Information Security Manager - EMEA
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Risk Management
In short
Ericsson is seeking an experienced Information Security Manager for the EMEA region to lead the Third-Party Security Risk Management program. The role involves strengthening the security posture, managing supplier risks, and contributing to the Information Security Management System, aligned with ISO/IEC 27001:2022. The position requires a strong understanding of cybersecurity regulations and experience in multinational environments.
Responsibilities
- Lead the Third-Party Security Risk Management program across EMEA.
- Develop and execute TPSRM operational plans, roadmaps, KPIs, and management reporting.
- Support and oversee supplier risk treatment activities.
- Monitor emerging supply chain threats and cybersecurity trends.
- Support the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in alignment with ISO/IEC 27001:2022.
- Lead Information Security Risk Assessments (ISRAs).
- Support the development and maintenance of Statements of Applicability (SoA).
- Act as a trusted security advisor to business leaders.
- Contribute to security awareness and initiatives that promote a strong security culture across EMEA.
- Support internal and external audits, regulatory compliance activities, and continuous improvement initiatives.
- Provide subject matter expertise for security investigations, incident management, and post-incident reviews.
- Support compliance with cybersecurity regulations across the EMEA region.
Requirements
- Minimum 5 years of experience in Information Security, Cybersecurity Risk Management, Third-Party Security Risk Management, Governance Risk & Compliance (GRC), or related domains.
- Experience working within large multinational organizations and complex matrix environments.
- Demonstrated experience performing security risk assessments, supplier assessments, risk treatment planning, and compliance activities.
- Strong understanding of Information Security Management Systems (ISMS), Information Security Risk Management (ISRM), and supplier risk management practices.
- Solid understanding of ISO/IEC 27001:2022, NIST Cybersecurity Framework (CSF), NIST SP 800-53, and cybersecurity regulatory requirements including NIS2, GDPR, and other EMEA relevant cybersecurity regulations.
- Fluent in English, both written and spoken.
Desired Qualifications
- Experience supporting and maintaining an ISO/IEC 27001-certified environment is highly desirable.
- Experience engaging with senior stakeholders and influencing risk-based decisions.
- Good understanding of AI and Generative AI tools, including security, privacy, governance, and compliance implications.
- Practical experience leveraging GenAI to streamline processes, improve efficiency, and support informed decision-making is highly desirable.
- Bachelor's degree in Information Technology, Cybersecurity, Engineering, Computer Science, or a related field.
- Preferred certifications include CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer/Auditor, CTPRP, or equivalent cybersecurity, risk management, governance, or compliance certifications.
Benefits
- Shape the security posture of one of the world's leading technology companies.
- Work with diverse stakeholders across Europe, the Middle East, and Africa.
- Influence strategic decisions in supplier security, risk management, and information security governance.
- Be part of a collaborative team dedicated to protecting Ericsson's people, information, and customers.
#Information Security#Cybersecurity#Risk Management#EMEA#Third-Party Risk