IT Security & Risk Officer
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet
I korthet
The IT Security & Risk Officer role focuses on strengthening cybersecurity governance through data-driven insights, performance monitoring, and management reporting. Responsibilities include developing metrics, creating dashboards, preparing management reports, and supporting risk & compliance analyses. This role requires 3-5 years of experience in Cybersecurity GRC, Risk Management, or Data Analytics, with familiarity in frameworks like ISO 27001 and NIST CSF.
Ansvarsområden
- Develop, maintain, and enhance governance metrics, KPIs, and reporting frameworks to monitor cybersecurity governance performance.
- Create and maintain governance and compliance dashboards for visibility into activities, compliance status, and KPIs.
- Prepare management reporting packages and governance insights for leadership teams and decision-making bodies.
- Support the preparation of regulatory readiness and compliance reports related to applicable cybersecurity regulations and standards.
- Ensure governance reporting is accurate, timely, and aligned with organizational objectives.
- Support governance, risk, and compliance analyses to identify trends, gaps, and emerging risks.
- Perform trend analysis and reporting to monitor governance performance and compliance maturity over time.
- Assist in monitoring and reporting on the effectiveness of cybersecurity governance controls and processes.
- Contribute to governance maturity assessments and improvement initiatives.
- Support internal and external audit activities through evidence gathering and reporting.
- Develop and maintain governance performance analytics to measure progress against cybersecurity governance objectives.
- Deliver analytical reporting and insights to support informed decision-making by management and governance stakeholders.
- Monitor developments in cybersecurity regulations and standards and support impact assessments.
- Identify opportunities to improve reporting methodologies, data quality, and governance intelligence capabilities.
- Provide recommendations based on data analysis to support continuous improvement initiatives.
- Collaborate with cybersecurity, risk, compliance, audit, and business teams for consistent data collection, validation, and reporting.
- Support governance forums, management reviews, and reporting cycles.
- Promote a data-driven governance culture through effective reporting, visualization, and performance measurement practices.
- Support stakeholders by providing governance insights, performance metrics, and reporting guidance.
- Contribute to improving governance processes, reporting standards, and operational effectiveness.
Krav
- 3-5 years of professional experience in Cybersecurity Governance, Risk & Compliance (GRC), Cybersecurity Operations, Risk Management, Compliance, Data Analytics, or related disciplines.
- Experience developing management reports, dashboards, KPIs, and performance measurements.
- Strong analytical skills with the ability to identify trends, risks, gaps, and opportunities from complex datasets.
- Experience collecting, validating, analyzing, and presenting data from multiple sources using reporting and visualization tools.
- Familiarity with cybersecurity and governance frameworks such as ISO 27001, NIST CSF, NIS2, DORA, or equivalent standards.
- Experience supporting governance reviews, compliance monitoring, audits, assessments, or continuous improvement initiatives.
- Ability to communicate technical, risk, and governance topics clearly to both technical and non-technical audiences.
- Strong collaboration and stakeholder management skills.
- Excellent written communication, reporting, and presentation capabilities.
Önskade kvalifikationer
- Experience working within large international organizations.
- Experience with reporting and visualization tools such as Power BI, Tableau, or similar platforms.
- Understanding of cybersecurity governance, risk management, and compliance processes.
- ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or other relevant cybersecurity/GRC certifications, or willingness to pursue professional certification.
Förmåner
- A strategic role driving data-driven cybersecurity governance across a global organization.
- Exposure to executive leadership, governance forums, and regulatory initiatives.
- Opportunities to shape governance intelligence, reporting capabilities, and performance measurement practices.
- Professional development opportunities within one of the organization's key cybersecurity and governance functions.
#IT#Cybersecurity#Risk Management#Compliance#Data Analytics#Governance