидеру в сфере управления контентом и станьте ключевым экспертом по кибербезопасности в Box!

Описание вакансии

What is Box?

Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

Why Box needs you:

As with many fast-moving SaaS companies, Box relies heavily on other companies to be efficient and scale. We are looking for a Risk Manager to review the security and compliance posture of third-party vendors and work with cross-functional stakeholders to mitigate against risk. As a key member of Box’s Third Party Risk Management (TPRM) team, you will also help increase AI adoption, design new processes, and lead initiatives to grow the team’s business impact.

What you'll do:

  • Deliver third-party risk assessments of Box's suppliers: assess controls, processes, and/or systems to identify risk, develop plans to mitigate against risks, and oversee the remediation plan to completion.
  • Interact with suppliers and internal stakeholders to understand the business objectives and gather info needed for security and compliance reviews, validations, and audits.
  • Manage and administer tools for performing supplier security and compliance reviews and risk mitigation. This includes data analytics and reporting on Third Party Risk
  • Drive initiatives for strategic transformation and operational improvement
  • Play a role in developing and fostering the Box culture in our growing office
  • Represent Box Poland internally and externally
  • Work hard, learn a lot, and have fun!

Who you are:

We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.

  • 4+ years of work experience in Information Security; Governance, Risk and Compliance (GRC); or Audit. Experience in Third Party Risk Management is preferred but not required.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, Business Administration, or related field
  • Knowledge of and interest in third party information security challenges and trends, including emerging threats; and general understanding of security and compliance certifications and frameworks such as SOC 2, ISO27001, NIST and PCI.
  • Experience solving complex, systemic issues that require creative thinking and solutions
  • Able to "wear multiple hats" at the same time and pivot quickly based on changes in the business.
  • Must speak English proficiently
  • Effective at written and oral communication. Highly organized with a strong attention to detail. You can easily translate business requirements into technical solutions and vice versa.
  • Passionate for collaboration, metrics, process improvement, figuring stuff out, and making things better.
  • Have integrity. Like to have fun. Make Mom Proud.

Percentage of Time Spent:

  • 40% third party risk assessments
  • 30% strategic initiatives
  • 20% mitigating and monitoring risk
  • 10% meetings

Systems

  • TPRM - Auditboard
  • Exceptions - Jira

BENEFITS

Check out the overview of Life at Box which include general perks and benefits.

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week. Your Recruiter will share more about how we work and company culture during the hiring process.

At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in.If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply!

EQUAL OPPORTUNITY

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation.

For details on how we protect your information when you apply, please see our Personnel Privacy Notice.

For more details on how Box Poland protects your information, please see our Supplemental Personnel and Candidate Privacy Notice.

#LI-KS2

#LI-Hybrid

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Audit
  • SOC 2
  • ISO 27001
  • PCI DSS
  • Information Security
  • NIST
  • Data Analytics
  • Jira
  • GRC
  • Third-Party Risk Management

Возможные вопросы на собеседовании

Проверка практического опыта оценки рисков сторонних организаций.

Опишите ваш процесс проведения оценки безопасности нового вендора: на какие критические области вы обращаете внимание в первую очередь?

Оценка знаний международных стандартов, упомянутых в описании.

Как вы проверяете соответствие поставщика стандарту SOC 2 Type II, и какие 'красные флаги' в отчете могут стать критическими для Box?

Проверка соответствия ценностям компании (AI-first).

Как, по вашему мнению, использование искусственного интеллекта может оптимизировать текущие процессы управления рисками третьих сторон (TPRM)?

Оценка навыков управления конфликтами и коммуникации.

Расскажите о случае, когда бизнес-подразделение настаивало на работе с рискованным поставщиком. Как вы аргументировали свою позицию и к какому решению пришли?

Проверка навыков работы с инструментами, указанными в вакансии.

Есть ли у вас опыт работы с Auditboard или Jira для управления рисками и исключениями? Если нет, какие аналогичные системы вы использовали?

Похожие вакансии

Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
250 000 ₽ – 450 000 ₽

Эксперт по защите периметра (WAF)

УдалённоРоссия
WAF · Wallarm · Positive Technologies Application Firewall · NGFW · IPS · Vulnerability Assessment · Network Security
+7 навыков
Квазар
до 350 000 ₽

DevOps-инженер/ИБ (devops engineer, information security)

УдалённоРоссия
TCP/IP · DNS · DHCP · HTTPS · SMTP · BGP · OSPF · VLAN · NAT · Zero Trust · RBAC · SIEM · Zabbix · ELK · Wazuh · Grafana · Bash · PowerShell · Python · VMware · Proxmox · Hyper-V · KVM · SoC
+24 навыков
Innostaff
Не указана

Сеньор AppSecOps-инженер

SeniorУдалённоБеларусь
AppSecOps · DevSecOps · SAST · DAST · SCA · CI/CD · Cybersecurity · Kubernetes · Docker
+9 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

boxinc
Страна
Польша