Payments Security Specialist

2 weeks ago


Stockholm, Stockholm, Sweden H&M Group Full time
H&M Group We are a family of brands, driven by our desire to make great design available to everyone in a sustainable way.

View company page

H&M is a fashion brand that offers the latest styles and inspiration, from fashion pieces and unique designer collaborations to affordable wardrobe essentials. Our business idea is fashion & quality at the best price in a sustainable way. Learn more about H&M here .

Job Description

Payment at H&M is supported by two teams, Payment Enablement Store and Payment Enablement Online. The teams operate in the component layer that is responsible for producing secure, composable payment solutions in a cost-efficient manner and as per completive time-to-market delivery timelines. The team collaborates closely with the experience layer which are responsible for the customer experience and the end-to-end value. Other important stakeholders' teams within Cyber Security who is over all responsible for governance and liaison with auditors and teams responsible for checkout in store and online and supporting vendors of these solutions.

Each team is managed by a Product Manager and are supported by Business Experts, Software Engineers, Technical Engineers, Program Managers, Solution Architects and Commercial Advisors.

The team's vision is to strive for fast, secure, and frictionless payments. With an agile mindset and a passion for technology, provide best in class services.

The team mission is to offer a relevant, smooth, and secure payment experience to customers visiting our stores and online channels.

You will be part of the team handling payment compliance (regulations and requirements), PCI DSS, PEN tests, risk assessments & mitigation and overall security of payment solutions in stores and online for all H&M brands worldwide.

You will work on assessing and addressing, planning, and coordinating all penetration test (PEN test) activities, from pre-test involvement in planning and environment preparation to post-test activities such as debriefs, mitigation, and remediation. Maintain a strong understanding of PCI compliance and provide support and coordination for related activities as needed. Collaborate with your team colleagues and relevant stakeholders to ensure proper compliance routines are followed, taking necessary actions to always maintain full payment security compliance in our store & online environments.

Qualifications

Key Responsibilities:

Ensure technical environment is maintained based on H&M objectives, guardrails, and security requirements.

Review security annexes answers of acquirers and PSP during RFI/RFP.

Attestation of Compliancy (AOC) (e.g new PSP, PCI audit) for new and existing PSPs.

Build Security Strategy for devices in store & online (emerging tech) incl. Security governance (of vendors).

Assurance of PCI compliance for hardware (Payment terminals), Assurance of PCI compliance for software (store) & solution (online).

Pre PEN tests (planning, booking, environ. Prep/MAC address, test lab), Security related solution updates (inc. whitelisting IP address, etc.).

Work on change in solutions for Payment infra & network (setup, traffic, security) NME

Be a Payment Audit Coordinator & Security Assessment vulnerability SPOC (PCI, Security etc.) for payments & mitigate & risk involved.

Work on PCI & post-audit reporting and mitigation, Security Vulnerability Assessment (online).

Plan and implement New payment method launch that needs approval submission of GDPR ROPA, etc.

Ensure country specific compliance of payment methods are met and adhered.

Work on Security incidents as required / raised by different teams.

Review security section of Solution Architecture document (SAD) before yearly PCI Audit and change of new PSP/Acquirer.

  • Work on Self-Checkout placeholder (PCI audit, pen test, E2E solution) semi-attended kiosk.

Qualifications:

5-7 years of experience in payment security, with a focus on penetration testing and PCI DSS compliance.

In-depth knowledge and hands-on experience with Payment Card Industry Data Security Standard (PCI-DSS) and PCI PIN Transaction Security (PCI-PTS) requirements.

Strong understanding of Information Security Management Systems, particularly ISO 27001, and familiarity with National Institute of Standards and Technology (NIST) cybersecurity frameworks.

Demonstrate expertise in international standards for information security.

Familiarity with the General Data Protection Regulation (GDPR) and its implications for data protection and privacy.

Demonstrate a robust skill set for auditing, information security management, and internal control crucial for maintaining compliance and security in payment environments.

Experience assisting auditors in setting up and running tests, providing necessary documentation, and facilitating the audit process.

Additional Information

This is a full-time position based in our Liljeholmen Office in Stockholm.

Last date of application is 10th of May but we aim to start interview process as soon as CVs come in.

Due to GDPR regulation, we do not accept any applications via email.

We strive to have a fair and equal process and therefore kindly ask you not to attach a cover letter in your application as they often contain information that easily can trigger unintentional biases.

Benefits:
We offer all our employees at H&M Group attractive benefits with extensive development opportunities around the globe. All our employees receive a staff discount card, usable on all our H&M Group brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET, Afound. In addition to our staff discount, all our employees are included in our H&M Incentive Program – HIP.

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Stockholm, Stockholm, Sweden Wolt Development Sverige AB Full time

    Wolt is looking to expand its Security team by hiring an Information Security Specialist to help us build an even more secure Wolt Perhaps we could do that with your help? You'll be joining Wolt's security team's Governance, Risk and Compliance (GRC) focus area, developing our information security management system to the next level. At Wolt we believe that...


  • Stockholm, Stockholm, Sweden CGI Full time

    Position Description:We are seeking an experienced Senior Business Analyst - Payments to collaborate with clients, propose solutions, and tackle challenges within projects. Join CGI's team to work with top Banking clients worldwide and make a positive impact on people's lives while advancing your career.Your future duties and responsibilities:In this role,...


  • Stockholm, Stockholm, Sweden BAUHAUS & Co KB IT Full time

    IT Security SpecialistAre you passionate about IT security? Do you have experience in managing security projects and ensuring compliance with industry standards and regulations? If so, you might be the IT security specialist we are looking forYour Responsibilities:Overseeing the security strategy and policies of BAUHAUS in the Nordics - a leading retailer of...

  • Security Engineer

    2 weeks ago


    Stockholm, Stockholm, Sweden Trustly Full time

    Trustly Trustly, as a simple and fast online banking payments solution, enables consumers and merchants to carry out in and out payments using their bank account. View company page Trustly is leading the human-centric payments revolution. To us, this means passionately building the most convenient, intelligent and responsible way of paying for things...


  • Stockholm, Stockholm, Sweden BAUHAUS & Co KB Servicecenter Full time

    IT Compliance SpecialistAre you passionate about IT processes and compliance? Do you have experience in ensuring compliance with security standards and regulations? If so, you might be the IT Compliance Specialist that we are looking forYour responsibilitiesAs an IT Compliance specialist, you will be responsible for compliance documentation and IT work...


  • Stockholm, Stockholm, Sweden BAUHAUS & Co KB IT Full time

    IT Compliance SpecialistAre you passionate about IT processes and compliance? Do you have experience in ensuring compliance with security standards and regulations? If so, you might be the IT Compliance Specialist that we are looking forYour responsibilities:As an IT Compliance specialist, you will be responsible for compliance documentation and IT work...

  • Security Engineer

    2 weeks ago


    Stockholm, Stockholm, Sweden Trustly Full time

    Trustly is leading the human-centric payments revolution. To us, this means passionately building the most convenient, intelligent and responsible way of paying for things online. Whether it's for shopping, paying subscriptions, funding trading accounts, booking airfare, playing online games and much more – we're all about a better way to pay. At our core,...


  • Stockholm, Stockholm, Sweden Epiroc Full time

    Epiroc is a leading productivity partner for the mining, infrastructure and natural resources industries. With cutting-edge technology, Epiroc develops and produces innovative drill rigs, rock excavation and construction equipment, and provides world-class service and consumables. The company was founded in Stockholm, Sweden, and has passionate people...

  • Security Engineer

    2 weeks ago


    Stockholm, Stockholm, Sweden Trustly Full time

    Trustly is leading the human-centric payments revolution. To us, this means passionately building the most convenient, intelligent and responsible way of paying for things online. Whether it's for shopping, paying subscriptions, funding trading accounts, booking airfare, playing online games and much more – we're all about a better way to pay. At our core,...


  • Stockholm, Stockholm, Sweden Wolt Full time

    Job DescriptionWolt is seeking to expand its Security team by hiring an Information Security Specialist to help enhance the security measures at Wolt. You'll join Wolt's security team's Governance, Risk, and Compliance (GRC) focus area. Your role involves developing the information security management system to a higher standard. At Wolt, we believe in...


  • Stockholm, Stockholm, Sweden A-hub Full time

    Are you ready to take the next stop in your role as Cyber Security Specialist?Are you interested in working in a tech scale up that are working with the future of technology?ABOUT THE COMPANYExeger is making sustainable energy more accessible for people around the globe with the vision to touch the lives of a billion people by 2030. Their solar cell,...


  • Stockholm, Stockholm, Sweden Nordea Bank Full time

    Job ID: 19306We are looking for an IT Security Specialist with an analytical mindset to join our Identity and Access Management (IAM) organisation. This is an opportunity for you to be part of an international team, eager to support our mission to Protect the Bank: De-risked, Compliant, Secure & Protected.About this opportunityAt IAM we provide centralised...


  • Stockholm, Stockholm, Sweden Nordea Bank Full time

    Job ID: 19306We are looking for an IT Security Specialist with an analytical mindset to join our Identity and Access Management (IAM) organisation. This is an opportunity for you to be part of an international team, eager to support our mission to Protect the Bank: De-risked, Compliant, Secure & Protected.About this opportunityAt IAM we provide centralised...

  • Card Specialist

    2 weeks ago


    Stockholm, Stockholm, Sweden Qliro Full time

    Are you passionate about providing excellent service while guarding against potential risks? We are currently in search of a highly analytical individual with a technical background to be part of our fraud team as a Fraud Prevention Card Specialist.As a Card Specialist in our Fraud team, your main task will be setting up fraud alerts to spot suspicious...


  • Stockholm, Stockholm, Sweden H&M Group Full time

    Cyber Security Culture – Communication and Content Specialist H&M Group We are a family of brands, driven by our desire to make great design available to everyone in a sustainable way. View company page H&M Group is transforming the way it addresses the continuously evolving and complex cyber security threats and risks. To do this we have created a new...


  • Stockholm, Stockholm, Sweden Innofactor Full time

    Innofactor utökar säkerhetsteamet med en Security Specialist inom M365 För oss på Innofactor är säkerhet A och O, och vårt mål är att bygga Sveriges mest kompetenta säkerhetsteam. Vill du arbeta med riktigt kompetenta kollegor i en organisation där vi låter våra medarbetare växa och bli bäst genom ständig utveckling och lärande av varandra?...


  • Stockholm, Stockholm, Sweden Acttif Full time

    Select how often (in days) to receive an alert: Remuneration Specialist Location: SE Employment Type: Permanent Driven by our vision of 'Progress for Humanity' – at Hyundai we work relentlessly to make high-quality, environmentally-friendly mobility available for all. The industry is re-inventing itself and we plan to lead this change with...

  • Security Specialist

    2 weeks ago


    Stockholm, Stockholm, Sweden CO-WORKER TECHNOLOGY Full time

    Job description:We are seeking a skilled and experienced PKI and Certificate Services Consultant to join our team. The ideal candidate will have in-depth knowledge of Public Key Infrastructure as a service(PKIaaS), and has indepth technical knowledge on Sectigo, Microsoft Certificate Services, and integrations with mobile device management solutions such as...

  • Security Specialist

    2 weeks ago


    Stockholm, Stockholm, Sweden Co-Worker Consulting Partner Sweden AB Full time

    Job description:We are seeking a skilled and experienced PKI and Certificate Services Consultant to join our team. The ideal candidate will have in-depth knowledge of Public Key Infrastructure as a service(PKIaaS), and has in-depth technical knowledge on Sectigo, Microsoft Certificate Services, and integrations with mobile device management solutions such as...


  • Stockholm, Stockholm, Sweden Hamlyn Williams Full time

    Our client is a Cyber Security Consultancy is undergoing massive growth and they are looking for a number of Information Security Officers / Consultants (Medior & Senior) to join their team in StockholmJob DescriptionDocumenting and managing risks related to IT systems and compliance with internal and external requirementsPerform both consulting, advisory...