Information Risk and Compliance Officer
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · DevOps · Mjukvaruutveckling
I korthet
WeQuel seeks an experienced Information Risk and Compliance Officer for a full-time, on-site role in Södertälje, Sweden. The position focuses on strengthening information security governance, risk management, and compliance within production and logistics environments.
Ansvarsområden
- Governance and continuous improvement of the ISMS within Production & Logistics
- Implementation of the ISMS within Production & Logistics
- IRAM assessments and follow-up
- Information security governance, processes and coordination
- Preparation and maintenance of security documentation, reports, presentations and supporting materials
- Review, rewriting and improvement of shopfloor IT procedures and guidelines for clarity, accuracy and compliance
- Collaboration with Production Units (PRUs), P&L IT (IN), Maintenance and Logistics
- Leadership and coordination of the Local Information Security Officers (LISOs) network
- Stakeholder support on information security and compliance requirements
- Assessment of Cyber Resilience Act (CRA) implications for Production & Logistics
- Structured, consistent security documentation and governance, aligned with the ISMS
Krav
- Experience in information security, cybersecurity support, risk management or compliance
- Experience in information security governance, risk and compliance (GRC)
- Experience supporting governance processes, documentation or coordination of security work
- Experience supporting or implementing structured security processes and ways of working
- Experience conducting or supporting risk assessments and follow-up
- Relevant academic degree, or equivalent professional experience, in information security, cybersecurity, risk management, compliance or a related field
- Fluent Swedish and English, spoken and written
- Strong ability to produce professional documentation and deliverables in English
- Strong documentation and analytical skills, with the ability to structure complex information clearly
- Strong ability to develop, review and improve security procedures, guidelines and documentation
- Able to translate complex security and compliance requirements into clear, practical documentation
- Able to work effectively with technical and operational stakeholders
- Able to coordinate activities across multiple stakeholders, functions and organisational areas
- Strong stakeholder management and communication skills
- Able to structure, prioritise and drive assigned activities independently
- Structured and detail-oriented, with strong analytical skills and a high focus on quality
- Proactive and solution-oriented; comfortable owning your activities while collaborating across functions and areas of expertise
- Communicates clearly with technical and operational stakeholders
- Able to turn complex information, security requirements and governance needs into structured, understandable documentation
- Comfortable handling multiple parallel activities with high accuracy and quality
Önskade kvalifikationer
- ISO 27000 certification and/or hands-on experience with ISO 27001 frameworks
- Knowledge of the Cyber Resilience Act (CRA) and NIS2
- Experience with Cybersecurity Management Systems (CSMS)
- Experience from industrial, production or manufacturing environments
- Experience with IT/OT environments
Förmåner
- Part of a consulting team that values people first.
- Success comes from engagement, collaboration and development.
- Flat organisation with short decision paths.
- Strong sense of community.
- Opportunity to shape your own development.
#Consulting#Information Security#Risk Management#Compliance#Södertälje