Point your AI agent at freehire and let it find you a job.

Get the CLI →

Deloitte Central Europe

NewBe an early applicant

Cybersecurity Compliance Manager

Posted
Discussion

We are looking for a Cybersecurity Manager to take ownership of NIS2 compliance across our in-scope entities in Central Europe (Poland, Romania, Czech Republic, Slovakia, Slovenia, Bulgaria and Hungary), working across regional and local stakeholders to embed regulatory requirements into day-to-day operational practice and ensure ongoing compliance with regulatory requirements.

This role sits within the regional CISO team, offering direct visibility into strategic security decision-making and the opportunity to meaningfully shape it. The individual in this position will have a tangible impact on regulatory standing and operational resilience across the region.

Scope of responsibilities:


1. Develop an understanding of local requirements:

  • Maintain a continuous awareness of NIS2 laws and regulations across the various countries of Central Europe and cooperate with local legal experts and consultants to understand scope and impact across the company;
  • Maintain and continuously update the roster of local roles and responsibilities of various functions across the company that are required to either act or provide input for NIS2 related matters;
  • Maintain and continuously update the catalogue of business services, hardware and software assets, and third-party suppliers across all in-scope entities, ensuring accuracy and completeness as the operational landscape evolves;
  • Support gap assessment initiatives across in-scope entities, identifying deficiencies in controls, documentation, and processes related to NIS2 and applicable national regulatory requirements.

2. Implement and NIS2 across the Central Europe region:

  • Develop and oversee structured remediation plans to address identified compliance gaps, coordinating remediation efforts across regional security functions and local stakeholders through to closure;
  • Draft, implement and maintain Standard Operating Procedures and Work Instructions to support the compliance framework and satisfy legal and regulatory obligations;
  • Ensure vendor contracts and internal documentation remain aligned with applicable legal and regulatory requirements;
  • Development and ongoing maintenance of security policies, procedures, and supporting documentation, applying version control, periodic review cycles, and management approval processes to ensure continued regulatory alignment;
  • Create and maintain a centralized control matrix related to NIS2 requirements as well as identify local, national level requirements, different from the Directive text and maintain local, country level controls, along with associated policies, procedures and work-instructions.


3. Monitor business continuity requirements:

  • Monitor and support the development, documentation and implementation of a business continuity and disaster recovery framework in alignment with NIS2 requirements, working with the relevant functions to ensure timely delivery and appropriate governance oversight;
  • Monitor periodic testing of business continuity, disaster recovery, and backup procedures including tabletop exercises, technical failover tests, and restoration verification ensuring that accountable teams conduct testing as required, findings are documented and identified gaps are tracked through to remediation.

4. Coordinate local level incident communication with regulatory bodies:

  • Serve as the primary point of contact for national authority inquiries, managing communications and coordinating the cyber incident response process across regional stakeholders and in-scope entities, gathering and disseminating relevant threat intelligence;
  • Manage the end-to-end process of cybersecurity incident notification to national authorities, ensuring all reporting obligations are fulfilled within prescribed regulatory timeframes.

5. Coordinate NIS2 activities to meet regulatory audit and self-assessment requirements:

  • Ensure periodic/event-triggered risk assessments and compliance reviews, including findings documentation, remediation tracking, and escalation to the Risk Register where required;
  • Manage the full lifecycle of mandated periodic regulatory audits, encompassing auditor procurement, scheduling and adherence to prescribed regulatory timelines, including preparation of audit evidence, facilitation of audit sessions, while maintaining an up-to-date Risk Treatment Plan and actively following up on the resolution of audit findings with local entities and regional stakeholders.

6. Monitor, report and participate in the NIS2 governance process across Central Europe:

  • Participate in the decision-making process to ensure that adequate support is allocated across the various business processes across the organization to support both the implementation of NIS2 requirements and the ongoing compliance obligations;
  • Deliver regular reporting on key risk indicators, key performance indicators, and overall compliance status to senior leadership, providing clear and actionable insight into the organization’s regulatory posture;
  • Drive continuous improvement across the compliance and cybersecurity governance framework, proactively identifying opportunities to strengthen controls, streamline processes and enhance the overall regulatory posture.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available