
IST Group AB · Stockholm
Do you want to help shape information security across one of Scandinavia's leading EdTech companies? At IST, we develop digital solutions that support education...
Do you want to help shape information security across one of Scandinavia's leading EdTech companies?
At IST, we develop digital solutions that support education and learning for millions of users across Scandinavia. As Information Security Manager, you will play a key role in protecting our information assets, driving compliance initiatives, and strengthening our security culture across the entire IST Group.
While the role has a strong focus on our Danish operations and product portfolio, you will work on a Group level, collaborating with colleagues and stakeholders across multiple countries and business areas.
This is an opportunity for someone who wants to combine strategic security leadership with hands-on security governance in a company with a meaningful societal mission. The role serves as an important bridge between customers, operations, development, and management when security-related issues occur.
About the role
As Information Security Manager, you will be responsible for developing, implementing, and maintaining IST's information security framework. You will work closely with product and development departments, customers, auditors, and external stakeholders to ensure that security is embedded throughout the business.
You will act as a trusted advisor on information security matters, supporting both operational and strategic initiatives while continuously improving our security posture.
Develop and maintain information security policies, standards, and procedures across the Group.
Lead and coordinate information security governance activities.
Drive compliance with relevant regulations and frameworks, including GDPR, NIS2, ISO 27001, ISAE 3000, and related requirements.
Manage and coordinate security incidents, investigations, and corrective actions.
Conduct risk assessments and support enterprise risk management activities.
Collaborate with product development teams to embed privacy and security by design.
Support audits, security reviews, and due diligence processes.
Manage and maintain data processing agreements and security-related documentation.
Drive security awareness initiatives and promote a strong security culture throughout the organization.
Prepare reports and security metrics for management and key stakeholders.
Your profile
We believe you have the following competence profile to succeed in this role:
A Bachelor’s degree within Information Security, Computer Science, IT, Law, Business, or a related field.
Experience working with information security, cybersecurity, risk management and/or compliance.
Experience with GDPR and information security governance, ISO 27001, NIS2, ISAE 3000, SOC reporting, or similar frameworks.
Experience supporting audits, inspections, or compliance reviews.
The ability to communicate complex security topics to both technical and non-technical audiences.
Strong stakeholder management and collaboration skills.
A proactive, self-driven, and structured working style.
Relevant certifications such as ISO 27001, CISSP, CISM, CRISC, or similar are considered an advantage.
Why join IST?
At IST, you will become part of a company that has been developing digital solutions for the education sector for more than 40 years. We are approximately 400 employees across several countries, united by the ambition to create better opportunities for learning and education.
A meaningful role with significant influence on the Group's security agenda.
The opportunity to work across multiple countries, products, and business areas.
A collaborative and supportive international environment.
Professional and personal development opportunities.
A strong culture characterized by trust, openness, and teamwork.
This is a full-time, permanent position. At IST, we apply an office-first policy, meaning we primarily work from the office as we believe physical presence fosters collaboration, innovation, and a strong team spirit. At the same time, we understand the importance of flexibility—if you live farther away, working from the office three days a week with the remaining time remote may be possible. In Scandinavia our offices are located in Stockholm, Växjö, Roskilde and Oslo.
Apply
Applications are reviewed continuously. For questions, contact Nanna Holm Thyboe, +45 20 72 60 34 or email: nanna.thyboe@ist.com
For questions about the recruitment process, contact hr@ist.com
Please note! Background check is part of the recruitment process.
Welcome to apply!
Join our diverse teams of passionate people and a career that allows you to develop both personally and professionally. At Getinge we exist to make life saving technology accessible for more people. To make a true difference for our customers – and to save more lives, we need team players, forward thinkers, and game changers. Are you looking for an inspiring career? You just found it. About this opportunity In this role, you will be part of Getinge’s cybersecurity organization, working across IT and the business to drive cybersecurity governance, cyber risk prioritization, and security program execution. The position plays a key role in ensuring that cybersecurity strategy, regulatory requirements, and management decisions are translated into measurable and delivered outcomes. What you will do In this role, you will be responsible for coordinating risk, compliance, and program activities to ensure cybersecurity initiatives are delivered effectively and aligned with business priorities. • Support cyber risk management by translating risk insights into prioritized actions and tracking mitigation progress across IT and business units • Own and drive the cybersecurity process and initiative portfolio, coordinating execution across Central IT, Business IT/OT, and corporate functions • Support execution of cybersecurity compliance obligations such as NIS2, ISO 27001, and internal audits • Act as the primary interface between cybersecurity, IT delivery teams, and business stakeholders to ensure requirements are clearly understood and realistically implemented • Define and maintain cybersecurity KPIs and provide structured reporting to the CISO and executive management This position is preferably based in Sweden either in Gothenburg, Stockholm or Getinge. It can be performed in a flexible hybrid setup, while maintaining regular collaboration with colleagues on site. You will bring To be successful in this position, we believe that you have the following qualifications. • Degree in Information Security, IT, Risk Management, or equivalent experience • Experience in cybersecurity governance, risk, compliance • Experience working in regulated environments (e.g. NIS2, ISO 27001, GDPR security) • Proven ability to drive execution across complex, federated organizations • Strong stakeholder management and communication skills You are structured and delivery-oriented, with strong coordination and influencing skills. You are comfortable working cross‑functionally and engaging with leadership, enabling progress in complex environments with multiple stakeholders. In addition to your technical skills, we highly value your personality. To be successful in this role we think you continuously seek new ideas to improve processes and materials and also work proactively to address challenges and opportunities. We also see that you are active in discussions and have an open communication with your different stakeholders. At Getinge we see ourselves as proactive and self-driven in learning and contributing to the continued development of our products and our organization's capabilities. We are Team Players, Forward Thinkers and Game Changers Why join Getinge Getinge offers a job in a safe and informal work environment, where we appreciate close team collaboration. We keep an open dialogue between leaders and employees, as well as between teams. We are focused on developing people, and together we will create a plan for learning and competence development when you start your career with us. We offer a competitive compensation and benefits package, including wellness allowances, generous family benefits, and joint company activities. Everything to ensure we support your well-being and goals. Application Applications will be reviewed continually, and we therefore recommend sending us your application as soon as possible, but no later than 2026-08-10. We kindly ask you to submit your application in our recruitment system by clicking the “apply now” button. Due to GDPR regulations, we do not accept applications via e-mail. We look forward to receiving your application. We exist to make life-saving technology accessible for more people. About us With a firm belief that every person and community should have access to the best possible care, Getinge provides hospitals and life science institutions with products and solutions aiming to improve clinical results and optimize workflows. The offering includes products and solutions for intensive care, cardiovascular procedures, operating rooms, sterile reprocessing and life science. Getinge employs over 12,000 people worldwide and the products are sold in more than 135 countries.
About the Role We are looking for a Security & Compliance Engineer to help ensure security across our internal digital landscape. Reporting to Tacton’s Security & Compliance Manager, you will play a key role in ensuring that our systems, integrations, data flows, and vendor ecosystem are secure by design and in operation. This role focuses on internal systems and corporate security architecture, including infrastructure, integrations, and third-party services. You will combine architectural thinking with hands-on expertise and act as a trusted partner to IT, Engineering, and business stakeholders. You will have a direct impact on how we design, connect, and secure our systems as we continue to grow globally. This is a high-impact role for someone who understands modern digital environments and how to secure them end-to-end. What You Will Do Internal Security & Risk Lead security assessments of systems, integrations, and data flows Conduct technical risk analyses for system implementations and vendor onboarding Perform threat modelling and security reviews Define and implement security requirements for infrastructure and cloud environments Help establish and maintain security guardrails across identity, access, encryption, and integrations Proficiency in risk management Knowledge of emerging cybersecurity threats and trends Vendor & Third-Party Security Define and enforce security requirements in procurement processes Conduct supplier security assessments and due diligence Evaluate third-party risks from a cybersecurity perspective Governance & Compliance Maintain alignment with ISO 27001 and SOC 2 Type II Contribute to policies, standards, and security guidelines Support incident investigations Act as a subject matter expert in audits and internal forums What Will Help You Thrive 5+ years of experience in cybersecurity, information security, or a related field Strong technical foundation in cloud, networking, identity & access management, and system integrations Strong communication and stakeholder management skills Experience conducting technical risk assessments and security reviews Familiarity with ISO 27001 and SOC 2 Type II Ability to understand complex system landscapes and data flows Comfortable working cross-functionally with IT, Engineering, and Legal Certifications such as CISSP, CISM, or CISA are a plus Degree in Computer Science, Engineering, or a related field Who We’re Looking For We’re looking for someone with a strong hands-on, doer mentality who is focused on getting things done and creating real impact. You are pragmatic, prestigeless, and motivated by outcomes. You thrive in dynamic environments where responsibilities are broad, and you feel comfortable navigating uncertainty and solving problems independently. You are curious by nature, proactive in your approach, and continuously looking to learn and improve both yourself and the way things are done. Why Tacton? At Tacton, we’ve been building CPQ software for over 20 years. We’re a stable company with global customers and a product that’s central to how manufacturers sell We offer competitive benefits, flexibility in how we work, and a culture that values learning and collaboration A solid and stable company with over 20 years of industry experience. Flexible hybrid setup - 3x a week at the office 33 days of paid time off – 30 vacation days plus 3 extra to make sure you get the rest you deserve. Premium occupational pension – Our pension plan goes beyond ITP1, with higher employer contributions depending on your age and salary level. Generous wellness allowance – 5,000 SEK annually to support your health and wellbeing. Private healthcare insurance – Skip the waiting lines and get quick access to private medical care, including specialist consultations and treatments. Parental leave top-up – We top up your parental leave so you receive up to 90% of your base salary for up to 6 months, helping you focus on your family without financial stress Weekly treats – Fika one week, breakfast the next, because good food brings people together. This role is based in Stockholm, where we have invested in creating our unique home right next to Hötorget station. Tacton is a leading Software as a Service company trusted by global manufacturers. We got started in the late 1990s when six computer scientists figured out a revolutionary way to help Manufacturers overcome their most business-critical, product configuration challenges. Since those early days, we have grown to support global manufacturers seeking to thrive in a changing world. We invite you to find out more about us @ www.tacton.com/about
ABOUT SINCH Sinch is pioneering the way the world communicates. More than 150,000 businesses — including Google, Uber, Paypal, Visa, Tinder, and many others — rely on Sinch’s Customer Communications Cloud to power engaging customer experiences through mobile messaging, voice, and email. Whether you need to verify users or craft omnichannel campaigns, Sinch makes it easy. Our AI-infused Super Network, APIs, and applications ensure you can connect with your customers reliably and securely, at every step of their journey. At Sinch we “Dream Big”, “Win Together”, “Keep it simple”, and “Make it Happen”. These values are our foundation! DESCRIPTION Sinch is on a multi-year journey to responsibly scale AI across Enterprise IT (EIT). We’re looking for a Specialist AI Technical Product Manager to take ownership of core AI capabilities as part of the EIT domain to ensure AI is safe, effective, and enterprise-ready. You’ll partner closely with our central AI Function (responsible for end-user experience, including agent configuration and design) and act as the bridge to Infrastructure, End-User Support, Security, and other IT teams. You’ll define, deliver, and continuously improve the technical products, integrations, and operating model that enable AI at scale. This role is based in Stockholm, Sweden (Hybrid) and reports to the VP, Business Operations EIT. What You’ll Do Own the AI Product Strategy: Define and manage the roadmap for enterprise AI capabilities, including connectors, LLM services, governance tools, and guardrails. Deliver Secure Integrations: Design and implement AI connectors for platforms like Microsoft 365, Slack, Jira, SAP, and data warehouses, ensuring performance and resilience. Build Knowledge Foundations: Set standards for data ingestion, classification, enrichment, and retention to power AI systems while protecting sensitive information. Drive AI Quality & Safety: Define success metrics, run A/B tests, and establish monitoring for drift, hallucinations, and compliance. Ensure Security & Compliance: Collaborate with Security, Legal, and Privacy teams to meet ISO 27001, SOC 2, and GDPR requirements; create incident response playbooks. Enable Adoption: Develop support playbooks, training programs, and clear roles across IT and business units to scale AI responsibly. REQUIREMENTS Education: Bachelor’s in Computer Science, Engineering, or related field (Master’s preferred). Experience: 3+ years in Product Management or Technical Program roles delivering AI/ML or data-driven products in enterprise environments. Security & Compliance: Strong grounding in data privacy, DLP, PII handling, and audit requirements. Ways of Working: Comfortable with Agile/Scrum; able to write clear PRDs and architecture diagrams. Soft Skills: Excellent communication and stakeholder management; proven ability to influence and lead change. Nice to Have: ITIL v4 and cloud certifications. Technical Expertise: Hands-on with LLMs and platforms like OpenAI, Anthropic, Azure OpenAI, AWS Bedrock (Google Agentspace is a plus). Familiarity with RAG architectures, embeddings, prompt management, and evaluation frameworks. Experience building secure APIs/connectors (REST/GraphQL) and working with cloud platforms (AWS, Azure, GCP). Knowledge of enterprise IT systems (Microsoft 365, Jira, Slack) and identity/access management (Azure AD, Okta). Our corporate language is English, please submit your application in English. Must currently reside in and be eligible for employment in Stockholm, Sweden. Relocation and visa sponsorship are not available for this role OUR HIRING PROCESS We are committed to ensuring a recruitment process that is fair, objective, consistent, and inclusive. Our approach includes structured, competency-based interviews designed to evaluate your skills, experience, and qualifications relevant to the role. At times, we may include a data-driven assessment to enhance our hiring success and identify candidates likely to excel. We believe in a two-way process and encourage you to ask questions throughout the journey. If this role isn't what you're looking for, please explore the other opportunities listed on our career page: https://www.sinch.com/careers/. No matter who you are, we hope you find an exciting path forward - hopefully with us!