Security Risk Management Lead

3 days ago


Stockholm, Stockholm, Sweden Grundfos GmbH Full time

Digital Architecture Team Member

Grundfos is looking for a highly skilled Security Risk Management Lead to join our Digital Architecture team.

The ideal candidate will have extensive experience in cybersecurity management, specifically in OT and IT security, risk assessment, and mitigation.

As a key member of our team, your primary focus will be on developing and enforcing robust risk management regimes, ensuring effective incident response, and promoting secure development practices across our product portfolio.

Main Responsibilities:

  1. Conduct assessments of projects and third-party vendors to ensure alignment with established cybersecurity standards and frameworks.
  2. Stay abreast of the latest cyber threats and vulnerabilities affecting OT and IT, and develop strategies to counteract these risks effectively.
  3. Ensure all development activities comply with IEC 62443-4-1, ISO 27001 and ISO 15288 standards, fostering a secure development lifecycle.
  4. Oversee and enhance information security processes in line with the Grundfos Information Security Management System (ISMS).
  5. Identify, document, and monitor cybersecurity risks, maintaining comprehensive risk registers and facilitating the development of risk treatment plans for development teams.
  6. Manage and track identified product vulnerabilities, coordinating response and disclosure efforts as per Grundfos policy.
  7. Handle and complete third-party security questionnaires related to information security and risk assessments from suppliers and clients.
  8. Develop, implement, and execute incident response to address and mitigate security incidents effectively.
  9. Assist with penetration testing, threat modelling, and review of product security documentation to ensure robust security measures are in place.
  10. Collaborate with the Application Security (AppSec) program to provide expertise, support, and training within cybersecurity topics, ensuring product compliance with standards like ISO27001, IEC62443, CRA, RED DA, and others.
  11. Conduct regular training sessions and awareness programs for development teams to promote a culture of cybersecurity vigilance and best practices.
  12. Collaborate with cross-functional teams to develop and update cybersecurity policies and procedures, ensuring they are relevant and effective.
  13. Continuously evaluate and improve existing security measures, leveraging new technologies and methodologies to enhance overall security posture.
  14. Ensure ongoing compliance with applicable legal, regulatory, and industry standards, conducting periodic audits and assessments as required.
  15. Work closely with other departments, including IT, legal, and compliance, to ensure a unified approach to cybersecurity. Provide regular reports on security status and initiatives to senior management.

Requirements

To succeed in this role, you will need:

  • A relevant technical degree related to Information Security, Computer Science, or Cybersecurity.
  • More than 5 years of experience with identifying, assessing, and managing information security risks related to physical products.
  • Experience with the technical context of IT systems, network security, encryption, and other technical aspects of information security.
  • Experience with OT (embedded & Linux) product development.
  • Understanding of cybersecurity in the scope of an end-2-end architecture within software development environments.
  • CISSP, CISM, CISA, CSSLP, or similar certifications is a plus.
  • Proficiency in security tools, forensic analysis, and incident detection and response technologies and methods.
  • Familiarity with legal and regulatory requirements related to data protection and incident reporting.
  • Strong analytical skills for incident investigation, data analysis, and threat identification.
  • Excellent communication and cross-collaboration skills.
  • Proficiency in English.


  • Stockholm, Stockholm, Sweden Qliro Group Full time

    About Qliro GroupWe are Qliro Group, a company dedicated to delivering safe and simple payment solutions. Our team is passionate about empowering our merchants to succeed in a fast-paced market. We believe in creating a collaborative and supportive work environment that fosters growth and innovation.About the RoleWe are seeking an experienced Chief...


  • Stockholm, Stockholm, Sweden TN Sweden Full time

    Job Overview:We are seeking an experienced professional to fill the role of Global Security Risk Manager. As a key member of our team, you will be responsible for conducting country security risk assessments and owning the destination level risk matrix.About the Role:Conduct in-depth security risk assessments of existing and potential destinationsDevelop and...


  • Stockholm, Stockholm, Sweden SEB group Full time

    We are seeking an Information Risk Manager to join our team at SEB Group in Stockholm. As a key member of the Security Governance department, you will contribute to developing and implementing effective security strategies that align with business objectives and regulatory requirements.About the JobYou will be responsible for identifying and mitigating...


  • Stockholm, Stockholm, Sweden SAS - Scandinavian Airlines Full time

    SAS Scandinavian Airlines is looking for an experienced Information Security Lead to join our team. As an Information Security Lead, you will be responsible for developing and implementing cybersecurity strategies and policies, overseeing and driving cyber risk management processes, and aligning key stakeholders on cybersecurity policies, data privacy.You...


  • Stockholm, Stockholm, Sweden Stegra Full time

    As a pioneering company, Stegra is committed to sustainability and innovation. We are seeking an experienced Information Security Manager to join our team and help us achieve our goals.The successful candidate will be responsible for developing and implementing a comprehensive security strategy that aligns with our business objectives. This includes creating...


  • Stockholm, Stockholm, Sweden TN Sweden Full time

    ResponsibilitiesThe Senior Cyber Risk Manager will be responsible for:Leading a team of cyber security professionals in driving the PCI program, security related internal and external audits, technical security architecture providing compliance to the business and delivery units.Developing and maintaining strong relationships with business stakeholders to...

  • ICT Risk Manager

    3 weeks ago


    Stockholm, Stockholm, Sweden Nordnet Bank AB Full time

    Nordnet is a leading pan-Nordic digital platform for savings and investments. Ever since our start in 1996, our purpose has been to democratize savings and investments. Through passion, simplicity, and transparency, we challenge traditional ways in the financial industry, and give private savers access to the same information, tools and services as...

  • IT Security Manager

    4 days ago


    Stockholm, Stockholm, Sweden Scandinavian Airlines System SAS Full time

    About the RoleThe IT Security Manager will play a vital part in ensuring cyber security and data protection across SAS operations. As a member of our Cybersecurity Skill Hub, you will be responsible for developing and enhancing cyber and data security policies, control objectives, controls, risk management processes, and standards.Your key responsibilities...


  • Stockholm, Stockholm, Sweden emagine GmbH Full time

    We are looking for a highly skilled Security Compliance Manager to join our team at emagine GmbH. As a key member of our security team, you will be responsible for developing and implementing security policies and procedures that align with industry standards and regulations.Main ResponsibilitiesDevelop and Implement Security Policies: Design, review, and...


  • Stockholm, Stockholm, Sweden SAS - Scandinavian Airlines Full time

    SAS Scandinavian Airlines is committed to achieving net-zero emissions by 2050. To support this goal, we're seeking a Risk Management Specialist to join our team. The ideal candidate will have a strong background in risk management and experience in either data privacy management or cybersecurity management.In this role, you'll be responsible for developing...


  • Stockholm, Stockholm, Sweden emagine GmbH Full time

    We are looking for a seasoned Information Security Lead to develop and implement our security vision and strategy. This role requires a strategic leader who can manage enterprise-wide risk frameworks, ensure compliance with legal standards, and address security incidents effectively.Key RequirementsProven Experience: 5-10 years of experience in IT security...

  • Cyber Risk Manager

    3 days ago


    Stockholm, Stockholm, Sweden Avida Finans AB Full time

    Avida Finans AB is a leading consumer and SME financier delivering exceptional customer experiences digitally and personally. As an Information Security Officer, you will be part of our IT management team, reporting directly to the CIO.Your primary responsibilities will include:Maintaining and driving a documented process for regular tests of Disaster...


  • Stockholm, Stockholm, Sweden TN Sweden Full time

    Job Summary:We are seeking an experienced Security Operations Lead to join our team. The successful candidate will be responsible for overseeing the implementation of security protocols and procedures across various destinations.About the Role:Develop and implement effective security protocols and proceduresConduct regular risk assessments of existing and...


  • Stockholm, Stockholm, Sweden emagine GmbH Full time

    About the RoleWe are looking for a seasoned Information Risk Manager to join our team and take on the responsibility of managing enterprise-wide risk frameworks.The successful candidate will have excellent communication skills, with the ability to work closely with key stakeholders to identify and assess risks, and develop strategies to mitigate them.This...


  • Stockholm, Stockholm, Sweden SEB group Full time

    About the RoleAs a key unit within SEB Life, Risk Management plays a vital role in coordinating risk management activities across the SEB Insurance Group. Our team in Sweden consists of seven specialists covering Operational Risk, Third-Party Management, Data Privacy, Security & Information Security, and Customer Complaints.You will work closely with...


  • Stockholm, Stockholm, Sweden emagine GmbH Full time

    At emagine GmbH, we are seeking an experienced IT Risk Professional to join our security team. The ideal candidate will have a strong background in IT security, particularly within a multinational environment.Main ObjectivesDevelop and Implement Security Policies: Develop and implement robust security policies and procedures that align with industry...


  • Stockholm, Stockholm, Sweden TN Sweden Full time

    Welcome to VIPAS AB, where we empower professionals to excel in the field of IT security. As a Digital Risk Manager, you'll play a critical role in helping clients mitigate cyber threats and ensure the security of their information systems.About VIPASOur team of experts is dedicated to providing exceptional service and delivering tailored solutions that meet...


  • Stockholm, Stockholm, Sweden atNorth Holding AB Full time

    About the RoleAt atNorth Holding AB, we're seeking an experienced security professional to lead and optimize our physical security system deployment in a cutting-edge environment. As a Security Systems Manager, you'll oversee and enhance security systems across our Nordic data centers, remote offices, and in support of our employees.In this role, you will...


  • Stockholm, Stockholm, Sweden Musikwoche Full time

    We're seeking an experienced Information Security Lead to join our team at Snowprint Studios.This role plays a vital part in ensuring the security and integrity of our gaming experience.About the JobIn this critical position, you will oversee the implementation and maintenance of endpoint security tools like XDR. You will collaborate with our teams to...


  • Stockholm, Stockholm, Sweden Internet Vikings Full time

    Join Internet Vikings as an Information Security ManagerAt Internet Vikings, openness is a core part of our culture – we believe it fosters growth and development. Internet Vikings is a provider of licensed in-state hosting for the sports betting and iGaming sector.Your RoleAs an Information Security Manager at Internet Vikings, you will play a key role in...