Information Security Director

15 hours ago


Stockholm, Stockholm, Sweden Grundfos GmbH Full time

About Our Company

At Grundfos GmbH, we are committed to pioneering solutions to the world's water and climate challenges and improving the quality of life for people.

We are seeking a skilled Information Security Director to join our Digital Architecture team and drive security excellence across our product portfolio.

Your primary focus will be on establishing and enhancing security frameworks, enforcing robust risk management, and promoting secure development practices within our software development divisions.

Main Responsibilities:

  1. Establish and enhance security frameworks, including implementation, maintenance, and continual improvement of the Grundfos Information Security Management System (ISMS).
  2. Develop and enforce a rigorous risk management regime to conduct, coordinate, register, document, and report relevant information security risks.
  3. Ensure effective responses to and management of information security incidents, minimizing impact and ensuring swift recovery.
  4. Promote secure development practices within software development divisions, aligning with industry standards and best practices.
  5. Collaborate with cross-functional teams to ensure compliance with legal, regulatory, and industry standards, contributing to the overall security posture of Grundfos.
  6. Conduct assessments of projects and third-party vendors to ensure alignment with established cybersecurity standards and frameworks.
  7. Stay abreast of the latest cyber threats and vulnerabilities affecting OT and IT, and develop strategies to counteract these risks effectively.
  8. Ensure all development activities comply with IEC 62443-4-1, ISO 27001 and ISO 15288 standards, fostering a secure development lifecycle.
  9. Oversee and enhance information security processes in line with the Grundfos Information Security Management System (ISMS).
  10. Identify, document, and monitor cybersecurity risks, maintaining comprehensive risk registers and facilitating the development of risk treatment plans for development teams.
  11. Manage and track identified product vulnerabilities, coordinating response and disclosure efforts as per Grundfos policy.
  12. Handle and complete third-party security questionnaires related to information security and risk assessments from suppliers and clients.
  13. Develop, implement, and execute incident response to address and mitigate security incidents effectively.
  14. Assist with penetration testing, threat modelling, and review of product security documentation to ensure robust security measures are in place.
  15. Collaborate with the Application Security (AppSec) program to provide expertise, support, and training within cybersecurity topics, ensuring product compliance with standards like ISO27001, IEC62443, CRA, RED DA, and others.
  16. Conduct regular training sessions and awareness programs for development teams to promote a culture of cybersecurity vigilance and best practices.
  17. Collaborate with cross-functional teams to develop and update cybersecurity policies and procedures, ensuring they are relevant and effective.
  18. Continuously evaluate and improve existing security measures, leveraging new technologies and methodologies to enhance overall security posture.
  19. Ensure ongoing compliance with applicable legal, regulatory, and industry standards, conducting periodic audits and assessments as required.
  20. Work closely with other departments, including IT, legal, and compliance, to ensure a unified approach to cybersecurity. Provide regular reports on security status and initiatives to senior management.

Requirements

To succeed in this role, you will need:

  • A relevant technical degree related to Information Security, Computer Science, or Cybersecurity.
  • More than 5 years of experience with identifying, assessing, and managing information security risks related to physical products.
  • Experience with the technical context of IT systems, network security, encryption, and other technical aspects of information security.
  • Experience with OT (embedded & Linux) product development.
  • Understanding of cybersecurity in the scope of an end-2-end architecture within software development environments.
  • CISSP, CISM, CISA, CSSLP, or similar certifications is a plus.
  • Proficiency in security tools, forensic analysis, and incident detection and response technologies and methods.
  • Familiarity with legal and regulatory requirements related to data protection and incident reporting.
  • Strong analytical skills for incident investigation, data analysis, and threat identification.
  • Excellent communication and cross-collaboration skills.
  • Proficiency in English.


  • Stockholm, Stockholm, Sweden Capgemini Full time

    Select how often (in days) to receive an alert:Director, Information Security & Security ProtectionChoosing Capgemini means choosing a company where you will be empowered to shape your career in the way you'd like, where you'll be supported and inspired by a collaborative community of colleagues around the world, and where you'll be able to reimagine what's...


  • Stockholm, Stockholm, Sweden Capgemini Full time

    Capgemini is seeking an experienced Information Security Director to join our team. As a key member of our organization, you will be responsible for leading security protection efforts and ensuring compliance with relevant regulations. You will work closely with clients and internal stakeholders to identify and mitigate potential security threats.Key...


  • Stockholm, Stockholm, Sweden Brite AB Full time

    About UsBrite AB is a leader in open banking-powered account-to-account (A2A) payment solutions, providing instant payments, payouts, and other financial services in Europe. Our mission is to create fast, secure, and transparent payment experiences that benefit both businesses and consumers.We operate a proprietary instant payments network, enabling...


  • Stockholm, Stockholm, Sweden Qliro Group Full time

    About Qliro GroupAt Qliro Group, we are dedicated to delivering safe and simple payments solutions. As a trusted partner to our merchants, we strive to provide an exceptional experience for their customers every day. Our team is passionate about empowering our merchants to grow, while fostering a culture of collaboration and mutual support.About the RoleWe...


  • Stockholm, Stockholm, Sweden Qliro Full time

    About QliroWe deliver safe and simple payments. As a dedicated partner to our merchants, we serve their customers every day. We believe that if our merchants grow, we grow.Our company culture is built around collaboration and empowerment. We strive to create a workplace that is diverse and inclusive, with employees from over 30 countries worldwide.Job...


  • Stockholm, Stockholm, Sweden Quinyx Full time

    Required Skills and QualificationsTo be successful in this role, you will need to have a degree in business administration or a technology-related field required. Additionally, you should possess professional security management certification and extensive experience in a combination of risk management, information security, and IT jobs.Desirable...


  • Stockholm, Stockholm, Sweden TN Sweden Full time

    TN Sweden is a global company that empowers people by providing intelligent solutions. We connect people, cities, businesses, and ideas through our network, voice, and data centre services.About the Job DescriptionThis job description outlines the key responsibilities and requirements for the position of Security Director Leader. The successful candidate...


  • Stockholm, Stockholm, Sweden H & M Hennes & Mauritz Gruppe Full time

    About the RoleThis full-time permanent position is based in our office in Stockholm, Sweden. As Cyber Security Director, you will lead and manage the Cyber Defence Center, ensuring the protection of our digital assets and compliance with relevant cyber security regulations and standards.


  • Stockholm, Stockholm, Sweden Ericsson GmbH Full time

    About the RoleWe are seeking an experienced Information Security Manager to join our BNEW Security Organization. As a key member of the team, you will be responsible for cultivating a 'Security and Business Resilience' mindset within BNEW, leading the BNEW Information Security core team, and driving operational excellence in information security posture.You...


  • Stockholm, Stockholm, Sweden Rotterdam Innovation City Full time

    Job DescriptionWe are seeking an experienced Chief Information Officer to join our team at Rotterdam Innovation City. As a key member of our leadership team, you will be responsible for developing and implementing a comprehensive enterprise information security and IT risk management program.The successful candidate will have extensive experience in a...


  • Stockholm, Stockholm, Sweden Internet Vikings Full time

    About the Role:We are looking for an experienced Information Security Executive to join our team at Internet Vikings. As an Information Security Manager, you will develop and implement our information security strategy.Your primary responsibilities will include leading efforts to identify, analyze, and mitigate security risks, ensuring compliance with...


  • Stockholm, Stockholm, Sweden Qbtech Full time

    Transforming healthcare requires a secure approach. As Information Security Officer at Qbtech, you will oversee the company's information security strategy and ensure that systems, data, and processes adhere to the highest security and compliance standards.The role is crucial in safeguarding sensitive healthcare information and maintaining customer trust....


  • Stockholm, Stockholm, Sweden TN Sweden Full time

    At VIPAS AB, we're shaping the future of IT consulting. Our mission is to guide organizations through their transformative digital journeys, tackling intricate challenges that arise.We find ourselves in perhaps the most exhilarating profession on the planet. As an Information Security Specialist, you'll be working with information systems security in...


  • Stockholm, Stockholm, Sweden Moventas Wind Ltd Full time

    About the RoleWe are seeking a seasoned Information Security Leader to join our team at Moventas Wind Ltd. As an Information Security Leader, you will be responsible for developing and implementing a comprehensive cybersecurity strategy that aligns with the company's overall business objectives.Background:Minimum of 5 years of working in cyber security,...


  • Stockholm, Stockholm, Sweden Northwave Full time

    About NorthwaveNorthwave is a visionary European Cyber Security specialist dedicated to delivering cutting-edge 24*7 cyber security services. With over 17 years of experience, we have perfected our integral approach, merging technology and human behavior expertise to offer customized solutions. As a trusted advisor, we support organizations in taking control...


  • Stockholm, Stockholm, Sweden Quinyx Full time

    About the RoleThe Chief Information Officer (CIO) is a senior-level executive responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected.This role involves developing integrated strategies and programs of work covering three key areas: information security,...


  • Stockholm, Stockholm, Sweden If Vahinkovakuutus Oyj Full time

    As an Information Security Specialist at If Vahinkovakuutus Oyj, you'll play a key role in embedding security into our CI/CD pipelines and engineering practices from the very beginning.You'll work closely with development teams to integrate security seamlessly into the software development lifecycle (SDLC).About the RoleIn this role, you'll design and...


  • Stockholm, Stockholm, Sweden La Fosse Full time

    About the PositionThis role offers a unique chance to make a significant impact on our clients' security posture by developing and implementing robust Information Security Management Systems (ISMS).As a key member of our team, you'll be responsible for assisting clients in identifying and mitigating risks, ensuring compliance with relevant regulations and...


  • Stockholm, Stockholm, Sweden Internet Vikings Full time

    Join Internet Vikings as an Information Security ManagerAt Internet Vikings, openness is a core part of our culture – we believe it fosters growth and development. Internet Vikings is a provider of licensed in-state hosting for the sports betting and iGaming sector.Your RoleAs an Information Security Manager at Internet Vikings, you will play a key role in...


  • Stockholm, Stockholm, Sweden Ericsson GmbH Full time

    Key QualificationsExperience in Information Security, IT Security, and Business Continuity managementExperience with Information Security standards and regulationsSelf-driven, results-oriented, and a team playerAnalytical mindset with problem-solving capabilities in the context of Information Security and IT security challenges