
INCYDE · Berlin/Darmstadt/Leipzig/München/Wien
DIESE AUFGABEN ERWARTEN DICH Als IT/OT-Security (Junior) Expert (m/w/d) erwarten Dich spannende und abwechslungsreiche Aufgabenfelder in der Entwicklung zukünf...
Als IT/OT-Security (Junior) Expert (m/w/d) erwarten Dich spannende und abwechslungsreiche Aufgabenfelder in der Entwicklung
zukünftiger und der Absicherung bestehender Industriesysteme. Du bist Experte in übergreifenden Cyber-Security Themen und
Raum.
unserer Kunden identifizierst und die Risiken bewertest.
Industriesystems weiter zu verbessern.
Strategie, Architektur und Umsetzung von IT-Security.
Projektumsetzung verantwortlich.
zu gestalten.
etc.) oder eine vergleichbare Ausbildung war der Grundstein für Deinen Start ins Berufsleben.
Industriesysteme sammeln.
Kunden.
auf externen Weiterbildungen kannst Du Dein Knowhow erweitern und Deine persönliche Weiterentwicklung vorantreiben.
We’re looking for a hands-on Smart Factory Architect who can design and drive delivery of edge-to-cloud industrial data & application architectures across global manufacturing sites. You’ll bridge OT systems (PLC/SCADA/DCS/MES/Historians) with cloud services (Azure/AWS/Snowflake, etc.), ensuring ISA-95 interoperability, robust cybersecurity (Zero Trust), and reliable data flows for use cases like performance analytics, predictive maintenance, and digital twins. You’ll operate as a technical leader who can review architecture, validate implementation plans, unblock delivery, and communicate clearly across engineering, OT, security, networking, and site stakeholders. ________________________________________ Key responsibilities Architecture & technical leadership • Act as the technical expert for Smart Factory / Edge architectures in a multi-site, multi-stakeholder environment. • Review architectural designs (edge, network, cloud, security, data models) and confirm the feasibility of implementation plans. • Align with Cloud Engineers and OT consultants to ensure ISA-95 compliant IT/OT integration and interoperability across layers (L0–L4/5). • Validate that all required services are deployed and configured correctly (cloud resources, edge runtime, connectivity, identity, monitoring). Edge-to-cloud integration & data flow validation • Define and validate edge-to-cloud data flow requirements, including: o Tag list/signals, payload schemas/formats, naming conventions o Frequency, buffering, store-and-forward, latency/availability targets o Data quality rules (units, timestamps, limits, gaps, duplicates) o Create logical & conceptual models for contextualization • Validate conceptual and logical modelling of the factory asset hierarchy (site/area/line/cell/equipment/component) and mapping to data streams. • Support the implementation of industrial connectivity patterns (e.g., OPC UA, MQTT, Modbus, REST) and integration with OT data sources (historians, SCADA, MES, CMMS, LIMS when relevant). Cloud & platform enablement (Azure/AWS/Snowflake) • Drive architecture decisions for ingestion, storage, and analytics using services such as: o Azure (IoT Hub, Event Hubs, Functions, AKS, Data Lake, Databricks/Synapse, Monitor, Key Vault, Private Link) o AWS (IoT Core, Kinesis, Lambda, EKS, S3, Glue, CloudWatch, Secrets Manager, Greengrass) o Snowflake (ingestion patterns, data modeling, governance, performance considerations) • Ensure observability is in place: logging, metrics, tracing, alerting, and operational runbooks. Network, cybersecurity & site readiness • Coordinate with site IT/networking to ensure: o Connectivity readiness (routing, DNS, proxy, certificates) o Firewall rules, ports, and secure connectivity patterns (VPN/ExpressRoute/Direct Connect where applicable) • Ensure alignment with factory cybersecurity and Zero Trust principles, including segmentation, least privilege, secure remote access, and auditability. Testing, go-live, and operational stabilization • Own the go-live checklist and drive issue resolution during integration testing and cutover. • Support test data ingestion and end-to-end validation, from OT signal extraction through cloud ingestion, storage, and consumption. • Validate performance and reliability requirements (throughput, latency, resilience, recovery) and ensure operational handover readiness. Digital Twin & OT platforms • Contribute to Digital Twin concepts built on IT/OT convergence (asset hierarchy + telemetry + context). • Work hands-on with OT / Smart Factory platforms such as AVEVA, Sight Machine, and/or similar (e.g., Ignition, OSIsoft/PI, Tulip, PTC ThingWorx, depending on environment). ________________________________________ Required qualifications & experience • 7+ years of experience in industrial IT/OT, smart factory, or manufacturing digitalization roles, with architect-level ownership of designs and deployments. • Proven hands-on delivery experience implementing edge-to-cloud integration in real factory environments. • Strong understanding of: o ISA-95 (integration patterns and manufacturing system layers) o Industrial architectures (OT network segmentation, DMZ patterns, edge gateways) o Core OT systems (PLC/SCADA/DCS, historian, MES) and data acquisition methods • Cloud architecture experience on Azure and/or AWS (plus familiarity with Snowflake, databricks and modern data platforms). • Solid fundamentals in networking (firewalls, VLANs, routing, certificates, proxies) and troubleshooting in restricted environments. • knowledge of identity and access management (Azure AD/RBAC/Managed Identities or AWS IAM, secrets, key management). • Excellent communication skills, able to lead technical conversations with security, IT, OT, and business stakeholders globally. ________________________________________ Technical skill set (must-have) • Edge/IIoT protocols & patterns: OPC UA, MQTT, REST APIs, store-and-forward, buffering, offline resilience • Data engineering basics: schema design, time-series concepts, streaming ingestion, partitioning, data quality checks • Cloud security: least privilege, private networking, key management, audit/logging, policy enforcement • Operational readiness: integration test planning, go-live governance, incident triage and structured problem-solving ________________________________________ Preferred / nice-to-have • Knowledge of IEC 62443 / OT security frameworks and industrial zero trust patterns. • Experience with Kubernetes at edge/cloud (AKS/EKS), IaC (Terraform/Bicep/CloudFormation), and CI/CD. • Experience with industrial historians and time-series stacks (e.g., AVEVA/PI-like patterns). • Familiarity with data governance (catalog, lineage, access policies) and regulated environments. • Experience building or operationalizing Digital Twin solutions (asset model + context + telemetry). ________________________________________
Are you an Information Security specialist? Are you ready to take on an overall responsibility and drive the IS area in a global business? Join us as our new CISO! As our world changes, Information & Cyber Security are becoming increasingly important for a company such as Westermo. We have long been known for robust hardware, and increasingly so also for Cyber Security features in our software. Information Security at Westermo is not, and should not be an isolated IT function. It is fundamental to trusted products, resilient operations, and long‑term customer confidence. We are now looking for a Global Chief Information Security Officer (CISO) to define, lead, and govern our global cyber security agenda across the entire global organization. This is a diverse role, with operational and strategic aspects. Governance, risk management, and operational resilience are key focus areas. In this global role, you will work across all levels; from the executive management team, our leaders, and key functions across Westermo’s global operations. You will collaborate with IT, R&D, Manufacturing, Operations & Quality to ensure information security is embedded into decision‑making, processes, and culture across the company. Are you our next Global Chief Information Security Officer (CISO)? As Global CISO, you oversee all Information Security related issues. You are the domain expert, the advisor and coordinator. You make sure that Westermo follows IS laws, directives, standards and also set up our own strategy, policies and guidelines. You lead the work and influence people in all departments, making sure we have the right routines, trainings, risk assessments and pass our audits. You will not be starting from a clean slate, but there will be large opportunities to challenge current state and shape the future. Key Responsibilities Advise on identification, assessment, and prioritization of cyber risks across Westermo Provide direction and governance for the Information Security Management System (ISMS) in accordance with ISO 27001, including audits and scope expansion across Westermo companies Support compliance with applicable cyber security regulations and standards (e.g. ISO 27001, IEC 62443, NIS2, customer security requirements) Provide oversight and advisory input on third‑party and supply‑chain cyber security risks Create awareness, teach and train others in the organization. Report regularly to executive management on cyber security posture, risks, incidents, and initiatives Who Are We Looking For? We are looking for someone who has experience in Information Security. You might be an expert in one area of Information Security, but you are looking for a wider role. Or you are already working with broad topics, but are looking for more responsibility, and the opportunity to make your own mark on a role and organization. You like it in a medium sized company; where there’s room for influence, and not hierarchical and bureaucratic. You appreciate having different kinds of competence around you, and are comfortable being the expert in your own area. You can speak to all of your stakeholders, and meet them where they are; from executive management to customers and employees. You are also comfortable in a global company; English is not a problem for you, and you understand there will be differences between countries, even if you don’t know exactly what they are. In short; you are an Information Security Specialist who wants to get in the driver’s seat, with your supporters in the seats next to you. Requirements You are familiar with ISO 27001 and NIS2. Strong knowledge of both IT security and OT/ICS security in industrial environments Great communication skills, being able to teach and train others, but also learn from other specialists in the organization. Proven experience with Information Security governance, risk management, and incident response Meritorious Background from industrial, manufacturing, R&D, or mission‑critical system environments Relevant certifications (e.g. CISSP, CISM, or equivalent) Interest or experience in digital transformation and data governance In Return, We Offer: You will be working at the forefront of technology in a friendly, open culture where you get the opportunity to learn from skilled colleagues every day. A mature and caring leadership in a flat organization. Through our collective agreement you will be covered in terms of insurance, pension and other benefits. We like to have fun together and we regularly enjoy sports and other social activities as a team. We believe that magic happens when people meet. We are a learning organization and we truly love to try new things, think outside the box and be innovative together! Basic Information Location: Västerås, Sweden (preferred) or other Westermo locations Job type: Full‑time Employment contract: Permanent Application: We review applications continuously — apply as soon as possible Contact: Hiring Manager: Johan Inestam, CFO, at johan.inestam@westermo.com Recruiter: Elin Sandell, at elin.sandell@westermo.com About Westermo Westermo is a leading provider of Industrial Data Communications equipment to the global market. Sales are conducted through our own offices in key markets in Europe, North America, Australia and Asia, as well as through distributors and OEM customers worldwide. Development and manufacturing take place in Sweden, Ireland, Germany and Switzerland. Westermo was founded in 1975 and today has over 480 employees with a turnover of around 1 Billion SEK. The company is a wholly owned subsidiary of Ependion, listed on the Nasdaq OMX Nordic stock exchange.
Om tjänsten Som SIEM Expert ansvarar du för drift, förvaltning och utveckling av Svenska kraftnäts SIEM-lösning för säkerhetsövervakning. Du bidrar till att stärka säkerheten i en av Sveriges mest samhällskritiska verksamheter genom att utveckla och förbättra säkerhetsövervakningen i en komplex IT- och OT-miljö. Du driftar och underhåller säkerhetsövervakningsplattformen Splunk och arbetar nära plattformens användare inom Security Operations Center (SOC) samt IT-driftsorganisationen. I uppdraget ingår bland annat konfiguration och förvaltning av Splunk-kluster, Linux-administration samt utveckling av innehåll i plattformen. Tjänsten innebär bland annat att: Drifta, förvalta och utveckla Svenska kraftnäts SIEM-lösning för säkerhetsövervakning. Utveckla nya funktioner i SIEM-lösningen. Utveckla och förvalta datamodeller i SIEM-plattformen. Tillgodose SOC-analytikernas behov genom en nära dialog och ett tätt samarbete. Utföra drift- och förvaltningsåtgärder i SIEM-systemet. Arbeta tillsammans med IT-drift för att ansluta nya IT-system till SIEM-plattformen. Vara en del av Svenska kraftnäts team för att hantera IT-säkerhetsincidenter.Som IT-säkerhetsspecialist Hos oss får du möjlighet att utvecklas inom IT-säkerhet i en verksamhet med höga säkerhetskrav. Rollen erbjuder stora möjligheter till personlig utveckling och kontinuerlig kompetensutveckling. Du får arbeta tillsammans med erfarna kollegor, dela kunskap både internt och med externa samarbetspartners inom branschen och myndighetsvärlden samt bidra till den fortsatta utvecklingen av Svenska kraftnäts säkerhetsövervakning. Du är placerad på enheten Operativ IT-säkerhet, som är en del av IT-säkerhetsavdelningen. Här arbetar du i ett team med omkring 20 tekniska IT-säkerhetsspecialister som tillsammans ansvarar för att upprätthålla, utveckla och förbättra Svenska kraftnäts säkerhetsplattform. Du arbetar med system som spänner över både IT- och OT-miljöer i en samhällskritisk verksamhet. Om dig Skallkrav: Personliga egenskaper: Vi söker dig som är samarbetsorienterad, analytisk, strukturerad och lösningsorienterad. Du trivs med att samarbeta med andra och har ett strukturerat arbetssätt som hjälper dig att analysera komplexa tekniska miljöer och hitta hållbara lösningar. Du ska också leva upp till https://www.statskontoret.se/forvaltningskultur/den-statliga-vardegrunden/ I denna rekrytering lägger vi stor vikt vid dina personliga egenskaper. Utbildning: Du har en akademisk utbildning inom IT eller motsvarande kompetens förvärvad på annat sätt som Svenska kraftnät bedömer likvärdig. Du har även: God erfarenhet av implementation/drift av SIEM-lösningar (minst 1 års arbetslivserfarenhet) Erfarenhet av arbete med distribuerade lösningar (t.ex. klusterlösningar, insamlare, indexerare, GUI) Kunskap inom regular expressions och scripting inom t.ex Python, Bash, PowerShell God erfarenhet av att arbeta i Linux (RHEL/CentOS) God erfarenhet av att förvalta system m.h.a. automationsspråk (t.ex. ansible) God förmåga att uttrycka dig i tal och skrift på svenska och engelska Meriterande God erfarenhet av data onboarding av diverse system/produkter och av normalisering av data Erfarenhet av att bygga avancerade larm, rapporter och visualiseringar Erfarenhet av arbete inom SOC (Security Operations Center) Erfarenhet av SPLUNK och SPLUNK Enterprise Security Relevanta utbildningar och certifieringar på SIEM lösningar Erfarenhet av säkerhetsarbete i ICS- och SCADA-system Erfarenhet av IT- och informations-säkerhetsarbete i större organisationer Bra att veta Tjänsten är placerad i Stockholm / Sundbyberg. Möjlighet till distansarbete upp till 50 % #LI-hybrid. Sista ansökningsdag är den 9 september 2026. Vi använder urvalsfrågor istället för personligt brev. Vänligen bifoga ditt CV på svenska där du tydligt beskriver den erfarenhet som vi söker. Tjänsten är en tillsvidaretjänst. https://www.svk.se/jobba-har/var-arbetsplats/formaner/ I den här rekryteringen samarbetar vi med Experis. Vill du veta mer, kontakta gärna rekryteringskonsult Carina Eyoma, tel. nr. 0730862275 eller via e-post: carina.eyoma@se.experis.com. Med anledning av semestertider kan svarstiderna vara något längre än vanligt. Kontakter på Svenska kraftnät: Carl Isaksson, rekryteringsspecialist, 010 489 20 28 Annika Ingeborn, SACO, 010 475 87 72 Erica Midfjäll, ST, 010 475 87 31 Du når oss också via e-post: fornamn.efternamn@svk.se https://www.svk.se/jobba-har/ Vi undanber oss direktkontakt med bemannings- och rekryteringsföretag samt säljare i samband med rekrytering, vi har upphandlade avtal som gäller för Svenska kraftnät som statlig myndighet. Övrig information Vi ställer höga krav på våra medarbetares säkerhets- och sekretess-medvetenhet. Inför anställning genomförs säkerhetsprövning enligt säkerhetsskyddslagen (2018:585) vilket innefattar grundutredning och om anställningen avser befattning i säkerhetsklass kommer säkerhetsprövningen även att innefatta en registerkontroll. För anställning på Svenska kraftnät kan det vara ett krav på svenskt medborgarskap i vissa befattningar. Med anställningen följer en skyldighet att krigsplaceras. För mer information om personalsäkerhet på svenska kraftnät. https://www.svk.se/sakerhet-och-beredskap/sakerhetsskydd/personalsakerhet