Sida 1 av 20
1 plats(er). ARBETSUPPGIFTER Som informationssäkerhetssamordnare har du en central och strategisk roll i kommunen. Du samordnar och utvecklar arbetet med informationssäkerhet på övergripande nivå och säkerställer att kommunen uppfyller gällande lagar, krav och riktlinjer. Uppdraget omfattar även att stödja kommunens bolag i informationssäkerhetsfrågor så att även dessa verksamheter bedriver ett säkert och strukturerat informationssäkerhetsarbete. Du arbetar nära IT- och Digitalisering, Säkerhetschef, dataskyddsombud och chefer samt stöttar organisationen i frågor som rör risker, klassning av information, styrning och rutiner. Rollen innebär både operativt och strategiskt arbete. Exempel på arbetsuppgifter • Driva och vidareutveckla kommunens arbete med informationssäkerhet enligt etablerade ramverk (t.ex. ISO 27000-serien) • Samordna riskanalyser, informationsklassning och kontinuitetsarbete • Ta fram, förvalta och följa upp styrande dokument såsom policyer, riktlinjer och rutiner • Stödja chefer och verksamheter inklusive kommunala bolag i att omsätta krav i praktiken • Bidra i arbetet kring nya Cybersäkerhetslagen, GDPR och annan relevant lagstiftning • Medverka i hantering och uppföljning av incidenter • Genomföra utbildnings- och informationsinsatser i organisationen • Följa upp och rapportera status till ledning och nämnder KVALIFIKATIONER Vi söker dig som har: • Eftergymnasial utbildning inom exempelvis informationssäkerhet, IT, juridik, samhällsvetenskap eller annan relevant inriktning eller motsvarande erfarenhet • Erfarenhet av arbete med informationssäkerhet, riskhantering eller närliggande områden • God förståelse för styrning, ledningssystem och verksamhetsutveckling • God förmåga att uttrycka dig i tal och skrift på svenska Det är meriterande om du har: • Erfarenhet från offentlig sektor och samarbete med andra myndigheter • Kunskap om ISO 27001/LIS • Kunskap/erfarenhet av relevanta lagar/förordningar såsom t ex GDPR, NIS2 etc. • Kännedom/erfarenhet av säkerhetsskyddsfrågor, signalskydd eller brottsförebyggande insatser • Erfarenhet av förändrings- och utbildningsarbete Vi tror att du • är strukturerad och analytisk • har lätt för att samarbeta och skapa förtroende • trivs i en rådgivande och stödjande roll • kan balansera krav, verksamhetsnytta och säkerhet Stor vikt läggs vid personlig lämplighet. Löneform: Månadslön. Anställningsform: Tillsvidareanställning. Varaktighet: Tillsvidare, tillträde: 2026-12-01 Eller enligt ök. Arbetstid: Dagtid. Hos oss får du • ett meningsfullt och samhällsviktigt uppdrag • möjlighet att påverka och utveckla kommunens säkerhetsarbete • engagerade kollegor i en utvecklingsinriktad organisation • goda möjligheter till kompetensutveckling Degerfors kommun använder sig av Offentliga jobb. Ansökningar som kommer via mail kommer inte vara med i urvalsprocessen. Vi undanbeder oss vänligen men bestämt kontakt med bemannings- och rekryteringsföretag samt annonsförsäljare för den här tjänsten.
Vi söker dig som vill arbeta i en central roll med att vidareutveckla och stärka vårt systematiska informationssäkerhetsarbete. Är du erfaren inom området och söker ett utvecklande uppdrag - läs mer nedan och sök! Om rollen och dina arbetsuppgifter Som informationsäkerhetsspecialist arbetar du strukturerat och riskbaserat för att säkerställa att kommunens information hanteras på ett korrekt och säkert sätt ur ett cybersäkerhetsperspektiv. Rollen innebär att växla mellan strategisk utveckling och operativt arbete. Du kommer att verka i en komplex miljö där riskhantering, regelefterlevnad och verksamhetens behov behöver balanseras för att skapa en effektiv och robust informationshantering. Du behöver förstå teknik och ha ett brinnande intresse för AI och hur det på ett säkert sätt kan utveckla vår verksamhet. Arbetet består i stor utsträckning av att stötta verksamheten i olika projekt t.ex med AI fokus, genomföra riskanalyser, kommunicera övergripande krav, hålla workshops, kontrollera och följa upp samt genomföra utbildningar inom området. Att utforma och bidra till interna policys och processer för att skydda information är också en del av arbetsuppgifterna. Rollen innebär att man måste hålla sig uppdaterad om nya hot, sårbarheter och lagstiftningar som påverkar informationssäkerheten. Informationssäkerhetsarbetet sker enligt ISO 27001 standard och vi lyder under cybersäkerhetslagen. Vi söker dig Vårt uppdrag är att skapa framgång för helheten, vi ser till hela verksamhetens bästa i ageranden och beslut. Det betyder att du måste kunna fokusera på att vara relevant för det större perspektivet. Du kommer att samarbeta med många olika funktioner i kommunen, vilket ställer höga krav på din kommunikativa förmåga. Du vet hur man når fram med sitt budskap, anpassar ton och format efter målgruppen och skapar förståelse även i komplexa frågor. Som person samarbetar du lätt med andra, du är smidig i din dialog och skapar goda relationer. När utmaningar uppstår hanterar du dem på ett konstruktivt och lösningsorienterat sätt. Vi söker dig som har några års erfarenhet av arbete med informationssäkerhet/cybersäkerhet. Du måste ha god kunskap om och erfarenhet av följande: Framtagande av styrande dokument inom informationssäkerhet Riskanalyser och utvärdering av dessa Upphandlingsarbete ur ett cybersäkerhetsperspektiv Standard ISO27001 Informationssäkerhetsarbete kopplat till cybersäkerhetslagen Det är positivt om du därtill har erfarenhet av: Offentlig verksamhet Cybersäkerhetslagen & AI förordningen NIST och CIS controls För att lyckas i rollen behöver du trivas med att arbeta tillsammans med andra i en resultatfokuserad miljö där leverans av hög kvalitet är en självklar målsättning. Samtidigt har du förmåga att planera, prioritera och leda ditt arbete självständigt. Du tar initiativ, följer upp och visar både nyfikenhet och driv i dina processer. Du har goda kunskaper i svenska språket i tal och skrift och du tar lätt till dig information och facklitteratur inom området på engelska. Vi erbjuder dig När du blir en del av oss får du mer än bara ett jobb, du blir en del av ett sammanhang. Här möts du av trevliga och kompetenta kollegor som gärna delar med sig av sin kunskap och erfarenhet. Vi tror på kollegialt lärande, där vi stöttar och inspirerar varandra för att utvecklas tillsammans. Hos oss väntar spännande och meningsfulla uppdrag där du får möjlighet att bidra, växa och göra skillnad - varje dag. Som medarbetare hos oss erbjuds du en rad förmåner med fokus på balans, trygghet och hälsa. Lunds kommun är en stor organisation med många spännande verksamheter och möjligheter för medarbetare till utveckling. Som medarbetare får du även tillgång till vår förmånsportal där du enkelt kan se dina förmåner och administrera dessa. https://lund.se/arbete-och-lediga-jobb/sa-ar-det-att-arbeta-med-oss/det-har-ger-vi-dig-som-medarbetare Om rekryteringen I denna rekrytering har vi tagit bort det personliga brevet och ersatt med frågor relevanta för tjänsten. Dina svar är därför viktiga i vårt urvalsarbete. Vi kommer att hålla första digitala intervjuer via Teams under vecka 35 och 36 samt slutintervjuer på plats vecka 37 och 38. Vi ber dig därför planera din tillgänglighet. Om arbetsplatsen Enheten för informationssäkerhet och dataskydd har ett spännande uppdrag! Vårt arbete sträcker sig från regelefterlevnad till verksamhetsutveckling och omfattar hela kommunens organisation och alla dess verksamhetsområden. Enhetens uppdrag är att harmonisera kommunens informations- och dataskyddsarbete, skapa tydligare riktning och driva vårt gemensamma arbete framåt utifrån koncernens samlade ambitioner kring digitalisering. Arbetsgruppen består av består av CiSO, jurist, informationssäkerhet- och dataskyddsspecialister som tillsammans ansvarar för att etablera gemensamma arbetssätt och säkerställa samordnat stöd för alla kommunens verksamheter. Vi tror på kraften i samarbete och arbetar nära olika enheter för att tillsammans lösa komplexa utmaningar, främja kommunens utveckling och bidra positivt till medborgarnas vardag. På kommunkontoret arbetar cirka 400 medarbetare inom strategiska funktioner. Tillsammans säkerställer vi att kommunen är en effektiv och modern organisation. Just nu befinner vi oss på en spännande utvecklingsresa med målet att fungera som en motor i utvecklingen av hela organisationen. Där vi tar ansvar för helheten, och sätter medborgarnas bästa i fokus. Här får du plats att växa. Inom Lunds kommun sätter vi kunskapen i centrum och skapar möjligheter att utvecklas i arbetslivet. Vi erbjuder en inkluderande arbetsmiljö, och chans att påverka och göra skillnad. Vill du bli en av oss?
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security controls across our Azure Gov Cloud environment (including hybrid and multi-cloud scenarios). In this hands-on role, you will build, strengthen, and maintain our cloud security posture, protect critical workloads, and collaborate with engineering, DevOps, and compliance teams to embed security throughout the development lifecycle. You will develop, implement, and leverage Microsoft’s native security tools to detect threats, respond to incidents, and ensure alignment with industry standards and regulations. Lastly, you will be required to both achieve and maintain compliance with government regulations such as FedRAMP and CMMC. RESPONSIBILITIES: * Implement, design, and manage security architecture for Azure Government and Commercial deployments (with considerations for DoD IL5\IL6 and FedRAMP High controls) * Configure and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response * Design and enforce identity & access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access * Secure network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints * Protect data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls * Develop and maintain security policies, initiatives, and blueprints using Azure Policy and Microsoft Purview for compliance (NIST, FedRAMP, CMMC, STIGs, etc.) * Perform threat hunting, incident response, and forensics using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of Infrastructure as Code (IaC), containers, Kubernetes (AKS), and serverless workloads * Collaborate with developers and architects to implement DevSecOps practices, including secure CI/CD pipelines, code scanning, and secure defaults * Monitor and remediate security findings, reduce attack surface, and improve overall security posture per the Microsoft Cloud Security Benchmark (MCSB) * Deploy configurations and compliance policies to Azure AVD endpoints using Intune and other Azure native services. BASIC QUALIFICATIONS: * Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one. * 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus) * Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview * Strong understanding of DLP implementation both in cloud and on endpoints utilizing Purview and other Microsoft native controls * Experience implementing security in hybrid/multi-cloud environments * Proficiency in scripting/automation (PowerShell, Azure CLI, Bicep/ARM templates, Terraform) * Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management * Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements * Excellent problem-solving, analytical, and communication skills * Strong verbal and written communication skills and the ability to stay composed under pressure. PREFERRED SKILLS AND EXPERIENCE: * Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100) * Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD) * Deep experience with detection and response engineering and SOC operations * Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection * Prior experience in government regulations frameworks such as FedRAMP and CMMC. COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: * To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
Education is one of the world's most important systems. At Kognity, we develop technology that enhances its effectiveness for both the teachers delivering it and the students who rely on it. The problems are real, the work is challenging, and the results show up in classrooms every day. We're a 125-person EdTech scale-up powering learning in 140+ countries, helping students and teachers thrive through an intelligent platform that combines rich, interactive pedagogy with smart AI and data. Why join Kognity? Work on problems that matter – Your work directly influences the lives of teachers and students in over 100 countries. The scale is global, and the outcomes are tangible. High ownership, high expectations – You are trusted to take initiative, make decisions and drive outcomes. Responsibility comes early, accountability is real, and results matter. A fast-moving, high-performing team – You will work with smart, driven colleagues across the globe on complex problems. Standards and expectations are high, feedback is direct, and the pace is fast. Continuous growth is the baseline – Everyone is expected and supported to learn quickly, improve constantly and raise their own bar. If you enjoy responsibility, momentum and meaningful challenge, you will thrive here. What you'll do As an Information Security Manager you will get a chance to take ownership of Kognity's information security programme, keeping certifications like SOC 2 and ISO live and evolving, and driving incident response and customer trust for a platform used in classrooms across 120+ countries. You will: Take full ownership of Kognity's information security certifications and the policies behind them, turning a complex compliance landscape into a dependable system. Manage Kognity's incident response plan and strategy for data breaches, ensuring the business can respond quickly and confidently if an incident occurs. Oversee the IT and data security of Kognity's web systems, including banking security, keeping customer and company data protected across our platform. Lead customer information security dialogues and respond to RFPs, building Kognity's reputation as a partner customers can trust with their data. Manage physical security across Kognity's premises, keeping security risks to our offices and people to a minimum. Provide day-to-day support to teams across Kognity on information security questions, keeping good security practice a part of how people work rather than an afterthought. What we're looking for Experience working with information security frameworks (SOC2, ISO 27000 and ISO 42000) and ownership of an information security set-up end to end. A collaborative approach, comfortable managing security-related projects across functions such as Legal, Engineering, and Commercial. A commercial mindset, understanding how information security not only protects Kognity but also drives customer trust and business success. A passion for AI and a drive to experiment with new tools to enhance creativity, decisions, and execution. Our Values We take ownership We are transparent We make every week count We obsess over customers We show up with heart How we hire Discovery call with a Recruiter Hiring manager discussion Case study Values discussion Leadership talk References
Education is one of the world's most important systems. At Kognity, we develop technology that enhances its effectiveness for both the teachers delivering it and the students who rely on it. The problems are real, the work is challenging, and the results show up in classrooms every day. We're a 125-person EdTech scale-up powering learning in 140+ countries, helping students and teachers thrive through an intelligent platform that combines rich, interactive pedagogy with smart AI and data. Why join Kognity? * Work on problems that matter – Your work directly influences the lives of teachers and students in over 100 countries. The scale is global, and the outcomes are tangible. * High ownership, high expectations – You are trusted to take initiative, make decisions and drive outcomes. Responsibility comes early, accountability is real, and results matter. * A fast-moving, high-performing team – You will work with smart, driven colleagues across the globe on complex problems. Standards and expectations are high, feedback is direct, and the pace is fast. * Continuous growth is the baseline – Everyone is expected and supported to learn quickly, improve constantly and raise their own bar. If you enjoy responsibility, momentum and meaningful challenge, you will thrive here. What you'll do As an Information Security Manager you will get a chance to take ownership of Kognity's information security programme, keeping certifications like SOC 2 and ISO live and evolving, and driving incident response and customer trust for a platform used in classrooms across 120+ countries. You will: * Take full ownership of Kognity's information security certifications and the policies behind them, turning a complex compliance landscape into a dependable system. * Manage Kognity's incident response plan and strategy for data breaches, ensuring the business can respond quickly and confidently if an incident occurs. * Oversee the IT and data security of Kognity's web systems, including banking security, keeping customer and company data protected across our platform. * Lead customer information security dialogues and respond to RFPs, building Kognity's reputation as a partner customers can trust with their data. * Manage physical security across Kognity's premises, keeping security risks to our offices and people to a minimum. * Provide day-to-day support to teams across Kognity on information security questions, keeping good security practice a part of how people work rather than an afterthought. What we're looking for * Experience working with information security frameworks (SOC2, ISO 27000 and ISO 42000) and ownership of an information security set-up end to end. * A collaborative approach, comfortable managing security-related projects across functions such as Legal, Engineering, and Commercial. * A commercial mindset, understanding how information security not only protects Kognity but also drives customer trust and business success. * A passion for AI and a drive to experiment with new tools to enhance creativity, decisions, and execution. Our Values * We take ownership * We are transparent * We make every week count * We obsess over customers * We show up with heart How we hire 1. We will review your applications on August, 3rd 2. Discovery call with a Recruiter 3. Hiring manager discussion 4. Case study 5. Values discussion 6. Leadership talk 7. References See more about how we collect and process your personal data in our Privacy Notice.
Do you want to help shape information security across one of Scandinavia's leading EdTech companies? At IST, we develop digital solutions that support education and learning for millions of users across Scandinavia. As Information Security Manager, you will play a key role in protecting our information assets, driving compliance initiatives, and strengthening our security culture across the entire IST Group. While the role has a strong focus on our Danish operations and product portfolio, you will work on a Group level, collaborating with colleagues and stakeholders across multiple countries and business areas. This is an opportunity for someone who wants to combine strategic security leadership with hands-on security governance in a company with a meaningful societal mission. The role serves as an important bridge between customers, operations, development, and management when security-related issues occur. About the role As Information Security Manager, you will be responsible for developing, implementing, and maintaining IST's information security framework. You will work closely with product and development departments, customers, auditors, and external stakeholders to ensure that security is embedded throughout the business. You will act as a trusted advisor on information security matters, supporting both operational and strategic initiatives while continuously improving our security posture. These are the key responsibilities: Develop and maintain information security policies, standards, and procedures across the Group. Lead and coordinate information security governance activities. Drive compliance with relevant regulations and frameworks, including GDPR, NIS2, ISO 27001, ISAE 3000, and related requirements. Manage and coordinate security incidents, investigations, and corrective actions. Conduct risk assessments and support enterprise risk management activities. Collaborate with product development teams to embed privacy and security by design. Support audits, security reviews, and due diligence processes. Manage and maintain data processing agreements and security-related documentation. Drive security awareness initiatives and promote a strong security culture throughout the organization. Prepare reports and security metrics for management and key stakeholders. Your profile We believe you have the following competence profile to succeed in this role: A Bachelor’s degree within Information Security, Computer Science, IT, Law, Business, or a related field. Experience working with information security, cybersecurity, risk management and/or compliance. Experience with GDPR and information security governance, ISO 27001, NIS2, ISAE 3000, SOC reporting, or similar frameworks. Experience supporting audits, inspections, or compliance reviews. The ability to communicate complex security topics to both technical and non-technical audiences. Strong stakeholder management and collaboration skills. A proactive, self-driven, and structured working style. Relevant certifications such as ISO 27001, CISSP, CISM, CRISC, or similar are considered an advantage. Why join IST? At IST, you will become part of a company that has been developing digital solutions for the education sector for more than 40 years. We are approximately 400 employees across several countries, united by the ambition to create better opportunities for learning and education. What we offer: A meaningful role with significant influence on the Group's security agenda. The opportunity to work across multiple countries, products, and business areas. A collaborative and supportive international environment. Professional and personal development opportunities. A strong culture characterized by trust, openness, and teamwork. This is a full-time, permanent position. At IST, we apply an office-first policy, meaning we primarily work from the office as we believe physical presence fosters collaboration, innovation, and a strong team spirit. At the same time, we understand the importance of flexibility—if you live farther away, working from the office three days a week with the remaining time remote may be possible. In Scandinavia our offices are located in Stockholm, Växjö, Roskilde and Oslo. Apply Applications are reviewed continuously. For questions, contact Nanna Holm Thyboe, +45 20 72 60 34 or email: nanna.thyboe@ist.com For questions about the recruitment process, contact hr@ist.com Please note! Background check is part of the recruitment process. Welcome to apply!
Do you want to help shape information security across one of Scandinavia's leading EdTech companies? At IST, we develop digital solutions that support education and learning for millions of users across Scandinavia. As Information Security Manager, you will play a key role in protecting our information assets, driving compliance initiatives, and strengthening our security culture across the entire IST Group. While the role has a strong focus on our Danish operations and product portfolio, you will work on a Group level, collaborating with colleagues and stakeholders across multiple countries and business areas. This is an opportunity for someone who wants to combine strategic security leadership with hands-on security governance in a company with a meaningful societal mission. The role serves as an important bridge between customers, operations, development, and management when security-related issues occur. About the role As Information Security Manager, you will be responsible for developing, implementing, and maintaining IST's information security framework. You will work closely with product and development departments, customers, auditors, and external stakeholders to ensure that security is embedded throughout the business. You will act as a trusted advisor on information security matters, supporting both operational and strategic initiatives while continuously improving our security posture. These are the key responsibilities: Develop and maintain information security policies, standards, and procedures across the Group. Lead and coordinate information security governance activities. Drive compliance with relevant regulations and frameworks, including GDPR, NIS2, ISO 27001, ISAE 3000, and related requirements. Manage and coordinate security incidents, investigations, and corrective actions. Conduct risk assessments and support enterprise risk management activities. Collaborate with product development teams to embed privacy and security by design. Support audits, security reviews, and due diligence processes. Manage and maintain data processing agreements and security-related documentation. Drive security awareness initiatives and promote a strong security culture throughout the organization. Prepare reports and security metrics for management and key stakeholders. Your profile We believe you have the following competence profile to succeed in this role: A Bachelor’s degree within Information Security, Computer Science, IT, Law, Business, or a related field. Experience working with information security, cybersecurity, risk management and/or compliance. Experience with GDPR and information security governance, ISO 27001, NIS2, ISAE 3000, SOC reporting, or similar frameworks. Experience supporting audits, inspections, or compliance reviews. The ability to communicate complex security topics to both technical and non-technical audiences. Strong stakeholder management and collaboration skills. A proactive, self-driven, and structured working style. Relevant certifications such as ISO 27001, CISSP, CISM, CRISC, or similar are considered an advantage. Why join IST? At IST, you will become part of a company that has been developing digital solutions for the education sector for more than 40 years. We are approximately 400 employees across several countries, united by the ambition to create better opportunities for learning and education. What we offer: A meaningful role with significant influence on the Group's security agenda. The opportunity to work across multiple countries, products, and business areas. A collaborative and supportive international environment. Professional and personal development opportunities. A strong culture characterized by trust, openness, and teamwork. This is a full-time, permanent position. At IST, we apply an office-first policy, meaning we primarily work from the office as we believe physical presence fosters collaboration, innovation, and a strong team spirit. At the same time, we understand the importance of flexibility—if you live farther away, working from the office three days a week with the remaining time remote may be possible. In Scandinavia our offices are located in Stockholm, Växjö, Roskilde and Oslo. Apply Applications are reviewed continuously. For questions, contact Nanna Holm Thyboe, +45 20 72 60 34 or email: nanna.thyboe@ist.com For questions about the recruitment process, contact hr@ist.com Please note! Background check is part of the recruitment process. Welcome to apply!
Do you want to help shape information security across one of Scandinavia's leading EdTech companies? At IST, we develop digital solutions that support education and learning for millions of users across Scandinavia. As Information Security Manager, you will play a key role in protecting our information assets, driving compliance initiatives, and strengthening our security culture across the entire IST Group. While the role has a strong focus on our Danish operations and product portfolio, you will work on a Group level, collaborating with colleagues and stakeholders across multiple countries and business areas. This is an opportunity for someone who wants to combine strategic security leadership with hands-on security governance in a company with a meaningful societal mission. The role serves as an important bridge between customers, operations, development, and management when security-related issues occur. About the role As Information Security Manager, you will be responsible for developing, implementing, and maintaining IST's information security framework. You will work closely with product and development departments, customers, auditors, and external stakeholders to ensure that security is embedded throughout the business. You will act as a trusted advisor on information security matters, supporting both operational and strategic initiatives while continuously improving our security posture. These are the key responsibilities: Develop and maintain information security policies, standards, and procedures across the Group. Lead and coordinate information security governance activities. Drive compliance with relevant regulations and frameworks, including GDPR, NIS2, ISO 27001, ISAE 3000, and related requirements. Manage and coordinate security incidents, investigations, and corrective actions. Conduct risk assessments and support enterprise risk management activities. Collaborate with product development teams to embed privacy and security by design. Support audits, security reviews, and due diligence processes. Manage and maintain data processing agreements and security-related documentation. Drive security awareness initiatives and promote a strong security culture throughout the organization. Prepare reports and security metrics for management and key stakeholders. Your profile We believe you have the following competence profile to succeed in this role: A Bachelor’s degree within Information Security, Computer Science, IT, Law, Business, or a related field. Experience working with information security, cybersecurity, risk management and/or compliance. Experience with GDPR and information security governance, ISO 27001, NIS2, ISAE 3000, SOC reporting, or similar frameworks. Experience supporting audits, inspections, or compliance reviews. The ability to communicate complex security topics to both technical and non-technical audiences. Strong stakeholder management and collaboration skills. A proactive, self-driven, and structured working style. Relevant certifications such as ISO 27001, CISSP, CISM, CRISC, or similar are considered an advantage. Why join IST? At IST, you will become part of a company that has been developing digital solutions for the education sector for more than 40 years. We are approximately 400 employees across several countries, united by the ambition to create better opportunities for learning and education. What we offer: A meaningful role with significant influence on the Group's security agenda. The opportunity to work across multiple countries, products, and business areas. A collaborative and supportive international environment. Professional and personal development opportunities. A strong culture characterized by trust, openness, and teamwork. This is a full-time, permanent position. At IST, we apply an office-first policy, meaning we primarily work from the office as we believe physical presence fosters collaboration, innovation, and a strong team spirit. At the same time, we understand the importance of flexibility—if you live farther away, working from the office three days a week with the remaining time remote may be possible. In Scandinavia our offices are located in Stockholm, Växjö, Roskilde and Oslo. Apply Applications are reviewed continuously. For questions, contact Nanna Holm Thyboe, +45 20 72 60 34 or email: nanna.thyboe@ist.com For questions about the recruitment process, contact hr@ist.com Please note! Background check is part of the recruitment process. Welcome to apply!
Do you want to help shape information security across one of Scandinavia's leading EdTech companies? At IST, we develop digital solutions that support education and learning for millions of users across Scandinavia. As Information Security Manager, you will play a key role in protecting our information assets, driving compliance initiatives, and strengthening our security culture across the entire IST Group. While the role has a strong focus on our Danish operations and product portfolio, you will work on a Group level, collaborating with colleagues and stakeholders across multiple countries and business areas. This is an opportunity for someone who wants to combine strategic security leadership with hands-on security governance in a company with a meaningful societal mission. The role serves as an important bridge between customers, operations, development, and management when security-related issues occur. About the role As Information Security Manager, you will be responsible for developing, implementing, and maintaining IST's information security framework. You will work closely with product and development departments, customers, auditors, and external stakeholders to ensure that security is embedded throughout the business. You will act as a trusted advisor on information security matters, supporting both operational and strategic initiatives while continuously improving our security posture. These are the key responsibilities: Develop and maintain information security policies, standards, and procedures across the Group. Lead and coordinate information security governance activities. Drive compliance with relevant regulations and frameworks, including GDPR, NIS2, ISO 27001, ISAE 3000, and related requirements. Manage and coordinate security incidents, investigations, and corrective actions. Conduct risk assessments and support enterprise risk management activities. Collaborate with product development teams to embed privacy and security by design. Support audits, security reviews, and due diligence processes. Manage and maintain data processing agreements and security-related documentation. Drive security awareness initiatives and promote a strong security culture throughout the organization. Prepare reports and security metrics for management and key stakeholders. Your profile We believe you have the following competence profile to succeed in this role: A Bachelor’s degree within Information Security, Computer Science, IT, Law, Business, or a related field. Experience working with information security, cybersecurity, risk management and/or compliance. Experience with GDPR and information security governance, ISO 27001, NIS2, ISAE 3000, SOC reporting, or similar frameworks. Experience supporting audits, inspections, or compliance reviews. The ability to communicate complex security topics to both technical and non-technical audiences. Strong stakeholder management and collaboration skills. A proactive, self-driven, and structured working style. Relevant certifications such as ISO 27001, CISSP, CISM, CRISC, or similar are considered an advantage. Why join IST? At IST, you will become part of a company that has been developing digital solutions for the education sector for more than 40 years. We are approximately 400 employees across several countries, united by the ambition to create better opportunities for learning and education. What we offer: A meaningful role with significant influence on the Group's security agenda. The opportunity to work across multiple countries, products, and business areas. A collaborative and supportive international environment. Professional and personal development opportunities. A strong culture characterized by trust, openness, and teamwork. This is a full-time, permanent position. At IST, we apply an office-first policy, meaning we primarily work from the office as we believe physical presence fosters collaboration, innovation, and a strong team spirit. At the same time, we understand the importance of flexibility—if you live farther away, working from the office three days a week with the remaining time remote may be possible. In Scandinavia our offices are located in Stockholm, Växjö, Roskilde and Oslo. Apply Applications are reviewed continuously. For questions, contact Nanna Holm Thyboe, +45 20 72 60 34 or email: nanna.thyboe@ist.com For questions about the recruitment process, contact hr@ist.com Please note! Background check is part of the recruitment process. Welcome to apply!
Join Truecaller – The place where innovation meets impact! Truecaller's mission is to build trust in communication by making it safer, smarter, and more efficient. Born in Sweden, trusted by the world, and here’s why we stand out: * We are trusted by over 450 million active users every month across 190+ countries * We identify over 15 billion calls daily, helping users avoid spam and scams * We are powered by a team of 450+ employees from 45+ nationalities We always look for people who take initiative, own their work, and keep raising the bar. An entrepreneurial mindset matters here, especially when it turns bold ideas into real actions. We stay collaborative and focused, always searching for smarter paths forward. If you want to make an impact and grow with a team that inspires millions, you’ll fit right in. The role: As a Senior Cloud Security Engineer, you will act as a technical leader in safeguarding our core cloud infrastructure. You will take ownership of maintaining the highest standards of security controls for our critical systems within Google Cloud Platform (GCP). We're looking for someone who thrives in complex environments, can solve infrastructure security problems where no established patterns exist, and isn't afraid to get their hands dirty. You won't just advise; you will actively build, configure, and fix security controls. You'll leverage your expert understanding of cloud services, infrastructure-as-code, and container security to architect robust security measures and drive systemic improvements across the organization. What you’ll do: * Architect and Lead GCP Security: Take end-to-end ownership of designing and implementing security architectures for our GCP infrastructure. You will look beyond immediate fixes to architect long-term, scalable solutions for networking, compute, storage, and GKE. * Hands-on Remediation & Engineering: You don't just identify risks; you fix them. You will actively write code, create Pull Requests, and apply configurations to resolve security issues, harden infrastructure, and deploy tooling (e.g., EDR, Identity proxies) in production environments. * Drive Systemic Risk Reduction: Identify repeating classes of vulnerabilities or systemic risks (e.g., data exfiltration paths) and drive organizational change to eliminate them, rather than just patching individual issues. * Manage GCP Security Posture: Utilize GCP-native tools (e.g., Security Command Center, Cloud Armor, VPC Service Controls, IAM) to continuously monitor, assess, and improve the security posture of our cloud environment. * Advanced Network & Container Security: Design complex network security controls and Kubernetes (GKE) hardening strategies, balancing strict security requirements with operational velocity. * Mentorship and Technical Sparring: Act as a technical mentor and sparring partner to other engineers. You will elevate engineering standards by guiding colleagues on advanced security concepts and architecture. * Automate Security Operations: Develop advanced automation (using Python, Go, No/Low Code) to eliminate toil, turning manual security reviews into automated policy-as-code checks and high-fidelity alerts. What you bring in: * Technical Experience: Several years of hands-on experience in a senior security engineering role. You have a track record of leading technical designs and influencing decisions across multiple squads. * Security Passion & Threat Awareness: You are passionate about security and stay constantly updated on the evolving threat landscape, emerging vulnerabilities, and attack vectors, translating this knowledge into proactive defense strategies. * Navigating Ambiguity: You excel at breaking down complex, multi-faceted technical problems into actionable components. You are comfortable defining security standards for experimental technologies where internal patterns may not yet exist. * Project Ownership & Grit: Demonstrated ability to drive mid-to-large scale projects from idea to implementation independently, including successful stakeholder alignment and management of external dependencies. * Operational "Doer" Mindset: You are a practitioner who enjoys the craft of engineering. You have recent, deep experience directly configuring infrastructure, writing production-grade code, and debugging complex systems. Once an issue has been identified you have the experience applying the fix either yourself or through collaboration with stakeholders. * Business-Aligned Risk Assessment: Experience weighing risk vs. speed, and making technical decisions that balance short-term delivery with long-term maintainability and business value. * Deep GCP Expertise: Expert-level knowledge of securing cloud infrastructure, with the ability to architect tool-agnostic solutions and evaluate trade-offs in GCP services (GCE, GKE, VPC, IAM, SCC). * Communication: Strong ability to communicate technical security concepts to non-technical stakeholders, clearly articulating business impact (e.g., financial loss, brand reputation) to secure buy-in. What we offer: We support growth through learning resources, leadership programs, mentoring, and real hands-on work. People can move between teams and projects to build new skills and keep things interesting. We offer clear internal mobility and a transparent path for progression, with leaders who stay involved and provide guidance throughout the year. In addition, you will benefit from: * A comprehensive compensation package: We offer a competitive salary, 30 days of paid vacation, private health insurance, parental leave top-up, pension, and wellness contributions. * Modern tools to do your best work: Choose your preferred computer and phone within our budget, so you can work comfortably and efficiently. * A people-focused office culture: We value in-person collaboration and follow an office-first model, with some flexibility. Our offices offer a vibrant environment with opportunities to learn, connect, and recharge, from breakfast, lunch, and well-stocked snack stations and quiet spaces to team activities such as movie nights, tech meetups, and cultural events. There's something for everyone. * Truecaller’s “Lab Days” offer a space for imagination: 5 times per year for 3 days, where everyone steps away from their normal tasks to explore new, bold ideas and build things they’ve always wanted to. It’s a space where curiosity leads the way, and prototypes take shape. Some concepts even make it into production, and a few have grown into real features used by millions today. Lab Days allow you to be creative, learn fast, and help shape Truecaller's future. Come as you are: Truecaller is committed to building a diverse and inclusive team. We believe that a wide range of backgrounds, perspectives, and experiences strengthens our products and our culture. No matter where you're from, what language you speak, or how you identify, we value what makes you unique and would love to get to know you. Check out Life at Truecaller - Behind the code: https://www.instagram.com/lifeattruecaller/ Sounds like a great opportunity? We will fill the position as soon as we find the right candidate, so please send your application as soon as possible. As part of the recruitment process, we will conduct a background check. We only accept applications in English.
Vill du äga och forma informationssäkerhetsarbetet på ett etablerat techbolag – och samtidigt ha en teknisk grund att stå på? Nu söker vi en Information Security Lead / Senior Sysadmin till vårt kontor i Malmö. Hos oss driver du vårt ISO 27001-arbete, sätter säkerhetsstrategin och blir vår nyckelperson inom informationssäkerhet – både för Netset och i nära samverkan med vår koncern, Movement Software. Vi har under 25+ år blivit marknadsledare inom B2B- och B2G-handelsmjukvara för IT- och telekombranschen. Vår flaggskeppsplattform Nettailer driver webbshoppar, inköpsflöden och distributörsintegrationer för över 350 IT-återförsäljare – från svenska SME-bolag till globala företag som ATEA, Advania, Telia och Vivicta. Om rollen Idag har vi en systemadministratör på plats – nu vill vi bygga ett starkare team med ett tydligare säkerhetsfokus. Som Information Security Lead / Senior Sysadmin får du ett helhetsansvar för vår informationssäkerhet, samtidigt som du tillsammans med din kollega ser till att drift och infrastruktur håller högsta nivå. Du arbetar tätt ihop med vårt team i Malmö, men samarbetar också nära koncernens centrala IT- och säkerhetsteam för att driva ISO 27001 och övriga ramverk gemensamt, med Netset som ditt primära fokus. Du behöver vara tekniskt kunnig nog att förstå serverpark, patchning och nätverk på djupet – det är just kombinationen av strategisk höjd och teknisk förståelse som gör att du kan säkra balansen mellan stabil drift och högsta säkerhetsnivå. Dina ansvarsområden inkluderar huvudsakligen: Informationssäkerhet & Compliance: Äga, driva och vidareutveckla ISO 27001-arbetet på Netset samt säkerställa efterlevnad av relevanta ramverk och regelverk (t.ex. NIS2 och GDPR). Säkerhetsstrategi & riskanalys: Ta fram, presentera och förvalta informationssäkerhetsstrategin gentemot ledningsgruppen samt genomföra löpande riskanalyser, säkerhetsgranskningar och internrevisioner. Incident- och sårbarhetshantering: Etablera och förvalta processer för incidenthantering, sårbarhetsanalys och härdning – och vara den som leder arbetet när något händer. Infrastruktur & drift: Tillsammans med vår sysadmin säkerställa drift, prestandaövervakning och backup av servrar hos våra hostingpartners (mestadels Linux-miljöer) där våra kunders lösningar ligger. Processförbättringar: Se över, härda och förbättra drift-, patch- och säkerhetsprocesser så att säkerhet är inbyggt i vardagen – inte ett tillägg. Teknisk rådgivning & arkitektur: Agera eskalationspunkt och säkerhetsrådgivare mot kunders IT-miljöer/leverantörer samt stötta den interna organisationen och utvecklingsteamet i säkerhetsfrågor. Om dig För att må bra, trivas och bli framgångsrik i rollen är din inställning lika viktig som din erfarenhet. Vi söker en självgående, strukturerad lagspelare med ett starkt eget driv och ett genuint engagemang för informationssäkerhet. Du har förmågan att kommunicera komplexa tekniska säkerhetsfrågor på ett pedagogiskt sätt, oavsett om du pratar med våra utvecklare eller med ledningsgruppen. För att lyckas i rollen ser vi att du har: Erfarenhet av att leda eller aktivt driva ISO 27001-arbete (certifiering, internrevision eller motsvarande). God kännedom om relevanta ramverk och regelverk inom informationssäkerhet, t.ex. NIS2 och GDPR. Erfarenhet av riskanalys, sårbarhetshantering, patchhantering och härdning av servrar. Gedigen erfarenhet av IT-drift i Linux-miljöer (routing, brandväggar, VPN, nätverkssäkerhet). Praktisk erfarenhet av Docker och containerbaserade arbetsflöden. God förståelse för MS SQL (databashantering och prestandaövervakning). Det är meriterande om du har kunskap inom: SIEM, loggning och incidenthantering. Skriptning och automation (Bash, Ansible). Molnsäkerhet och molntjänster (AWS, Azure, Google Cloud). Virtualisering (VMware/KVM), Kubernetes, Tomcat eller Apache/Nginx. Låter det intressant? Låter det här som ett team, en arbetsmiljö och kultur du skulle kunna trivas i – då vill vi gärna höra mer från dig! Sök jobbet, connecta med oss eller dela detta med någon du tror skulle passa in. Har du frågor om tjänsten, teamet eller företaget hör du av dig till Linnea Olsson, People Business Partner på Movement Software. En del av Movement Software Netset är en del av Movement Software – en nordisk mjukvarukoncern med ett tjugotal entreprenörsdrivna bolag inom branscherna fordon, transport & logistik samt integrerad e-handel. Vi drivs av teknisk innovation, med kravet att kundnyttan alltid står i centrum. Sedan 2023 är Movement Software en del av Axcel, ett nordiskt riskkapitalbolag med stort intresse för tech-sektorn. Att vara en del av Movement Software innebär ökade möjligheter för utveckling både för oss som företag och för dig som anställd, och samtidigt större trygghet. Är du som oss, tror vi att du vill känna meningsfullhet på jobbet – och vara med om att göra Netset till ett ännu bättre och roligare ställe att jobba på. För roligt är viktigt – jobbet är en för stor del av livet för att inte ha kul!
About Consilium Safety Group At Consilium Safety Group, we don’t just build technology, we create solutions that protect people, assets, and the planet. As a global leader in fire and gas safety, we serve critical industries such as marine, energy, rolling stock, and infrastructure. With more than 100 years of expertise, we combine deep industry knowledge with cutting-edge innovation to shape the future of Safety Tech. Headquartered in Gothenburg, Sweden, and operating in over 55 locations worldwide, we are a fast-growing global organization backed by Antin Infrastructure Partners. With strong financial support and a clear strategic vision, we are on an ambitious journey of growth and transformation, investing in innovation, operational excellence, and talent. This is an exciting time to join us. We are now looking for an Information Security Engineer to join the information security team at Consilium! About the Role As an Information Security Engineer at Consilium, you will combine hands-on security operations with strategic governance and compliance work. In practice, the role is split into two central pillars: Operational Excellence: Working hands-on to implement security controls, managing daily security activities, and acting as an internal subject matter expert. Strategic and Compliance-Oriented Leadership: Developing and driving our security strategy, ensuring we meet regulatory requirements, and continuously strengthening our security posture. You will help protect Consilium’s information assets, lead compliance efforts related to NIS2, and support alignment with frameworks such as NIST CSF, ISO 27001, the EU CRA, and the AI Act. The role works closely with teams across IT, HR, R&D, Sales, and Marketing. Your Main Responsibilities In this role, you will manage day-to-day security operations activities as well as strengthening the ISMS, implement controls aligned with ISO 27001, NIS2, and NIST CSF, coordinate audits, develop policies, and provide risk reporting and advisory support across the business. Qualifications and Experience To succeed in this role, you bring strong technical security knowledge, incident-handling capability, and an interest in governance and compliance. Requirements Technical Environment: Solid understanding of Microsoft Defender suite, Azure/O365, Windows, and Linux. Networking & Security Tools: Strong knowledge of TCP/IP, segmentation, firewalls, SIEM, EDR/EPP, and patch management. Automation: Basic to intermediate scripting skills (PowerShell, Python, Bash, KQL, or Graph API). Incident & Frameworks: Experience with log analysis, incident lifecycles, and frameworks like ISO 27001 or NIST CSF. Communication: Ability to explain technical security concepts clearly to non-technical stakeholders. Meriting Hands-on experience with Microsoft's advanced security stack (Sentinel, XDR, Entra, Intune, Purview/Priva). Cloud security controls (Azure), DevSecOps (GitHub Advanced Security), or direct audit-evidence collection experience. Previous experience working with audits and evidence collection linked to ISO 27001/NIS2/NIST CSF. Who Are We Looking For? We are looking for someone with hands-on experience in IT security and information security compliance, along with a solid understanding of relevant regulations and security frameworks. You are structured, analytical, and able to communicate clearly with a wide range of stakeholders. Personal Attributes You are analytical, proactive, and solution-oriented, with high integrity and a structured way of working. You communicate clearly, work well independently, and build strong relationships across technical and non-technical teams. What We Offer At Consilium Safety Group, you will join an innovative international environment where quality and safety come first. This is a high-impact role with opportunities to shape global security initiatives, along with a competitive salary, benefits, and career development. Apply Now Does this sound like your next challenge? Submit your application as soon as possible, as we review applications on a rolling basis. Consilium Safety Group is an equal opportunity employer committed to diversity and inclusion. Ready to learn more about our journey? Hear from our CEO: Philip Isell Lind af Hageby, Consilium, en mästare på turnarounds - Värdeskaparna | En podd om riskkapital av OPX Partners | Podcast on Spotify
Vill du ta nästa steg i karriären inom cybersäkerhet? Vill du jobba med komplexa problem i teknisk framkant och bidra till samhällsnyttiga projekt? Ta nu chansen i rollen som Information Secuity Engineer hos vår kund inom försvarsindustrin. Om tjänsten Du kommer att spela en central roll inom utveckling och säkerställande av interna IT-system. Ditt arbete kommer att kretsa kring att implementera och förbättra IT-säkerhetsåtgärder, vilket innebär ett nära samarbete med flera tvärfunktionella team. Ett av huvudansvaren är att säkerställa att organisationen ligger i framkant avseende tekniska innovationer och säkerhetsstandarder. Du kommer även att hantera tekniska gränssnitt för att säkerställa att systemen uppfyller både behov och kravställningar inom olika verksamhetsområden. Dina dagliga uppgifter kommer bland annat att inkludera säkerhetstestning, kravanalys och regeltolkning. Arbetet omfattar flera globala regelverk såsom NIST 800-171 Rev.2, NIS2, ISO-standarder samt andra internationella säkerhetsramverk. Du kommer också att vara ansvarig för att följa och implementera regelverk som ISO-standarder och GDPR, vilket är avgörande för att säkerställa organisationens compliance. För att lyckas i rollen krävs det att du har intresse för ny teknologi och en vilja att ständigt utöka din kunskap. Teamet arbetar ibland remote där virtuella verktyg används för samarbete. Det förekommer gemensamma teamdagar där det krävs fysisk närvaro on-site. Det finns möjlighet att arbeta från olika kontor/hubbar beroende på geografisk placering. Sammanfattningsvis erbjuder denna roll en rik möjlighet att bidra till och växa i en dynamisk och framåttänkande IT-miljö, där din insats kommer att vara avgörande för att framtidssäkra verksamheten och dess tekniska lösningar. Vi söker dig som har erfarenhet av en eller flera av följande områden:Säkerhetspraxis (te.x OWASP) Regelverk såsom ISO27xxx, GDPR, SOC2, DORA Kravställning och kravanalys IAM-roll-och-policybaserade behörighetssystem Praktisk erfarenhet av säkerhetstestning (t.ex. MITM) God kommunikation förmåga på svenska och engelska i tal och skrift Det kommer även läggas stor vikt vid personlig lämplighet i rekryteringen. För att trivas i rollen tror vi att du är en engagerad lagspelare med ett driv och vilja att utvecklas. Du kommer ingå i ett team där nyfikenhet och kreativitet uppmuntras, därför tror vi att du gillar innovation och gillar att komma med nya idéer och lösningar. Befattningen kräver att du genomgår och godkänns enligt gällande säkerhetsskyddsbestämmelser. För vissa roller kan detta innebära krav på säkerhetsklassning och i förekommande fall specifika medborgarskapskrav. Urval sker löpande och uppdraget kan komma att tillsättas innan sista ansökningsdatum Om anställningen: Detta är ett konsultuppdrag vilket innebär att du kommer vara anställd av Friday och arbeta som konsult ute hos vår kund. På Friday tror vi att människor som är på rätt plats har störst möjlighet att nå sin fulla potential. Vi är övertygade om att rätt människor, i rätt roller, skapar morgondagar värda att längta till. Övrig info: Omfattning: Heltid Start: Enligt överenskommelse Placering: Utångspunkt i Linköping men går att utgå från andra platser i landet Lön: Marknadsmässig månadslön Kontaktperson: Hampus Kindgren, hampus.kindgren@Friday.se Om Friday På Friday brinner vi för att ge dig som Tech-talang en riktigt bra start på karriären. Genom att lyssna på vad just du vill och drivs av, matchar vi dig med företag och möjligheter som får dig att se fram emot att gå till jobbet. Vi värderar ambition och potential högt och arbetar aktivt för en fördomsfri rekrytering, där alla ges samma chans att lyckas. Vi finns i Stockholm, Göteborg, Malmö, Linköping och Örebro. Varje år genomför vi över 5 000 karriärmöten och matchar kandidater med allt från globala företag till innovativa startups. Öppen för alla Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.
Northmill Bank is a challenger bank at the intersection of technology and finance, committed to revolutionizing the way people manage and protect their financial well-being. We are creating a different kind of banking experience, digital yet personal. Northmill Bank was founded in 2006 and have grown to over 240 employees in 3 countries, 4 000 merchants and 600 000 end users. We use the latest technology to develop safe, smart, and user-friendly products for our customers. They are the sole reason why we do what we do. We are a 100% cloud-based product company where technology is the driver to create smarter banking products. Grab this opportunity to be a part of us and our journey! About the role The Information Security Officer is subject matter expert, and a member of the Information Security team in the second line of defense. The team is tasked to provide governance, oversight and guidance, meaning to ICT write policies, and monitor and control first line’s compliance towards these policies. The team also has a number of security capabilities that we provide ourselves, such as technical security scanners or security training activities. While the team’s primary responsibility is governance, oversight, this is a small bank and you will also play a hands-on role in driving security initiatives, designing procedures, and building security capabilities. You will directly influence the secure design of systems, support risk management, and respond to security incidents. Much of information security material needs a significant rewrite, so this role comes with a great opportunity to use prior experience to influence the Bank’s ways of working, risk appetite and ultimately its risk posture. You will have a blank canvas to modernize our security framework, moving us from legacy documentation to a lean, ISO 27001-aligned 'Version 2.0.' This is a rare opportunity to use your experience to directly shape the Bank’s ways of working, risk appetite, and long-term security posture. What you will do Translating information security requirements into practical, effective, and business-aligned policies, procedures, guidelines or strategies. Northmill is both a bank and payment provider in multiple European regions, and also has a number of business requirements affecting information security. Monitor compliance for our internal information security rules and our applicable business and regulatory requirements. DORA, GDPR, PSD2, FFFS, Visa, Swift, Swish, Bankgirot, Rixbanken, etc. Structure information security requirements in the ISMS in alignment with the ISO 27001 standard. Act as an advisor and lead for information, cyber security, or privacy incidents. Serve as a subject matter expert within privacy and data protection Act as subject matter expert in relation to our PCI-DSS certification and conduct readiness assessments towards the business. Keep track of that recurring tasks are performed as needed. Contribute to reporting towards supervisory authorities (e.g. SFSA, IMY, FIN-FSA) Ensure that the organization has relevant security awareness and training in place Lead and participate in Business Impact Analysis, ICT vendor approval, the Register of Information, Critical and Important functions, ICT Risk assessments, Data Protection Impact Assessments, IA-act risk assessments, NPAP, and various GAP analyses. What we are looking for Experience working as an Information Security Officer or in a similar role Hands-on experience in developing policies, procedures, and security frameworks A pragmatic mindset and a strong understanding of how to balance regulatory requirements with business needs Strong problem-solving skills and the ability to operate in a dynamic environment A collaborative approach and willingness to work closely with different parts of the organization Professional proficiency in both Swedish and English (Finnish or German is a plus) Based in Stockholm, with EU/EEA residency or citizenship Certifications such as CISM or ISO 27001 Lead Implementer are meritorious, but not required. What we offer A fantastic office in a prime Stockholm location with great spaces and views An independent role with the opportunity to make a real impact Great opportunities for professional development Health - 5 000 kr health care allowance Conference abroad every other year Breakfast and fruits every day, as well as "holy fika” each Friday Regular after work and celebrated successes at the office Apply today and be a part of Northmill!
Om uppdraget 🚀 Organisationen skalar upp sitt arbete med AI och behöver förstärka inom informationssäkerhet och GRC. Fokus ligger på att hantera risker kopplade till AI, SaaS och integrationer – både operativt och strategiskt. Dina arbetsuppgifter 🛠️ Genomföra riskbedömningar kopplade till AI-initiativ Kommunicera risker och konsekvenser till ledning på ett affärsnära sätt Bidra till att bygga säkra AI-lösningar och relevanta guardrails Stötta utveckling av risk intake-processer Förbättra och strukturera organisationens övergripande riskhantering Förväntade leveranser 📦 Genomförda och dokumenterade riskanalyser inom AI/SaaS Tydliga beslutsunderlag till ledning Etablerade eller förbättrade processer för risk intake Konkreta rekommendationer för säker AI-användning Din profil / Obligatoriska kompetenser ✅ Erfarenhet av risk management och IT-säkerhet Teknisk bredd inom AI, SaaS och integrationer Minst 1–2 års aktuell erfarenhet av AI-/SaaS-relaterade risker Förmåga att översätta tekniska risker till affärspåverkan Flytande engelska i tal och skrift Meriterande färdigheter ⭐ Erfarenhet av att arbeta nära ledningsgrupp Tidigare arbete i organisationer med snabb AI-adoption Erfarenhet av att etablera GRC-processer Personliga egenskaper 🤝 Affärsdriven och kommunikativ Strukturerad och lösningsorienterad Självständig med hög leveransförmåga Övrig information 📍 Plats: Stockholm (onsite) Omfattning: Heltid Start: ASAP (flexibelt) Period: 3–6 månader Språk: Engelska Sway Sourcing är en innovativ rekryteringspartner som specialiserar sig på att matcha rätt talang med rätt företag – snabbt och effektivt. Vårt huvudfokus ligger inom Ekonomi, Administration, HR, Marknad och IT, men vi har även den breda expertis och flexibilitet som krävs för att leverera skräddarsydda rekryteringslösningar inom alla branscher. Trots att vi är en relativt ny aktör har vi redan byggt förtroende hos många av Sveriges största företag och arbetar både nationellt och internationellt. Med baser i Sverige och Spanien erbjuder vi en unik kombination av lokal expertis och global räckvidd. Vårt starka nätverk och djupa branschinsikter gör oss till en självklar partner för företag som vill ligga steget före i sin rekrytering.
About the Role You will be the hands-on security specialist responsible for keeping our internal digital landscape secure — across systems, integrations, cloud environments, data flows, and our vendor ecosystem. This role reports into the CISO office, directly to the CISO & Compliance Manager. You will combine security architecture thinking with practical execution: threat modeling, technical risk assessments, vendor due diligence, and governance work. You will partner closely with IT, Engineering, and Legal, acting as the internal security expert stakeholders turn to. You will also play a key role in how we secure our growing use of AI — an area that brings both significant opportunity and significant risk. This is a high-impact, cross-functional role for someone energized by the full breadth of security work — from technical assessments to policy and standards. What You Will Do * Lead security assessments of systems, integrations, and data flows * Conduct technical risk analyses for system implementations and vendor onboarding * Perform threat modelling and security architecture reviews * Define and implement security requirements for infrastructure and cloud environments * Assess and manage third-party and supplier security risks * Evaluate and manage security risks related to AI systems and AI-integrated products * Maintain alignment with ISO 27001 and SOC 2 Type II; contribute to policies, standards, and guidelines * Support incident investigations and act as a subject matter expert in audits * Help establish security guardrails across identity, access, encryption, and integrations What Will Help You Thrive * 5+ years in cybersecurity, information security, IT risk, or security architecture * Hands-on experience with threat modelling, risk assessments, and vendor security reviews * Strong technical foundation in cloud, networking, identity & access management, and system integrations * Familiarity with ISO 27001 and SOC 2 Type II * Awareness of AI security risks and how AI adoption changes the compliance and threat landscape * Strong communication and stakeholder management skills — you work across IT, Engineering, and Legal * Certifications such as CISSP, CISM, or CISA are a plus * Degree in Computer Science, Engineering, or a related field Who We're Looking For You combine technical rigour with genuine people skills — comfortable owning a threat model one day and a policy document the next. You are pragmatic, hands-on, and motivated by outcomes. You communicate clearly across audiences, thrive with broad responsibilities, and are proactive about improving both yourself and the way things are done. What to Expect During the Recruitment Process * Screening call with Global Talent Acquisition Partner * First Interview with our Hiring Manager * Personality and logical ability test * Second Interview with AI specialist peers * Third Interview & assignment * Final Interview with senior management * Reference and Background checks Why Tacton? * At Tacton, we’ve been building CPQ software for over 20 years. We’re a stable company with global customers and a product that’s central to how manufacturers sell * We offer competitive benefits, flexibility in how we work, and a culture that values learning and collaboration * A solid and stable company with over 20 years of industry experience. * Flexible hybrid setup - 3x a week at the office * 33 days of paid time off – 30 vacation days plus 3 extra to make sure you get the rest you deserve. * Premium occupational pension – Our pension plan goes beyond ITP1, with higher employer contributions depending on your age and salary level. * Generous wellness allowance – 5,000 SEK annually to support your health and wellbeing. * Private healthcare insurance – Skip the waiting lines and get quick access to private medical care, including specialist consultations and treatments. * Parental leave top-up – We top up your parental leave so you receive up to 90% of your base salary for up to 6 months, helping you focus on your family without financial stress * Weekly treats – Fika one week, breakfast the next, because good food brings people together. About Tacton Tacton is a global leader in software for manufacturers of complex, highly configurable products. Tacton delivers the Buyer-Centric Smart Factory, connecting buyer engagement with engineering and order fulfillment through a single source of truth. By uniting Configure, Price and Quote, Configuration Lifecycle Management, and Configured Order Fulfillment, Tacton helps manufacturers manage complexity, protect margins, and deliver with confidence across the lifecycle. With more than 26 years of experience, Tacton supports manufacturers worldwide and is headquartered in Stockholm, Sweden and Chicago, USA. Learn more at www.tacton.com.
Om din roll Som Information Security, Compliance & Risk Specialist arbetar du strukturerat och verksamhetsnära med att omsätta krav inom informationssäkerhet, regelefterlevnad och riskhantering till praktiskt värde. Du bidrar till att säkerställa efterlevnad av regelverk och är en viktig del i arbetet med att identifiera, förebygga och följa upp risker i en komplex omnichannel-verksamhet. Du samarbetar tätt med funktioner inom verksamheten och externa aktörer och verkar i gränslandet mellan teknik, regelverk och affär i frågor som rör dataskydd, compliance och risk. Rollen kombinerar operativt arbete med analys, uppföljning och utveckling av arbetssätt inom säkerhet och compliance. Exempel på arbetsuppgifter: Stödja och vidareutveckla Åhléns arbete inom informationssäkerhet, compliance och risk Säkerställa efterlevnad av lagar, regelverk och interna policys som berör GDPR och PCI DSS Genomföra och följa upp riskbedömningar kopplade till informationssäkerhet, betalflöden, system och leverantörer Delta i arbete kring bedrägeririsker (fraud), incidenthantering och uppföljning av förbättringsåtgärder Analys och följa upp säkerhetsincidenter, avvikelser och identifierade förbättringsåtgärder Bidra till framtagning och uppdatering av styrande dokument, riktlinjer och utbildningsmaterial Delta i bedömning av säkerhets-, risk- och compliancekrav vid upphandling, onboarding och uppföljning av externa leverantörer. Omvärldsbevaka relevanta förändringar inom regelverk och praxis avseende informationssäkerhet, dataskydd och betalningar, samt bidra med analyser och rekommendationer kring nödvändiga åtgärder. Vi erbjuder dig: Åhléns är ett välkänt retailbolag med över 120 års historia och en tydlig ambition att fortsätta utvecklas genom digitalisering, innovation och hållbara arbetssätt. Hos oss får du arbeta i en affärsnära roll där säkerhet, risk och compliance är en självklar del av vår tillväxtresa. Du blir en del av ett engagerat team och får möjlighet att påverka, samarbeta tvärfunktionellt och utveckla arbetssätt i en organisation med högt tempo och stort kundfokus. Till oss tar du med dig: Några års erfarenhet av arbete inom informationssäkerhet, IT-risk eller compliance God kunskap om GDPR och dataskydd Erfarenhet av eller god förståelse för PCI DSS och betalrelaterade säkerhetskrav Erfarenhet av riskanalyser och uppföljning av säkerhets- och complianceåtgärder Meriterande: erfarenhet från retail, e-handel eller betalningsintensiv verksamhet samt kännedom om standarder som ISO/IEC 27001. För att lyckas i rollen krävs att du är strukturerad, analytisk och lösningsorienterad, med god kommunikativ förmåga och ett affärsmedvetet förhållningssätt. Du trivs med att arbeta självständigt och tvärfunktionellt i en föränderlig miljö. Om rekryteringen Tjänsten är en tillsvidareanställning på heltid. Du är placerad på vårt huvudkontor på Dalagatan 100 och vi ser gärna att du kan börja hos oss så snart som möjligt. Urval och intervjuer kan komma att ske löpande och tjänsten kan tillsättas innan sista ansökningsdag, så skicka in din ansökan redan idag! Som Information Security, Compliance & Risk Specialist på Åhléns blir du en del av ett passionerat team som drivs av affärsmannaskap och entreprenörskap. Vi ger dig förtroende och möjligheten att växa i en utvecklande miljö. Med det hälsar vi dig varmt välkommen till Åhléns!
Job Title: Information risk and compliance officer TRATON is a group of strong brands with a shared mission: transforming transportation together to create the future of sustainable transport solutions. Within TRATON, we include MAN, Scania, Volkswagen Truck & Bus, and International. As part of a global team of industry experts, you get to think bigger, experience more, and reach further. Together, we have the power to transform transportation - Let´s make a difference together. Find out more: www.traton.com Our values – customer first, respect, team spirit, responsibility, and elimination of waste – are at the heart of everything we do. Role Summary As a Information Risk and Compliance Officer you will conduct internal audits to ensure compliance with regulatory requirements and internal policies, and develop and implement compliance policies in liaison with regulators. Assess and report on compliance risks, investigate incidents and take action to ensure compliance. Has knowledge of government laws and regulations affecting the company's business area, and ability to interpret laws and regulations in light of operations. Ensures all external regulatory frameworks are complied with within reasonable risk and cost parameters. Job Responsibilities Your responsibilities Together with the PO, push for and support in driving our communication with internal and external stakeholders, improving shared processes and way-of-working. Together with the team and PO, outline our areas of responsibility and how to grow our capabilities and functions, contribute to setting the strategies and processes, and Support our day-to-day operations of the monitoring and incident response functions. Based on the usage and impact of delivered features, evaluate and guide future developments. Your qualifications We believe you have a fair amount of the following experiences and competencies: Previous experience in a management position such as; Product Manager, PO, or Team Lead (required). Previous hands-on experience from the Cybersecurity, Information security, or Physical security arena (required). A structured and communicative working style, with the ability to balance business goals and technical constraints. The ability to align stakeholders around a clear product vision and delivery roadmap. Experience from the automotive industry Fluency in English is necessary; Swedish is a bonus. Security certifications such as CISM, CISSP, GIAC or similar are beneficial. Who You Are A team-player that wants to lead, communicate and shape the direction of our functional efforts, and responsibilities. You help drive our development and deliveries in a structured way, to meet our stakeholders’ expectations. You are a natural leader, complementing the existing PO and team in helping us maintain and push for set targets and beyond. You thrive from collaborating closely within the team, toward stakeholders and other teams. You navigate both operational and strategical perspectives with the ambition to create value. This Is Us We are a diverse team of specialists working in the cybersecurity area to maintain road security. Our task is to ensure our products stay safe, secure, and resilient to cybersecurity threats. We operate with high integrity and with dedication to our company core values; Respect, Responsibility, Elimination of waste, Team spirit, and Customer first. As a team we value knowledge sharing, dialogue, and a willingness to explore and find solutions together with our peers. We are in need of growing to help us drive the area alongside existing members, and want someone who is dedicated to contributing to raising the bar for product cybersecurity operations. Who am I, your manager? I am here to support you and our team of experts in being successful and taking the necessary steps towards fulfilling our goals and stakeholders’ expectation. I value spending time on building a safe work environment, one that engages people, grow team-spirit and trust. As our responsibilities are challenging, I safeguard transparency and collaboration. And I try to create an open, safe atmosphere where everyone is heard and where we are allowed to express ideas as well as concerns. As your manager, I prioritize work-life balance and the well-being of individuals and the team. TRATON Offers We offer a dynamic and engaging workplace where collaboration, innovation, and continuous improvement are part of everyday life. You will be part of a strong team environment that encourages knowledge sharing and close cooperation across functions. With a structured development plan and a wide range of training opportunities, TRATON Group R&D supports your professional growth both locally and internationally. Benefits include access to our health center in Gröndal or a wellness allowance, bonus, flexible working hours, and company car leasing. We also arrange events for employees and their families, and for those living in Stockholm, convenient commuting is supported through direct Scania Job express buses to Södertälje. Application We look forward to receiving your application, consisting of your CV and kindly ask you not to share a cover letter to ensure an efficient and unbiased recruitment process for all parties. Apply as soon as possible, no later than 2026-07-19. Screening will take place on an ongoing basis during the application period. Logical and personality tests may be used as part of the selection process, and a background check may be required for this role. If you have questions or would like more information, please contact: Jenny Holmqvist , Manager, Cybersecurity Monitoring and Incident Response, jenny.holmqvist@scania.com We look forward to your application! This recruitment process is handled by Scania for TRATON Group R&D
TL;DR: We're looking for an exceptional security leader and executive to build and run the function that will make Lovable the most trusted AI-powered software creation platform Why Lovable? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Lovable-built applications and websites are visited hundreds of millions of times a month, and our enterprise footprint is compounding fast. And we're just getting started. We're a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. What we're looking for 10+ years in information security, including 3+ years leading security at a high-growth SaaS or platform company A track record of building security programs from the ground up, including scaling through SOC 2, ISO 27001, or equivalent enterprise frameworks Deep technical fluency across cloud, application, and infrastructure security — comfortable going hands-on, not just directing others Experience partnering with engineering, legal, and sales to close enterprise deals and pass customer due diligence The judgment and communication skill to translate technical risk into business decisions for an executive team and board Experience securing platforms that generate or execute user-created code, or prior experience as a founding security hire at a startup What you'll do Own Lovable's security strategy and risk management framework end to end, reporting directly to the executive team Build and lead the security organization, starting with our first security engineers and analysts Get Lovable certified against the frameworks our enterprise customers require, including SOC 2 Type II and ISO 27001 Own application, infrastructure, and cloud security — secure SDLC, vulnerability management, incident response Partner with Sales and Customer Success to move security reviews and questionnaires from blocker to closer Build the security-first culture and training that lets a fast-moving engineering org stay fast without cutting corners Be the person our team, our customers, and regulators call when something needs an answer About your application Please submit your application in English. It's our company language, so you'll be speaking lots of it if you join. We treat all candidates equally - if you're interested, please apply through our careers portal.
Shape the future of cyber security in Atlantic Container Line AB Atlantic Container Line AB (ACL), part of the Grimaldi Group, is the world's oldest continuously operating container line and has been connecting Europe and North America since 1967. Operating the world's largest combination container and Roll-on/Roll-off (RORO) vessels, ACL is a key link in global trade. As our business continues to evolve, information security plays an increasingly vital role in supporting operational resilience, customer trust and regulatory compliance. We are now looking for our first in-house Chief Information Security Officer (CISO) to lead the next phase of our security journey. The opportunity This is a unique opportunity to build and shape the information security function within an international organization operating critical infrastructure and global supply chains. As CISO, you will own and drive ACL's information security agenda, providing strategic leadership while also taking a hands-on role in developing governance, processes and security capabilities. You will partner closely with executive leadership, internal stakeholders and external partners to establish a modern, risk-based approach to security that supports both business growth and regulatory requirements. You will play a key role in ensuring compliance with NIS2 and other relevant frameworks, while helping the organization strengthen its cyber resilience, security culture and overall maturity. Joining ACL at this stage means you will not be starting from scratch. Foundational work has already been established together with experienced external partners, providing you with a solid platform from which to further develop and embed security across the business. Key responsibilities: Lead and continuously develop ACL's information security strategy and roadmap. Drive implementation and ongoing compliance with NIS2, GDPR and related regulatory requirements. Establish and maintain policies, governance frameworks, risk management processes and security controls. Act as a trusted advisor to senior management and business stakeholders on security, risk and compliance matters. Coordinate security initiatives across ACL and within The Grimaldi Group. Manage relationships with external security partners, auditors and regulatory bodies. Support incident response, business continuity and cyber resilience planning. Drive security awareness and help build a strong security culture throughout the organization. Who you are You are a security professional who enjoys creating structure, influencing stakeholders and translating complex security requirements into practical business solutions. You combine strategic thinking with a pragmatic, hands-on approach and are comfortable working across organizational boundaries. You may already hold a CISO position or be ready to take the next step from a senior information security, cyber security or governance role. We believe you have: Several years of experience within information security, cyber security, governance, risk management or compliance. Good understanding of regulatory and security frameworks such as NIS2, ISO 27001, NIST or similar, as well as GDPR. Experience leading projects and driving initiatives across multiple stakeholders. Ability to communicate effectively with both technical specialists and business leaders. Experience working in an international environment. Professional proficiency in both English and Swedish. The following are considered advantageous: Experience from critical infrastructure, transportation, logistics or other regulated industries. Knowledge of cloud environments such as Microsoft Azure or Oracle Cloud. Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or similar. Why ACL? At ACL, you'll have the opportunity to make a genuine impact in a business that operates globally and plays an important role in international trade. You'll work closely with senior leadership, influence strategic decisions and help shape the future of security within a company where your expertise will matter from day one. We offer a collaborative international environment, short decision-making paths and the opportunity to build something lasting within a respected global organization. The position is based in Gothenburg and involves close collaboration with colleagues across Europe and North America. Some travel may be required. Recruitment process ACL is partnering with Ants Tech Recruiters in this recruitment. You’re welcome to reach out to Gabriella Hagström at gabriella.hagstrom@ants.se if you have any questions. As we're entering the summer holiday period, we'll continue the recruitment process in the middle of August. We look forward to your application. About ACL Atlantic Container Line AB, headquartered in Sweden, is part of the Grimaldi Group of Naples, Italy. Since 1967, ACL has operated continuous weekly transatlantic container and Roll-on/Roll-off (RORO) services between Europe and North America, making it the world's longest continuously operating container line. ACL operates the world's largest combination container and RORO vessels, among the world's greenest ships. Purpose-built with 100% cell-guides for containers above and below deck, as well as 100% underdeck RORO stowage, they offer a unique combination of efficiency and flexibility. Designed to accommodate cargo of virtually any size or weight, ACL's vessels transport everything from containers and vehicles to boats, aircraft, construction and agricultural equipment, and other oversized project cargo. With corporate teams based across Sweden, the UK, Belgium, Germany and the US, ACL combines global reach with specialist expertise to support customers with some of the world's most complex transportation needs.
Sida 1 av 20