IT Security & Risk Officer
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · IT-support
I korthet
As an IT Security & Risk Officer - Associate at Volvo Group in Wroclaw, you will be responsible for shaping IT security and risk management. You will advise on security requirements, identify vulnerabilities, and implement mitigations within a global enterprise environment. The role requires collaboration with various teams to ensure robust security measures and adherence to industry standards.
Ansvarsområden
- Drive strategic and tactical IT security direction.
- Assess risks, identify vulnerabilities, evaluate impact, and recommend mitigations.
- Advise on solution design and review solution blueprints.
- Develop, update, and enforce security policies, procedures, and guidelines.
- Perform gap analyses against frameworks such as ISO, ISF, CSA, NIST, etc.
- Identify, assess, and implement IT/OT security controls across projects and organizations.
- Collaborate with stakeholders in a multicultural environment.
- Act as a trusted advisor on security best practices.
- Monitor framework effectiveness and recommend improvements based on emerging threats.
- Ensure adherence to information protection laws and regulations.
- Review the coverage and effectiveness of IT and OT security controls.
- Stay current on IT security trends and advancements.
Krav
- Broad IT Security experience and understanding of challenges facing large enterprises.
- Strong stakeholder management and ability to build trusted relationships.
- Strong critical thinking and analytical skills.
- Experience driving change and influencing others.
- Excellent communication and presentation skills.
- Adaptability and resilience in a changing security landscape.
- Strong listening, collaboration, and teamwork skills.
- Curiosity and enthusiasm for innovation and continuous improvement.
- Knowledge of cybersecurity frameworks such as ISF, CSA, NIST, SCF, ISO 27x, OWASP, etc.
- Experience with Microsoft Azure services and cloud-based applications.
- Understanding of least privilege and Zero Trust in distributed IT/OT environments.
- Knowledge of on-premise and cloud network security technologies.
- Understanding of on-premises, multicloud, and hybrid interconnecting solutions.
- Experience with AppSec and SDLC practices such as DevSecOps, SAST, SCA, DAST, and container security.
- Knowledge of cloud security, container security, API security, Infrastructure as Code, and IAM technologies.
- Security certification such as ISC2 CC/SSCP, CompTIA Security+, Microsoft Azure AZ-900/AZ-500, or similar.
Önskade kvalifikationer
- Practical experience with threat modelling using standards such as STRIDE, MITRE, OWASP, etc.
- Familiarity with AI development frameworks, model providers, open-source models, or model evaluation platforms.
Förmåner
- Flexibility is possible and discussed with the manager based on business and role needs.
- Opportunity to work with next-gen technologies and collaborative teams.
- Opportunity to make a difference on a global scale.
#IT Security#Risk Management#Cybersecurity#Information Protection#Cloud Security#DevOps