(Cybersecurity) Threat and Controls Assessment Consultant

(Cybersecurity) Threat and Controls Assessment Consultant

Threat and Controls Assessment Consultant

 

Location: Kraków, Poland

Work model: Hybrid – 6 days per month from the Kraków office

Contract: B2B

About the role

 

We are looking for a Senior Cybersecurity Threat Analyst to join a global cybersecurity environment and play a key role in identifying security threats, assessing controls and helping technology teams build secure solutions.

In this role, you will focus on threat modelling, security assessments and identifying vulnerabilities and control gaps across a diverse technology landscape, including applications, databases, networks, infrastructure and cloud environments.

 

You will work closely with developers, architects, technical leads and business stakeholders, translating technical security findings into clear business risks and practical recommendations.

This is a hands-on role for someone who combines a strong technical cybersecurity background with excellent analytical and communication skills.

 

What you will do

  • Perform threat modelling and threat & control assessments for technology services and solutions across on-premise, cloud and external environments.
  • Identify potential security threats, vulnerabilities and control gaps across applications, databases, networks and infrastructure.
  • Work closely with developers, architects and technical leads to understand end-to-end solutions and identify security risks.
  • Assess existing security controls and recommend appropriate improvements.
  • Translate technical security findings into clear and actionable business risks and recommendations.
  • Provide security input throughout the software development lifecycle (SDLC), from design through implementation and support.
  • Contribute to the design and development of technology solutions by providing practical security recommendations.
  • Evaluate security implications of new technologies, products and solutions and provide technical recommendations.
  • Collaborate with cybersecurity and technology stakeholders to investigate and address potential security issues.
  • Contribute to the continuous improvement of security assessment processes, methodologies and tools.
  • Keep up to date with emerging technologies, cybersecurity threats, industry trends and best practices.
  • Support a collaborative, international environment and contribute to knowledge sharing across the wider cybersecurity community.

 

What we are looking for

Cybersecurity & risk expertise

  • Several years of professional experience in cybersecurity, information security or a related technology field.
  • Hands-on experience with threat modelling and security assessments.
  • Strong understanding of cybersecurity concepts, principles and best practices.
  • Good understanding of risk and control management.
  • Ability to identify and assess threats, vulnerabilities and control weaknesses.
  • Experience translating technical security issues into business risks and practical recommendations.
  • Experience with security assessment of complex enterprise technology environments.

 

Strong technical background

  • Good understanding of application design and architecture.
  • Knowledge of application, network and host security.
  • Good understanding of cloud security and practical experience with at least one major cloud platform: AWS, Azure or GCP.
  • Strong understanding of the Software Development Lifecycle (SDLC), with a focus on security.
  • Understanding of modern Generative AI and Agentic AI systems and their associated security risks.
  • Good understanding of emerging technologies and related cybersecurity threats.
  • Experience with security processes, methodologies and continuous improvement.

 

Communication & stakeholder management

  • Strong communication skills and the ability to work effectively with both technical and non-technical stakeholders.
  • Ability to explain complex security topics in a clear and business-oriented way.
  • Experience working in international and multicultural environments.
  • Strong stakeholder management skills and the ability to influence and provide recommendations.
  • Ability to work independently while also being an effective team player.
  • Strong analytical, problem-solving and decision-making skills.
  • Comfortable working in a fast-paced environment where priorities and requirements may change.

 

Certifications

Industry-recognised cybersecurity certifications are an advantage, such as:

  • CISSP
  • CISM
  • CRISC
  • Cloud Security certifications

 

What we offer

  • B2B contract
  • Hybrid work model – 6 days per month from the Kraków office
  • Lux Med private medical care
  • MyBenefit cafeteria
  • Dedicated support from a Contractor Care Specialist
  • Opportunity to work on complex, international cybersecurity initiatives
  • Exposure to modern technologies, cloud environments and emerging AI security challenges
  • A collaborative environment with opportunities for professional development
ID: 16651 job_post.published_on: 09/09/2026
announcement.apply