You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Rafal JaworskiRJ

Rafal Jaworski

Head of Cybersecurity

€700/day
Berlin, DE
15+ years

Average response time: 1 hour

About Rafal

Head of Cybersecurity and vCISO specialising in NIS2, DORA, ISMS, GRC and AI Governance.

I support organisations in building mature, compliant and resilient security programmes - from technical oversight to regulatory alignment and executive-level risk leadership.

With more than 15 years of business experience, I have led cybersecurity, GRC and risk management functions across fintech, financial services and international organisations. I have worked as Head of Cybersecurity in a global fintech (valued at $1B), served as vCISO for multiple companies, and acted as COO in one of the cybersecurity companies within a publicly listed capital group.

My consulting focus includes:
- NIS2 / DORA readiness, audits and implementation
- vCISO services and cybersecurity leadership
- GRC (governance, risk and compliance)
- ISMS design and ISO 27001 preparation and implementation
- AI governance, EU AI Act readiness and responsible AI controls
- IT security oversight
- Board-level cybersecurity advisory and executive reporting
- Due diligence under ICT and third-party risk management (TPRM)

I combine strategic security leadership with hands-on understanding of compliance, risk and technology. I work with organisations that need clear structure, fast improvement and strong alignment with European regulatory requirements - from planning to execution.

Available for:
✔ Cybersecurity advisory
✔ Fractional/vCISO engagements
✔ Compliance and risk projects
✔ NIS2 / DORA / AI Act preparation
✔ Audits, assessments, gap analysis and security strategy development

Senior cybersecurity leader delivering measurable results in governance, risk and compliance.

📊Impact in numbers:
- Secured information assets valued at ~$1.5B
- Ran a zero-audit programme across 10 critical domains in under 3 months
- Delivered SAT training to 1 000+ employees across multiple regions
- Built a proprietary DDQ with 50+ security controls for TPRM
  • English

    Native or bilingual

  • Polish

    Native or bilingual

  • Swedish

    Basic

Remote only
Primarily works remotely

Experience

  • Macrobond Financial
    Head of Cybersecurity
    BANKING AND INSURANCE
    October 2021 - November 2025 (4 years and 1 month)
    As the Head of Cybersecurity at a global fintech company, I oversee the strategic enhancement of cybersecurity frameworks, focusing on Governance, Risk, and Compliance (GRC).

    My role supports the organization in strengthening cybersecurity defenses while servicing customers in a highly regulated industry. I aim to ensure that a risk-based approach is an integral part of the product delivery process to major banks, asset managers, government entities, and research institutions.

    My responsibilities have been expanded to include AI Governance, focusing on risk and compliance assessment, and the development of frameworks and policies for responsible AI implementations.

    In my daily work, I advocate for the 'cybersecurity as a business enabler' approach, emphasizing how a proactive and risk-aware posture can support business success.
    Cybersecurity Strategy GRC (Governance, Risk and Compliance) Risk Management NIS2 Compliance AI Governance
  • H2B Group IT Consulting
    vCISO
    DIGITAL AND IT
    November 2023 - Today (2 years and 8 months)
    In an advisory capacity, I collaborate with H2B Group as a vCISO and independent cybersecurity consultant, providing both strategic leadership and hands-on support across key security domains.

    My work covers areas such as security audits, penetration testing oversight, Governance, Risk & Compliance (GRC), and the development and scaling of cybersecurity capabilities. I also support broader initiatives focused on strengthening the organisation’s operational and strategic security posture.

    As an advisory partner, I offer expert guidance to the organisation and its clients wherever senior-level security insight, governance leadership or additional operational capacity is required.
    vCISO GRC (Governance, Risk and Compliance) Cybersecurity Strategy Security Audit Risk Management
  • CISO #Poland
    Member of The Supervisory Board
    March 2023 - Today (3 years and 4 months)
    Acting as a representative of the CISO #Poland community and providing supervisory oversight of the Management Board's activities.

Recommendations

Be the first to recommend Rafal

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Postgraduate - Cybersecurity Management
    SGH (Warsaw School of Economics)
    2019
    Postgraduate - Cybersecurity Management
  • Masters - Business Management
    Banking School (WSB Merito University)
    2014
    Masters - Business Management

Certifications

  • Security+
    CompTIA
    2019
    Incident Response Identity & Access Management Threat Detection Risk Management
  • AI in Business Development
    Google
    2025
    AI Strategy AI Governance Fundamentals Responsible AI AI in Business Development

Skill set

Categories