
Northmill Bank AB · Stockholm
Northmill Bank is a challenger bank at the intersection of technology and finance, committed to revolutionizing the way people manage and protect their financia...
Northmill Bank is a challenger bank at the intersection of technology and finance, committed to revolutionizing the way people manage and protect their financial well-being. We are creating a different kind of banking experience, digital yet personal.
Northmill Bank was founded in 2006 and have grown to over 240 employees in 3 countries, 4 000 merchants and 600 000 end users. We use the latest technology to develop safe, smart, and user-friendly products for our customers. They are the sole reason why we do what we do. We are a 100% cloud-based product company where technology is the driver to create smarter banking products.
Grab this opportunity to be a part of us and our journey!
About the role
The Information Security Officer is subject matter expert, and a member of the Information Security team in the second line of defense. The team is tasked to provide governance, oversight and guidance, meaning to ICT write policies, and monitor and control first line’s compliance towards these policies. The team also has a number of security capabilities that we provide ourselves, such as technical security scanners or security training activities.
While the team’s primary responsibility is governance, oversight, this is a small bank and you will also play a hands-on role in driving security initiatives, designing procedures, and building security capabilities. You will directly influence the secure design of systems, support risk management, and respond to security incidents.
Much of information security material needs a significant rewrite, so this role comes with a great opportunity to use prior experience to influence the Bank’s ways of working, risk appetite and ultimately its risk posture.
You will have a blank canvas to modernize our security framework, moving us from legacy documentation to a lean, ISO 27001-aligned 'Version 2.0.' This is a rare opportunity to use your experience to directly shape the Bank’s ways of working, risk appetite, and long-term security posture.
What you will do
Translating information security requirements into practical, effective, and business-aligned policies, procedures, guidelines or strategies. Northmill is both a bank and payment provider in multiple European regions, and also has a number of business requirements affecting information security.
Monitor compliance for our internal information security rules and our applicable business and regulatory requirements. DORA, GDPR, PSD2, FFFS, Visa, Swift, Swish, Bankgirot, Rixbanken, etc.
Structure information security requirements in the ISMS in alignment with the ISO 27001 standard.
Act as an advisor and lead for information, cyber security, or privacy incidents.
Serve as a subject matter expert within privacy and data protection
Act as subject matter expert in relation to our PCI-DSS certification and conduct readiness assessments towards the business. Keep track of that recurring tasks are performed as needed.
Contribute to reporting towards supervisory authorities (e.g. SFSA, IMY, FIN-FSA)
Ensure that the organization has relevant security awareness and training in place
Lead and participate in Business Impact Analysis, ICT vendor approval, the Register of Information, Critical and Important functions, ICT Risk assessments, Data Protection Impact Assessments, IA-act risk assessments, NPAP, and various GAP analyses.
What we are looking for
Experience working as an Information Security Officer or in a similar role
Hands-on experience in developing policies, procedures, and security frameworks
A pragmatic mindset and a strong understanding of how to balance regulatory requirements with business needs
Strong problem-solving skills and the ability to operate in a dynamic environment
A collaborative approach and willingness to work closely with different parts of the organization
Professional proficiency in both Swedish and English (Finnish or German is a plus)
Based in Stockholm, with EU/EEA residency or citizenship
Certifications such as CISM or ISO 27001 Lead Implementer are meritorious, but not required.
What we offer
A fantastic office in a prime Stockholm location with great spaces and views
An independent role with the opportunity to make a real impact
Great opportunities for professional development
Health - 5 000 kr health care allowance
Conference abroad every other year
Breakfast and fruits every day, as well as "holy fika” each Friday
Regular after work and celebrated successes at the office
Apply today and be a part of Northmill!
Om uppdraget 🚀 Organisationen skalar upp sitt arbete med AI och behöver förstärka inom informationssäkerhet och GRC. Fokus ligger på att hantera risker kopplade till AI, SaaS och integrationer – både operativt och strategiskt. Dina arbetsuppgifter 🛠️ Genomföra riskbedömningar kopplade till AI-initiativ Kommunicera risker och konsekvenser till ledning på ett affärsnära sätt Bidra till att bygga säkra AI-lösningar och relevanta guardrails Stötta utveckling av risk intake-processer Förbättra och strukturera organisationens övergripande riskhantering Förväntade leveranser 📦 Genomförda och dokumenterade riskanalyser inom AI/SaaS Tydliga beslutsunderlag till ledning Etablerade eller förbättrade processer för risk intake Konkreta rekommendationer för säker AI-användning Din profil / Obligatoriska kompetenser ✅ Erfarenhet av risk management och IT-säkerhet Teknisk bredd inom AI, SaaS och integrationer Minst 1–2 års aktuell erfarenhet av AI-/SaaS-relaterade risker Förmåga att översätta tekniska risker till affärspåverkan Flytande engelska i tal och skrift Meriterande färdigheter ⭐ Erfarenhet av att arbeta nära ledningsgrupp Tidigare arbete i organisationer med snabb AI-adoption Erfarenhet av att etablera GRC-processer Personliga egenskaper 🤝 Affärsdriven och kommunikativ Strukturerad och lösningsorienterad Självständig med hög leveransförmåga Övrig information 📍 Plats: Stockholm (onsite) Omfattning: Heltid Start: ASAP (flexibelt) Period: 3–6 månader Språk: Engelska Sway Sourcing är en innovativ rekryteringspartner som specialiserar sig på att matcha rätt talang med rätt företag – snabbt och effektivt. Vårt huvudfokus ligger inom Ekonomi, Administration, HR, Marknad och IT, men vi har även den breda expertis och flexibilitet som krävs för att leverera skräddarsydda rekryteringslösningar inom alla branscher. Trots att vi är en relativt ny aktör har vi redan byggt förtroende hos många av Sveriges största företag och arbetar både nationellt och internationellt. Med baser i Sverige och Spanien erbjuder vi en unik kombination av lokal expertis och global räckvidd. Vårt starka nätverk och djupa branschinsikter gör oss till en självklar partner för företag som vill ligga steget före i sin rekrytering.
At Securitas, Digital Security (Cyber Security) is focused on protecting our systems, applications, data, and services while enabling secure and reliable business operations. All countries within our scope are either certified against ISO/IEC 27001 or actively implementing it, ensuring a consistent and structured approach to information security management across the organisation. Your Role – Cluster Digital Security Officer (Cluster North) As a Cluster Digital Security Officer, you will support the technical execution, coordination, and oversight of Digital Security across Cluster North (Sweden, Norway, Finland, Denmark, the UK, and Ireland), while also contributing to Group/ Division-level security priorities. This is a hands-on, operational role, delivered as part of a wider Digital Security organization. You will work closely with different Division/Group IT teams, Digital Security Operations, Digital Security, and Country IT teams, operating in a collaborative, multi-country and multi-layer (Cluster–Division–Group) environment. Key Responsibilities Security Coordination & Team Collaboration (Cluster & Division) Coordinate Digital Security activities across the Cluster and support execution of the security roadmap aligned with Division priorities, including application security initiatives Ensure consistent implementation of security controls, baselines, and services across infrastructure and applications Work closely with GITS, Application teams, Domain and other IT teams to ensure alignment and effective execution Contribute actively to the Digital Security community, including sharing practices related to application and platform security Provide regular, transparent, and data-driven reporting on risk posture, control effectiveness, and remediation progress Technical Security Oversight (Infrastructure & Applications) Monitor and assess the security posture of platforms, infrastructure, and applications (on-prem and cloud) Oversee key control areas including vulnerability management, patching, identity and access management, endpoint security, and application security Support secure practices across the application lifecycle (SDLC), including awareness of secure design and common vulnerabilities (e.g. OWASP Top 10) Ensure effective logging, monitoring, and incident detection capabilities are in place across infrastructure and applications Track and assess third-party and supplier risks, including risks related to applications and integrations Risk, Compliance & Assurance Identify and track gaps against security policies, standards, and mandates, including application security requirements Support/execute risk assessments, internal and external audits, and customer assurance activities across Cluster environments Drive and follow up on risk remediation plans, ensuring clear ownership and execution across technical teams Securitas Alarm Monitoring Centers (SOC) Security In addition to Cluster responsibilities, you will contribute to Division-level security of Securitas Alarm Monitoring Centers (SOCs) supporting the Domain Digital Security Officer SOC and RVS, which are among the most critical environments within Securitas. This includes: Supporting and overseeing the security posture of SOC environments, including underlying infrastructure and supporting applications Ensuring implementation of enhanced technical controls (e.g. network segmentation, strong access control, privileged access management, monitoring, and secure application access) Monitoring the availability, integrity, and protection of SOC systems, applications, and data flows Supporting incident detection, response readiness, and recovery capabilities for SOC-related platforms and applications Working closely with Infrastructure, Application, SOC and other IT teams to reduce attack surface and strengthen resilience of SOC environments Ideal Candidate Profile We are looking for a candidate who combines technical understanding across infrastructure and applications, structured execution, and strong collaboration skills. Certifications (mandatory) CISSP or CISM or equivalent Experience & Knowledge 5–7 years of experience in Cyber Security, Information Security or Application Security Minimum of 2 years of experience in IT operations Good understanding of security domains (IAM, endpoint security, vulnerability management, logging/monitoring, network security, and application security) Solid understanding of application security principles, including secure development practices, common vulnerabilities (e.g. OWASP Top 10), and risks in application architecture and integrations Good understanding of ISO 27001 standard Experience with risk management, audits, or compliance activities Understanding of infrastructure environments (networks, servers, cloud platforms) and their interaction with applications Technical & Analytical Skills Ability to assess security posture across infrastructure and applications and identify control gaps Comfortable working with security metrics, reports, and risk data Understanding of incident detection and response processes, including those impacting applications Ability to translate security requirements into practical and implementable actions across infrastructure and application teams
Om oss Vi är en välfinansierad startup som bygger verktyg för att hjälpa samhället att stå emot och anpassa sig till säkerhetshot, naturkatastrofer, extremväder och andra risker. Vår plattform möjliggör simulering, scenarioplanering, incidenthantering och tidig varning och används i miljöer där tillgänglighet, robusthet och säkerhet är helt avgörande. Vi arbetar nära aktörer inom myndigheter och samhällskritisk infrastruktur, vilket innebär höga krav på både teknisk säkerhet och efterlevnad av regulatoriska krav. Om rollen Vi söker en Senior IT & Information Security Officer som vill vara med och bygga upp och utveckla säkerhetsarbetet i en verksamhet där säkerhet är en central del av affären. Det här är en senior och verksamhetsnära roll för dig som trivs i gränslandet mellan säkerhet, teknik och verksamhet. Som en av de första säkerhetsfunktionerna i bolaget får du stort mandat att påverka hur vi arbetar med informations- och IT-säkerhet. Rollen är hands-on och innebär att du själv driver och genomför stora delar av säkerhetsarbetet i nära samarbete med verksamheten. Du kommer att arbeta nära ledning, produkt och teknik i en miljö där regulatoriska krav, samhällsnytta och säkerhet går hand i hand. Exempel på arbetsuppgifter: Säkerställa efterlevnad av Säkerhetsskyddslagen, NIS2/Cybersäkerhetslagen och ISO 27001 Driva organisationens arbete inom informationssäkerhet, IT-säkerhet, riskhantering och incidenthantering Ansvara för informationsklassificering, informationsmärkning, säkerhetspolicyer och andra styrande dokument Etablera och leda incident- och krishanteringsprocesser samt fungera som primär kontaktpunkt mot relevanta myndigheter vid incidentrapportering Genomföra leverantörsbedömningar och due diligence-arbete med fokus på supply chain security Utveckla och genomföra utbildningsinsatser inom informations- och cybersäkerhet Rapportera säkerhetsläge, risker och efterlevnad till ledning och andra beslutsfattare Omsätta regulatoriska, operativa och säkerhetsrelaterade krav till produktstrategi, prioriteringar och verksamhetsförbättringar Om dig Du är en pragmatisk och handlingskraftig person som trivs i en roll där du kombinerar strategiskt tänkande med operativt genomförande. Du tar naturligt ägarskap, bygger förtroende hos olika intressenter och har förmågan att få med dig organisationen i säkerhetsfrågor. Du uppskattar miljöer där mycket fortfarande är under uppbyggnad och där du får möjlighet att påverka både arbetssätt och riktning. För att lyckas i rollen har du: Gedigen erfarenhet av arbete inom informationssäkerhet, IT-säkerhet eller säkerhetsstyrning Dokumenterad erfarenhet av att tillämpa Säkerhetsskyddslagen och NIS2/Cybersäkerhetslagen i praktiken Erfarenhet av att utveckla och implementera säkerhetsprocesser, styrmodeller och riskhanteringsarbete Erfarenhet av att arbeta i komplexa miljöer med många intressenter och höga krav på säkerhet och efterlevnad Förmåga att omsätta regulatoriska och verksamhetsmässiga krav till konkreta åtgärder och prioriteringar Flytande svenska och engelska i tal och skrift Erfarenhet av arbete enligt ISO 27001 samt certifieringar såsom CISSP, CISM eller motsvarande är meriterande. Vad vi erbjuder Konkurrenskraftig ersättning och långsiktig uppsida i ett bolag med stark tillväxt och ett tydligt samhällsnyttigt syfte. En flexibel arbetsmiljö med stort mandat att påverka, där du får möjlighet att bygga upp och utveckla säkerhetsarbetet i nära samarbete med ledning, produkt och teknik. Viktig information För slutkandidater genomför vi en fördjupad bakgrundskontroll via en extern leverantör. Rollen omfattas av säkerhetsprövning.