Posted:
7/29/2025, 7:23:42 PM
Location(s):
Greater Poland Voivodeship, Poland ⋅ Poznan, Greater Poland Voivodeship, Poland
Experience Level(s):
Senior
Field(s):
IT & Security
Key Responsibilities:
Complete supplier cybersecurity assessments and reports in line with departmental procedures and processes.
Maintain and mature the third-party risk management process framework for security risk, including necessary standards, procedures, and technologies
Provide clarifying support, where necessary, to internal third-party relationship owners or third-party representatives in their efforts to provide responses to the security risk assessment questionnaire.
Coordinate with various stakeholders to ensure proper security clauses are included in third-party contracts
Effectively translate third-party responses to assessment questionnaire, using sound judgement, into concise risk exposure reporting for delivery to internal stakeholders
Collaborate with internal third-party relationship owners and external third-party representatives to recommend necessary security controls to effectively mitigate risks to GSK
Ensure robust tracking and remediation of third-party security and privacy risk exposures identified through assessment processes
Provide any necessary training and awareness related to the third-party security risk assessment process
Contribute to the gathering and distribution of periodic program metrics and/or dashboards
Provide consultancy SME support in conducting security posture assessments as part of continuous monitoring or post breach scenarios to ensure that suppliers have adequate security controls.
Requirements:
Prior experience in conducting cybersecurity and third-party security assessments.
Experience in building and enhancing internal processes, including developing workflows, documenting procedures, identifying inefficiencies, and implementing improvements to support operational effectiveness and compliance.
Good verbal and written communication skills, with the ability to effectively interact with professionals at all levels
Ability to prioritize, delegate, and foster the development of high-performance teams to lead/support an environment driven by customer service and teamwork.
Understanding of frameworks and standards such as ISO 27001, NIST, CIS, etc.
Knowledge of cyber security principles, IT security controls, and related technologies and products.
Work with virtual teams located in different countries around the world, aligning and adapting different work, culture, and communication styles.
Why GSK?
Uniting science, technology and talent to get ahead of disease together.
GSK is a global biopharma company with a special purpose – to unite science, technology and talent to get ahead of disease together – so we can positively impact the health of billions of people and deliver stronger, more sustainable shareholder returns – as an organisation where people can thrive. We prevent and treat disease with vaccines, specialty and general medicines. We focus on the science of the immune system and the use of new platform and data technologies, investing in four core therapeutic areas (infectious diseases, HIV, respiratory/ immunology and oncology).
Our success absolutely depends on our people. While getting ahead of disease together is about our ambition for patients and shareholders, it’s also about making GSK a place where people can thrive. We want GSK to be a place where people feel inspired, encouraged and challenged to be the best they can be. A place where they can be themselves – feeling welcome, valued, and included. Where they can keep growing and look after their wellbeing. So, if you share our ambition, join us at this exciting moment in our journey to get Ahead Together.
GSK is an Equal Opportunity Employer. This ensures that all qualified applicants will receive equal consideration for employment without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), military service or any basis prohibited under federal, state or local law.
Important notice to Employment businesses/ Agencies
GSK does not accept referrals from employment businesses and/or employment agencies in respect of the vacancies posted on this site. All employment businesses/agencies are required to contact GSK's commercial and general procurement/human resources department to obtain prior written authorization before referring any candidates to GSK. The obtaining of prior written authorization is a condition precedent to any agreement (verbal or written) between the employment business/ agency and GSK. In the absence of such written authorization being obtained any actions undertaken by the employment business/agency shall be deemed to have been performed without the consent or contractual agreement of GSK. GSK shall therefore not be liable for any fees arising from such actions or any fees arising from any referrals by employment businesses/agencies in respect of the vacancies posted on this site.
Please note that if you are a US Licensed Healthcare Professional or Healthcare Professional as defined by the laws of the state issuing your license, GSK may be required to capture and report expenses GSK incurs, on your behalf, in the event you are afforded an interview for employment. This capture of applicable transfers of value is necessary to ensure GSK’s compliance to all federal and state US Transparency requirements. For more information, please visit the Centers for Medicare and Medicaid Services (CMS) website at https://openpaymentsdata.cms.gov/
Website: https://gsk.com/
Headquarter Location: London, England, United Kingdom
Employee Count: 10001+
Year Founded: 1929
IPO Status: Public
Last Funding Type: Grant
Industries: Biotechnology ⋅ Health Care ⋅ Pharmaceutical