Senior Business and System Analyst
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · Verksamhetsanalys · IT-support
I korthet
We are seeking a Senior Information Risk and Compliance Officer in Södertälje to lead ISMS governance, risk management, and compliance within Production & Logistics. This full-time, on-site role involves developing and improving security processes, documentation, and collaborating with various stakeholders.
Ansvarsområden
- Governance and continuous improvement of the ISMS within Production & Logistics
- Implementation of ISMS requirements and ways of working
- IRAM assessments and related follow-up activities
- Information security governance, processes and coordination
- Preparation and maintenance of security-related documentation, reports and presentations
- Review, rewriting and improvement of shopfloor IT procedures and guidelines
- Collaboration with stakeholders across PRUs, P&L IT (IN), Maintenance and Logistics
- Leadership and coordination of the network of Local Information Security Officers (LISOs)
- Support to stakeholders in understanding and addressing information security and compliance requirements
- Assessment of the implications of the Cyber Resilience Act (CRA) for Production & Logistics
- Quality assurance of structured, consistent and ISMS-aligned governance documentation
Krav
- Experience within information security, cybersecurity support, risk management or compliance
- Experience of information security governance, risk and compliance activities
- Experience of supporting or implementing structured security processes and ways of working
- Experience of conducting or supporting risk assessments and follow-up activities
- Experience of supporting governance processes, documentation activities and coordination of security-related work
- Relevant academic degree or equivalent professional experience within information security, cybersecurity, risk management, compliance or related field
- Fluent Swedish and English, both spoken and written
- Strong ability to produce professional documentation and deliverables in English
- Ability to develop, review and improve security-related procedures, guidelines and documentation
- Ability to translate complex security and compliance requirements into clear, practical documentation
- Strong documentation and analytical skills, with ability to structure complex information clearly
- Strong stakeholder management and communication skills, towards both technical and operational stakeholders
- Ability to coordinate activities across multiple stakeholders, functions and organisational areas
- Structured, detail-oriented and quality-focused
- Proactive and solution-oriented, with ownership of your own activities
- Ability to independently structure, prioritise and drive assigned activities, including several parallel activities
Önskade kvalifikationer
- ISO 27000 certification and/or practical experience of ISO 27001 frameworks
- Knowledge of the Cyber Resilience Act (CRA) and NIS2
- Experience of Cybersecurity Management Systems (CSMS)
- Experience from industrial, production or manufacturing environments
- Experience of IT/OT environments
Förmåner
- Opportunity to work at leading companies within industry, manufacturing and logistics
- Contribute to strengthening security processes
- Part of a consultant team that values people first
- Success is created through commitment, collaboration and development
- Flat organisation with short decision paths
- Strong sense of community
- Opportunity to influence your own development
#Information Security#Risk Management#Compliance#ISMS#Cyber Resilience Act#NIS2#ISO 27000#IT/OT#Sweden#Södertälje