
Professional Galaxy AB · Stockholm
Build the Future of Technology with Professional Galaxy AB Join a network of talented engineers, developers, cloud specialists, and AI innovators working on imp...
Build the Future of Technology with Professional Galaxy AB
Join a network of talented engineers, developers, cloud specialists, and AI innovators working on impactful projects across Sweden and Europe. At Professional Galaxy AB, we connect top tech talent with organizations driving digital transformation in areas like cloud computing, software engineering, data, cybersecurity, and artificial intelligence.
Explore exciting opportunities and grow your career while working with cutting-edge technologies and forward-thinking teams.
We are looking for a Cyber Security Advisor
Act as a trusted advisor to management and key stakeholders, ensuring cybersecurity considerations are integrated into decision-making
Ensure cybersecurity best practices align with business objectives and delivery goals without hindering operational efficiency
Provide cybersecurity expertise during projects and engagements to mitigate risks and enhance security controls
Work with cross-functional teams to enhance the organization’s overall cybersecurity resilience
Identify, assess, and provide guidance on mitigating cybersecurity risks across business functions
Support compliance with relevant cybersecurity laws, regulations, and industry standards
Contribute to the development and implementation of security strategies, policies, and frameworks
Promote cybersecurity awareness and best practices among employees and stakeholders
Typically 10+ years of experience in cybersecurity, information security, IT governance, risk management, or compliance
Bachelor’s degree in Computer Science or related field (or equivalent experience)
Proven leadership in security governance frameworks, policies, and strategies
Experience aligning security and data privacy with business objectives at a strategic level
Hands-on experience with enterprise risk management and compliance frameworks (e.g., GDPR, ISO 27001, NIST, PCI DSS)
Strong expertise in third-party/vendor risk management
Experience in security incident response and crisis management
Ability to influence senior leadership and board-level stakeholders
Strong communication skills and stakeholder management
Business understanding with security impact awareness
Ability to analyze and mitigate security risks
Certifications such as CISSP, CIPM, CISA, ISO/IEC 27001 Lead Auditor
Specializations such as AI Governance, Cloud Security, or CIPP/E
Uppdragslängd: 2026-05-04 – 2026-09-30 Placeringsort: Stockholm
Svar önskas snarast, dock senast 2026-05-03.
Your updated CV
Your availability to start
A motivation statement describing your suitability
Please note: Applications via email will not be accepted. All applications must be submitted through the portal.
Öppen för alla
Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.
Job Description Join our Cyber Security Engineering unit, where innovation and security drive us. We are transforming technology with modern Network Security, integrations and cloud services. We are looking for a highly skilled and experienced Senior Cyber Security Engineer to join our Network Security Engineering team. This role involves architecting, designing, implementing, and maintaining robust security measures to protect our global network infrastructure. The ideal candidate will blend theoretical knowledge with hands-on expertise. This role requires a deep understanding of cybersecurity principles, Network Security technologies, and the ability to collaborate across multiple globally dispersed stakeholders and teams. WHAT YOU’LL DO Lead the development, optimization and integration of network security policies, rules and monitoring across platforms such as NDR, SSE, SD‑WAN and proxy solutions Design and improve network security solutions across branches, stores and data centers, ensuring strong alignment with business and security needs Conduct security architecture reviews, risk assessments and threat modelling, and drive hardening initiatives across our network landscape Modernize network security by transitioning from legacy systems to modern SSE and ZTNA solutions, supported by clear roadmaps, policies and plans Monitor and enhance the performance, availability and reliability of network security solutions, ensuring compliance with ISO, NIST, GDPR and internal standards Design, configure and troubleshoot network security devices and services across on‑prem and cloud environments, providing advanced Level‑3 support when needed WHO YOU'LL WORK WITH You’ll join a friendly and collaborative Network Security Engineering team of seven, soon to be eight, working closely with colleagues across Business Tech. Your daily partners will include network SMEs, Cyber Security Advisors, Core Platforms and Global Infrastructure Services, as well as teams supporting stores, warehouses and new market entries. You’ll also connect with external partners and contribute to cross‑functional projects where network and cyber security come together. This is a highly collaborative environment where your expertise will help shape our security posture and uplift the team’s cyber maturity. WHO YOU ARE 6+ years of experience in cybersecurity engineering, with a focus on network environments Strong, practical knowledge of: Network security technologies (firewalls, IDS/IPS, SWG, SASE, VPN, CASB, ZTNA), Cloud platforms: Azure, GCP, Security architecture methodologies and governance frameworks Expertise in network security solutions and products provided by Cisco, HP Aruba, Zscaler and Citrix NetScaler (proven by certificates) Strong knowledge of risk assessment and security control frameworks (ISO 27001, NIST). Familiarity with security maturity models including C2M2 Excellent ability to translate security requirements into implementable engineering solutions. Strong understanding of IP networking and protocols, including IPsec, HSRP, BGP, OSPF, 802.11, and QoS. Understand regulatory and compliance requirements (GDPR, PCI-DSS, Schrems, etc.). Independent problem-solving, addressing complex security challenges with minimal supervision. Preferred qualifications: CCNP (Security) or higher-level certifications such as the CCIE. CISSP or OSCP security certifications. Azure Security Engineer, or GCP Security Engineer certification. Experience with Agile methodologies and tools (e.g., Jira/Confluence) WHO WE ARE H&M is a fashion brand that offers the latest styles and inspiration, from fashion pieces and unique designer collaborations to affordable wardrobe essentials. Our business idea is fashion & quality at the best price in a sustainable way. Learn more about H&M here. WHY YOU’LL LOVE WORKING HERE Benefits All our employees are included in our H&M Incentive Program (HIP) All our employees receive a staff discount card, which is usable on all our H&M Group brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET. Work-life balance, 30 days’ vacation and wellness allowance 4000 SEK/yearly Access to Benify, for discounts on e.g. Gym memberships, travel, hotels and many other great deals. Compensation boost during parental leave In addition to our global benefits, all our local markets offer different competitive perks and benefits. Please note that they may differ between employment type and countries. Inclusion & Diversity H&M is a part of H&M Group. At H&M Group, we’re determined to create and maintain inclusive, diverse and equitable workplaces throughout our organization. Our teams should consist of a variety of people that share and combine their knowledge, experience and ideas. Having a diverse workforce leads to a positive impact on how we address challenges, on what we perceive possible and on how we choose to relate to our colleagues and customers all over the world. Hence all diversity dimensions are taken into consideration in our recruitment process. We are committed to a recruitment process that is fair, equitable, and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
Job Description Join our Cyber Security Engineering unit, where innovation and security drive us. We are transforming technology with modern Network Security, integrations and cloud services. We are looking for a highly skilled and experienced Senior Cyber Security Engineer to join our Network Security Engineering team. This role involves architecting, designing, implementing, and maintaining robust security measures to protect our global network infrastructure. The ideal candidate will blend theoretical knowledge with hands-on expertise. This role requires a deep understanding of cybersecurity principles, Network Security technologies, and the ability to collaborate across multiple globally dispersed stakeholders and teams. WHAT YOU’LL DO Lead the development, optimization and integration of network security policies, rules and monitoring across platforms such as NDR, SSE, SD‑WAN and proxy solutions Design and improve network security solutions across branches, stores and data centers, ensuring strong alignment with business and security needs Conduct security architecture reviews, risk assessments and threat modelling, and drive hardening initiatives across our network landscape Modernize network security by transitioning from legacy systems to modern SSE and ZTNA solutions, supported by clear roadmaps, policies and plans Monitor and enhance the performance, availability and reliability of network security solutions, ensuring compliance with ISO, NIST, GDPR and internal standards Design, configure and troubleshoot network security devices and services across on‑prem and cloud environments, providing advanced Level‑3 support when needed WHO YOU'LL WORK WITH You’ll join a friendly and collaborative Network Security Engineering team of seven, soon to be eight, working closely with colleagues across Business Tech. Your daily partners will include network SMEs, Cyber Security Advisors, Core Platforms and Global Infrastructure Services, as well as teams supporting stores, warehouses and new market entries. You’ll also connect with external partners and contribute to cross‑functional projects where network and cyber security come together. This is a highly collaborative environment where your expertise will help shape our security posture and uplift the team’s cyber maturity. WHO YOU ARE 6+ years of experience in cybersecurity engineering, with a focus on network environments Strong, practical knowledge of: Network security technologies (firewalls, IDS/IPS, SWG, SASE, VPN, CASB, ZTNA), Cloud platforms: Azure, GCP, Security architecture methodologies and governance frameworks Expertise in network security solutions and products provided by Cisco, HP Aruba, Zscaler and Citrix NetScaler (proven by certificates) Strong knowledge of risk assessment and security control frameworks (ISO 27001, NIST). Familiarity with security maturity models including C2M2 Excellent ability to translate security requirements into implementable engineering solutions. Strong understanding of IP networking and protocols, including IPsec, HSRP, BGP, OSPF, 802.11, and QoS. Understand regulatory and compliance requirements (GDPR, PCI-DSS, Schrems, etc.). Independent problem-solving, addressing complex security challenges with minimal supervision. Preferred qualifications: CCNP (Security) or higher-level certifications such as the CCIE. CISSP or OSCP security certifications. Azure Security Engineer, or GCP Security Engineer certification. Experience with Agile methodologies and tools (e.g., Jira/Confluence) WHO WE ARE H&M is a fashion brand that offers the latest styles and inspiration, from fashion pieces and unique designer collaborations to affordable wardrobe essentials. Our business idea is fashion & quality at the best price in a sustainable way. Learn more about H&M here. WHY YOU’LL LOVE WORKING HERE Benefits All our employees are included in our H&M Incentive Program (HIP) All our employees receive a staff discount card, which is usable on all our H&M Group brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET. Work-life balance, 30 days’ vacation and wellness allowance 4000 SEK/yearly Access to Benify, for discounts on e.g. Gym memberships, travel, hotels and many other great deals. Compensation boost during parental leave In addition to our global benefits, all our local markets offer different competitive perks and benefits. Please note that they may differ between employment type and countries. Inclusion & Diversity H&M is a part of H&M Group. At H&M Group, we’re determined to create and maintain inclusive, diverse and equitable workplaces throughout our organization. Our teams should consist of a variety of people that share and combine their knowledge, experience and ideas. Having a diverse workforce leads to a positive impact on how we address challenges, on what we perceive possible and on how we choose to relate to our colleagues and customers all over the world. Hence all diversity dimensions are taken into consideration in our recruitment process. We are committed to a recruitment process that is fair, equitable, and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
Northmill Bank is a challenger bank at the intersection of technology and finance, committed to revolutionizing the way people manage and protect their financial well-being. We are creating a different kind of banking experience, digital yet personal. Northmill Bank was founded in 2006 and have grown to over 240 employees in 3 countries, 4 000 merchants and 600 000 end users. We use the latest technology to develop safe, smart, and user-friendly products for our customers. They are the sole reason why we do what we do. We are a 100% cloud-based product company where technology is the driver to create smarter banking products. Grab this opportunity to be a part of us and our journey! About the role The Information Security Officer is subject matter expert, and a member of the Information Security team in the second line of defense. The team is tasked to provide governance, oversight and guidance, meaning to ICT write policies, and monitor and control first line’s compliance towards these policies. The team also has a number of security capabilities that we provide ourselves, such as technical security scanners or security training activities. While the team’s primary responsibility is governance, oversight, this is a small bank and you will also play a hands-on role in driving security initiatives, designing procedures, and building security capabilities. You will directly influence the secure design of systems, support risk management, and respond to security incidents. Much of information security material needs a significant rewrite, so this role comes with a great opportunity to use prior experience to influence the Bank’s ways of working, risk appetite and ultimately its risk posture. You will have a blank canvas to modernize our security framework, moving us from legacy documentation to a lean, ISO 27001-aligned 'Version 2.0.' This is a rare opportunity to use your experience to directly shape the Bank’s ways of working, risk appetite, and long-term security posture. What you will do Translating information security requirements into practical, effective, and business-aligned policies, procedures, guidelines or strategies. Northmill is both a bank and payment provider in multiple European regions, and also has a number of business requirements affecting information security. Monitor compliance for our internal information security rules and our applicable business and regulatory requirements. DORA, GDPR, PSD2, FFFS, Visa, Swift, Swish, Bankgirot, Rixbanken, etc. Structure information security requirements in the ISMS in alignment with the ISO 27001 standard. Act as an advisor and lead for information, cyber security, or privacy incidents. Serve as a subject matter expert within privacy and data protection Act as subject matter expert in relation to our PCI-DSS certification and conduct readiness assessments towards the business. Keep track of that recurring tasks are performed as needed. Contribute to reporting towards supervisory authorities (e.g. SFSA, IMY, FIN-FSA) Ensure that the organization has relevant security awareness and training in place Lead and participate in Business Impact Analysis, ICT vendor approval, the Register of Information, Critical and Important functions, ICT Risk assessments, Data Protection Impact Assessments, IA-act risk assessments, NPAP, and various GAP analyses. What we are looking for Experience working as an Information Security Officer or in a similar role Hands-on experience in developing policies, procedures, and security frameworks A pragmatic mindset and a strong understanding of how to balance regulatory requirements with business needs Strong problem-solving skills and the ability to operate in a dynamic environment A collaborative approach and willingness to work closely with different parts of the organization Professional proficiency in both Swedish and English (Finnish or German is a plus) Based in Stockholm, with EU/EEA residency or citizenship Certifications such as CISM or ISO 27001 Lead Implementer are meritorious, but not required. What we offer A fantastic office in a prime Stockholm location with great spaces and views An independent role with the opportunity to make a real impact Great opportunities for professional development Health - 5 000 kr health care allowance Conference abroad every other year Breakfast and fruits every day, as well as "holy fika” each Friday Regular after work and celebrated successes at the office Apply today and be a part of Northmill!