Information Risk and Compliance Officer
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · DevOps · Systemteknik
I korthet
WeQuel seeks an Information Risk and Compliance Officer in Södertälje, Sweden, to lead ISMS governance, risk management, and compliance within Production & Logistics. This full-time, on-site role involves developing clear processes, documentation, and supporting risk assessments to strengthen industrial security.
Ansvarsområden
- Governance and continuous improvement of the ISMS within Production & Logistics
- Support and execution of IRAM assessments and related follow-up activities
- Contribution to information security governance, processes and coordination activities
- Preparation and maintenance of security-related documentation, reports and presentations
- Review, rewriting and improvement of shopfloor IT procedures and guidelines
- Collaboration with stakeholders across Production Units (PRUs), P&L IT (IN), Maintenance and Logistics
- Leading and coordinating the network of Local Information Security Officers (LISOs)
- Support to stakeholders in understanding and addressing information security and compliance requirements
- Assessment of the implications of the Cyber Resilience Act (CRA) for Production & Logistics
- Ensuring structured, consistent documentation and governance activities aligned with the ISMS
Krav
- Experience within information security, cybersecurity support, risk management or compliance-related activities
- Experience of information security governance, risk and compliance work
- Experience of supporting or implementing structured security processes and ways of working
- Experience of conducting or supporting risk assessments and follow-up activities
- Experience of supporting governance processes, documentation activities or coordination of security-related work
- Relevant academic degree or equivalent professional experience within information security, cybersecurity, risk management, compliance or a related field
- Fluent Swedish and English, both spoken and written
- Strong ability to produce professional documentation and deliverables in English
- Strong documentation and analytical skills, with the ability to structure complex information clearly
- Ability to develop, review and improve security-related procedures, guidelines and documentation
- Ability to translate complex security and compliance requirements into clear, practical documentation
- Ability to coordinate activities across multiple stakeholders, functions and organisational areas
- Strong stakeholder management and communication skills, towards both technical and operational stakeholders
- Structured, proactive and solution-oriented, with a high focus on quality and accuracy
- Comfortable taking ownership and working across multiple parallel activities
Önskade kvalifikationer
- ISO 27000 certification and/or practical experience of ISO 27001 frameworks
- Knowledge of the Cyber Resilience Act (CRA) and NIS2
- Experience of Cybersecurity Management Systems (CSMS)
- Experience from industrial, production or manufacturing environments
- Experience of IT/OT environments
Förmåner
- Part of a consultant team that values people first
- Success is created through commitment, collaboration and development
- Flat organisation with short decision paths
- Strong sense of community
- Opportunity to influence your own development
#Consulting#Information Security#Risk Management#Compliance#ISMS#Cybersecurity#Production#Logistics