We're hiring a Cybersecurity Risk Manager to join a large-scale IT security programme for a major EU agency, delivered through a specialist staffing partner. This is a fully on-site role at the agency's headquarters in Warsaw (100% intra-muros), with no travel foreseen. The role sits within a highly regulated environment, protecting critical assets and infrastructure, and requires a Personal Security Clearance at CONFIDENTIEL UE/EU CONFIDENTIAL level (screening initiated within the first 45 days of assignment). Logistics Location: Warsaw, Poland - fully on-site, 100% intra-muros, no travel foreseen Engagement: framework contract, 12-month initial term with up to 3 annual renewals (up to 48 months total) Clearance: Personal Security Clearance required (CONFIDENTIEL UE/EU CONFIDENTIAL), to be initiated within the first 45 days Selection process: written test and interview You'll own the organisation's cybersecurity risk-management lifecycle end to end - from asset inventory and threat/vulnerability assessment through to control design, monitoring, and executive reporting - helping keep risk within acceptable levels across the organisation's assets. What you'll do Develop and maintain the organisation's cybersecurity risk-management strategy Manage the asset inventory Identify and assess cybersecurity threats and vulnerabilities Profile the threat landscape and attacker capability Assess risks and propose treatment options (controls, mitigation, avoidance) aligned to strategy Monitor control effectiveness and risk levels Keep risk within acceptable levels for the organisation's assets Develop, maintain, report, and communicate the full risk-management cycle What you bring Strong background in risk assessment, risk-management framework implementation, and stakeholder risk communication 9+ years overall IT experience, with 6+ years in a similar risk-management role Level 7 education (Master's degree or higher) English at C1 level At least four of: CISA, CISM, CRISC, CISSP, CGRC, CSSLP, CCSP, CISSP-ISSMP, GSNA, GCCC, GIAC Certified ISO-27000 Specialist, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager (or internationally recognised equivalents) Experience producing Business Impact Assessments; ServiceNow GRC risk-assessment module experience a plus Experience with personal data protection documentation, threat modelling (graphical and programmatic tools, including for DevOps), Zero Trust Architecture design, Secure SDLC, and Directory Services defence controls Comfortable presenting risk-informed recommendations to executives and stakeholders, and building an organisation-wide risk-aware culture