
Spektrum · Ramstein
Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to...
Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent
to our team and look forward to hearing from you.
Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a
wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales,
delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.
Who we are supporting
The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and
information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is
headquartered in Brussels, Belgium.
systems against cyber threats.
operations.
between NATO forces.
to its communication networks.
and servers.
Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information
technology capabilities.
The program
Assistance and Advisory Service (AAS)
The NATO Communications and Information Agency (NCI Agency) is NATO’s principal C3 capability deliverer and CIS service provider.
It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult
together under Article IV, and, when required, stand together in the face of attack under Article V.
To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high
performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International
Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI
Agency workforce and make up approximately 15 percent of the total workforce.
Role ID –C004920
Role Background
The Cyber Security Officer is responsible for designing, implementing, and
maintaining cyber security solutions that protect the organization's information
systems and infrastructure. The role supports secure system development, risk
management, security operations, compliance activities, and incident response while
leading a small Cyber Security and COMSEC team. The position works closely with
stakeholders and the NATO Cyber Security Centre (NCSC) to ensure systems comply
with NATO security policies and operational requirements.
Role Duties and Responsibilities
Design, develop, implement, test, and maintain secure information systems
throughout the system development lifecycle.
Develop cyber security solutions that meet operational and business requirements.
Work with stakeholders to translate business and functional requirements into secure
technical solutions.
Apply and maintain security controls in accordance with organizational policies and
local risk assessments.
Perform risk assessments for information systems and identify security risks.
Recommend security improvements and mitigation strategies for identified risks.
Define and maintain secure system configurations that comply with approved
architectures.
Support the investigation of cyber security incidents, suspected attacks, and security
breaches.
Lead and supervise a team of 3–4 Cyber Security and COMSEC personnel.
Manage Cyber Security operations as the Cyber Security Section Head.
Coordinate cyber security activities with the NATO Cyber Security Centre (NCSC).
Oversee boundary protection, data loss prevention, endpoint protection, and
enterprise anti-malware solutions.
Plan, schedule, coordinate, and facilitate cyber security audits and inspections.
Manage corrective actions resulting from security audits and inspections.
Supervise security monitoring, testing, evaluation, and accreditation activities for
information systems.
Plan and implement cyber security services to support Agency business units.
Deputize for senior staff when required.
Perform additional duties as assigned.
Support physical tasks, including lifting equipment up to 25 lbs when required.
Essential Skills, Experience and Certifications
Strong knowledge of cyber security principles, system security, and security
architecture.
Windows Server security hardening and compliance management.
Network security, firewall technologies, VPNs, intrusion detection, and forensic
tools.
Security governance, risk management, and vulnerability management.
Security incident response and investigation.
Data Loss Prevention (DLP) and endpoint security management.
Security audit coordination and compliance management.
Server, network, and storage virtualization technologies.
Public Key Infrastructure (PKI).
Cloud technology fundamentals.
Strong analytical and problem-solving skills.
Ability to work independently and manage multiple priorities.
Excellent written and verbal communication skills.
Positive customer-focused attitude with strong interpersonal skills.
Ability to perform effectively in high-pressure environments.
Familiarity with ITIL service management processes.
Basic understanding of Disaster Recovery (DR) and Business Continuity (BC).
Experience
Minimum 5 years' experience in Windows Server security hardening.
Minimum 3 years' experience with Trellix ePolicy Orchestrator and Trellix Endpoint
Security (or equivalent endpoint security platform).
o System security
o Security architecture
o Network security engineering
o Security governance
o Risk management
o Windows Server 2016, 2019 and 2022
o Windows 10 and Windows 11
o Palo Alto Enterprise Firewalls
o Trellix/McAfee Endpoint Security solutions
o Vulnerability scanning tools such as Nessus
o VMware vSphere, ESX, NSX and vSAN
o Wireless LAN security
o Mobile endpoint security
o Supporting NATO Enterprise CIS environments
Previous experience working in an international military and civilian environment
is desirable.
Education
Bachelor's degree in Cyber Security, Information Technology, Computer Science,
or a related discipline.
OR
At least 6 years of extensive and progressive experience in a closely related cyber
security role.
Certifications
Mandatory
CISM or CISSP
Preferred
CGRC/CAP, CASP+, Cloud+, PenTest+, Security+, GSEC, CISA, CISSO, CPTE,
CySA+, FITSP-A, GCSA, CISSP-ISSEP, GSLC, GSNA, CEH, GIAC certifications
ITIL Foundation (v3 or v4)
NATO COMPUSEC Practitioner Level 1 (0731)
NATO COMPUSEC Practitioner Level 2 (0732)
NATO CIS Security Officer (0280)
Language
English Level B2–C1 (NATO STANAG 6001 Level 3333).
Working Location
Location: Ramstein, Germany
Work Arrangement: Full-time, primarily on-site
Remote work may be permitted only with prior Agency approval and project
requirements.
Some physical duties may be required, including lifting up to 25 lbs.
Working Policy
Employment Type: Full-time Contract
Contract Duration: 30 August 2026 – 30 December 2026
Weekly Working Hours: 38 hours per week
Working Days: Monday to Friday
Daily unpaid lunch break in accordance with local regulations.
Contractor must maintain valid personal liability and comprehensive insurance.
Must be available during agreed working hours.
Must comply with all Agency security, information assurance, and data protection
policies.
Reliable communication and secure access to Agency systems are required
throughout the assignment.
Travel
Some travel to other NATO sites may be required
Security Clearance
Valid NATO Cosmic Top Secret (CTS-A / COSMIC TOP SECRET ATOMAL)
security clearance at the time of submission and throughout the contract.
We never know what new opportunities might be just over the horizon. If this opportunity isn't for you, please feel free to send
us your resume anyway and be the first to know if something suitable for your skills and experience comes up.
Northmill Bank is a challenger bank at the intersection of technology and finance, committed to revolutionizing the way people manage and protect their financial well-being. We are creating a different kind of banking experience, digital yet personal. Northmill Bank was founded in 2006 and have grown to over 240 employees in 3 countries, 4 000 merchants and 600 000 end users. We use the latest technology to develop safe, smart, and user-friendly products for our customers. They are the sole reason why we do what we do. We are a 100% cloud-based product company where technology is the driver to create smarter banking products. Grab this opportunity to be a part of us and our journey! About the role The Information Security Officer is subject matter expert, and a member of the Information Security team in the second line of defense. The team is tasked to provide governance, oversight and guidance, meaning to ICT write policies, and monitor and control first line’s compliance towards these policies. The team also has a number of security capabilities that we provide ourselves, such as technical security scanners or security training activities. While the team’s primary responsibility is governance, oversight, this is a small bank and you will also play a hands-on role in driving security initiatives, designing procedures, and building security capabilities. You will directly influence the secure design of systems, support risk management, and respond to security incidents. Much of information security material needs a significant rewrite, so this role comes with a great opportunity to use prior experience to influence the Bank’s ways of working, risk appetite and ultimately its risk posture. You will have a blank canvas to modernize our security framework, moving us from legacy documentation to a lean, ISO 27001-aligned 'Version 2.0.' This is a rare opportunity to use your experience to directly shape the Bank’s ways of working, risk appetite, and long-term security posture. What you will do Translating information security requirements into practical, effective, and business-aligned policies, procedures, guidelines or strategies. Northmill is both a bank and payment provider in multiple European regions, and also has a number of business requirements affecting information security. Monitor compliance for our internal information security rules and our applicable business and regulatory requirements. DORA, GDPR, PSD2, FFFS, Visa, Swift, Swish, Bankgirot, Rixbanken, etc. Structure information security requirements in the ISMS in alignment with the ISO 27001 standard. Act as an advisor and lead for information, cyber security, or privacy incidents. Serve as a subject matter expert within privacy and data protection Act as subject matter expert in relation to our PCI-DSS certification and conduct readiness assessments towards the business. Keep track of that recurring tasks are performed as needed. Contribute to reporting towards supervisory authorities (e.g. SFSA, IMY, FIN-FSA) Ensure that the organization has relevant security awareness and training in place Lead and participate in Business Impact Analysis, ICT vendor approval, the Register of Information, Critical and Important functions, ICT Risk assessments, Data Protection Impact Assessments, IA-act risk assessments, NPAP, and various GAP analyses. What we are looking for Experience working as an Information Security Officer or in a similar role Hands-on experience in developing policies, procedures, and security frameworks A pragmatic mindset and a strong understanding of how to balance regulatory requirements with business needs Strong problem-solving skills and the ability to operate in a dynamic environment A collaborative approach and willingness to work closely with different parts of the organization Professional proficiency in both Swedish and English (Finnish or German is a plus) Based in Stockholm, with EU/EEA residency or citizenship Certifications such as CISM or ISO 27001 Lead Implementer are meritorious, but not required. What we offer A fantastic office in a prime Stockholm location with great spaces and views An independent role with the opportunity to make a real impact Great opportunities for professional development Health - 5 000 kr health care allowance Conference abroad every other year Breakfast and fruits every day, as well as "holy fika” each Friday Regular after work and celebrated successes at the office Apply today and be a part of Northmill!
At Securitas, Digital Security (Cyber Security) is focused on protecting our systems, applications, data, and services while enabling secure and reliable business operations. All countries within our scope are either certified against ISO/IEC 27001 or actively implementing it, ensuring a consistent and structured approach to information security management across the organisation. Your Role – Cluster Digital Security Officer (Cluster North) As a Cluster Digital Security Officer, you will support the technical execution, coordination, and oversight of Digital Security across Cluster North (Sweden, Norway, Finland, Denmark, the UK, and Ireland), while also contributing to Group/ Division-level security priorities. This is a hands-on, operational role, delivered as part of a wider Digital Security organization. You will work closely with different Division/Group IT teams, Digital Security Operations, Digital Security, and Country IT teams, operating in a collaborative, multi-country and multi-layer (Cluster–Division–Group) environment. Key Responsibilities Security Coordination & Team Collaboration (Cluster & Division) Coordinate Digital Security activities across the Cluster and support execution of the security roadmap aligned with Division priorities, including application security initiatives Ensure consistent implementation of security controls, baselines, and services across infrastructure and applications Work closely with GITS, Application teams, Domain and other IT teams to ensure alignment and effective execution Contribute actively to the Digital Security community, including sharing practices related to application and platform security Provide regular, transparent, and data-driven reporting on risk posture, control effectiveness, and remediation progress Technical Security Oversight (Infrastructure & Applications) Monitor and assess the security posture of platforms, infrastructure, and applications (on-prem and cloud) Oversee key control areas including vulnerability management, patching, identity and access management, endpoint security, and application security Support secure practices across the application lifecycle (SDLC), including awareness of secure design and common vulnerabilities (e.g. OWASP Top 10) Ensure effective logging, monitoring, and incident detection capabilities are in place across infrastructure and applications Track and assess third-party and supplier risks, including risks related to applications and integrations Risk, Compliance & Assurance Identify and track gaps against security policies, standards, and mandates, including application security requirements Support/execute risk assessments, internal and external audits, and customer assurance activities across Cluster environments Drive and follow up on risk remediation plans, ensuring clear ownership and execution across technical teams Securitas Alarm Monitoring Centers (SOC) Security In addition to Cluster responsibilities, you will contribute to Division-level security of Securitas Alarm Monitoring Centers (SOCs) supporting the Domain Digital Security Officer SOC and RVS, which are among the most critical environments within Securitas. This includes: Supporting and overseeing the security posture of SOC environments, including underlying infrastructure and supporting applications Ensuring implementation of enhanced technical controls (e.g. network segmentation, strong access control, privileged access management, monitoring, and secure application access) Monitoring the availability, integrity, and protection of SOC systems, applications, and data flows Supporting incident detection, response readiness, and recovery capabilities for SOC-related platforms and applications Working closely with Infrastructure, Application, SOC and other IT teams to reduce attack surface and strengthen resilience of SOC environments Ideal Candidate Profile We are looking for a candidate who combines technical understanding across infrastructure and applications, structured execution, and strong collaboration skills. Certifications (mandatory) CISSP or CISM or equivalent Experience & Knowledge 5–7 years of experience in Cyber Security, Information Security or Application Security Minimum of 2 years of experience in IT operations Good understanding of security domains (IAM, endpoint security, vulnerability management, logging/monitoring, network security, and application security) Solid understanding of application security principles, including secure development practices, common vulnerabilities (e.g. OWASP Top 10), and risks in application architecture and integrations Good understanding of ISO 27001 standard Experience with risk management, audits, or compliance activities Understanding of infrastructure environments (networks, servers, cloud platforms) and their interaction with applications Technical & Analytical Skills Ability to assess security posture across infrastructure and applications and identify control gaps Comfortable working with security metrics, reports, and risk data Understanding of incident detection and response processes, including those impacting applications Ability to translate security requirements into practical and implementable actions across infrastructure and application teams
About Husqvarna We’re one of the world’s oldest start-ups — and we’re just getting started. At Husqvarna Group, innovation is in our DNA. With over 330 years of heritage and a passion for pioneering technology, we design and deliver world-class products and solutions for forest, park, garden and construction care. From robotic lawn mowers to cutting-edge chainsaws and sustainable battery systems, we’re shaping the future — and we want you to be part of it. About The Team You will join the Group Cyber and Information Security Office — a central function that sets the direction for cyber, information and product security across Husqvarna Group. Our responsibility covers both internal security — protecting our people, information, systems and ways of working — and product security, ensuring that the connected products and services we deliver to customers are secure, trusted and resilient. We create the governance, frameworks and common ways of working that help the business build security into everything we do. While the role is part of CISO organization, this is not a traditional Information Security or IT Security position. Instead, your focus will be on securing the connected products we design, develop and deliver to customers around the world. As our products become increasingly connected, cybersecurity becomes an essential part of the product lifecycle and customer experience. In this role, you will support all three business divisions — Husqvarna, Gardena and Construction — ensuring product security is embedded in everything we do. You will collaborate closely with Legal, Compliance, R&D and divisional Product Security Managers as well as senior business stakeholders to build a strong governance structure and drive consistent implementation across the Group. About The Role As Product Security Officer, you will play a key role in strengthening Husqvarna Group’s product security capabilities. You will report to the Chief Information Security Officer (CISO) and act as the central authority for product security across divisions. Your mission will be to set the direction, frameworks and follow-up structures needed to secure our increasingly connected and digital products. You will ensure that security is integrated throughout the entire product lifecycle while supporting the development of secure, connected products that meet both customer expectations and evolving regulatory requirements. A key and time-critical part of the role is to drive Husqvarna Group’s implementation of the Cyber Resilience Act (CRA). The goal is to establish the product security governance, processes and evidence needed for CRA readiness across divisions — with mandatory vulnerability and incident reporting applying from September 2026 and full CRA obligations applying from December 2027. You will play a central role in creating momentum, aligning stakeholders and ensuring that our ways of working evolve fast enough to meet these regulatory milestones and future market expectations. You will engage with stakeholders at all levels — from R&D engineers to executive leadership — and ensure that our security practices align with regulatory requirements, business needs, and market expectations. Success in this role depends just as much on your ability to influence people as on your technical expertise. You will drive change across the organization, build alignment with R&D and senior stakeholders, and help create momentum around product security initiatives—even when priorities compete. This is a role with great visibility and long-term potential: over time, you will be instrumental in shaping how Husqvarna Group builds trust in its products globally. This is a unique opportunity to influence how one of the world's leading manufacturers secures the next generation of connected products. About You You are a pragmatic and collaborative leader who thrives on making complex topics clear, actionable and easy to understand. With a positive, solution-oriented mindset, you know how to simplify challenges while creating meaningful impact across the organization. You excel at building trust and influencing others without formal authority, enabling you to drive change and create momentum in a complex, global environment. You are confident challenging stakeholders when needed, while maintaining strong relationships and bringing people together around shared goals. Comfortable operating at both a strategic and technical level, you enjoy collaborating with cross-functional teams and turning strategy into practical action. You combine strong stakeholder management skills with the ability to navigate ambiguity, inspire confidence and ensure that security becomes an integral part of the way products are developed Your Skills And Background • Extensive experience working with product security for connected products, including product security governance, secure product development and regulatory requirements such as the Cyber Resilience Act. • Experience from industries such as automotive, consumer electronics, home appliances, industrial equipment, IoT, embedded systems or other connected product environments is highly valued. • Experience from R&D, product development or engineering environments is especially important — even more than a traditional security background — combined with the ability to lead cross-functional teams and translate security needs into practical product development actions. • Experience from product development, R&D or application development environments — with the ability to “speak the language” of engineers and developers. • Experience collaborating closely with R&D and product development organizations. • Proven ability to influence without formal authority and align multiple stakeholders towards common goals. • Confidence in engaging with senior leadership and executive forums. • Experience establishing governance, frameworks and ways of working that create long-term business value. • A collaborative and agile mindset, with respect for autonomous teams and modern ways of working. Location This position will be based at one of our sites in Sweden: Huskvarna, Stockholm, or Jonsered. More info in the job application link.