
Wrknest AB · Stockholm
Om tjänsten Vi rekryterar nu en ISO compliance & Cyber Security Lead till ett växande bolag inom fintech. Rollen är central i organisationen och innebär att ta ...
Vi rekryterar nu en ISO compliance & Cyber Security Lead till ett växande bolag inom fintech. Rollen är central i organisationen och innebär att ta ett helhetsansvar för ISO arbete och cybersäkerhet, samt efterlevnad och styrning kopplat till kvalitet, informationssäkerhet och cybersäkerhet.
I rollen ansvarar du för att bolagets ISO arbete är levande, verksamhetsnära och revisionsredo. Arbetet omfattar standarder som ISO 27001, ISO 9001 och ISO 14001, samt regulatoriska krav och lagar kopplade till cybersäkerhet såsom Cybersäkerhetslagen. Utöver arbetet med ISO arbete kommer du även att ha en viktig roll i att driva och utveckla bolagets informationssäkerhet och cybersäkerhetsarbete, där du identifierar risker, definierar säkerhetskrav och säkerställer att organisationen arbetar strukturerat för att skydda verksamheten mot externa hot.
Du kommer att leda och driva arbetet genom att definiera krav, kontroller, åtgärder och arbetssätt, införande av tekniska säkerhetsåtgärder görs av andra interna eller externa parter. Samtidigt arbetar du nära verksamheten och säkerställer att organisationen följer de strukturer och processer som sätts upp. Du kommer att arbeta nära bolagets ledning och bli en nyckelperson i att utveckla strukturer, driva förbättringsarbete och stärka organisationens arbete med kvalitet, risk, informationssäkerhet och cybersäkerhet.
Dina framtida arbetsuppgifter
I rollen ansvarar du för att utveckla och driva organisationens arbete med ISO och cybersäkerhet, och säkerställer att bolagets arbete är strukturerat, integrerat i verksamheten och följs upp löpande.
Äga och utveckla bolagets ISO arbete, inklusive policyer, processer och kontrollstrukturer
Säkerställa efterlevnad kopplat till standarder som ISO 27001, ISO 9001 och ISO 14001
Driva och utveckla organisationens arbete med informationssäkerhet och cybersäkerhet på governance-nivå
Identifiera cybersäkerhetsrisker och föreslå åtgärder för att stärka organisationens skydd mot externa hot
Etablera och följa upp kontroller kopplade till informationssäkerhet och cybersäkerhet, exempelvis kring accesshantering, loggning, övervakning och sårbarhetshantering
Driva organisationens arbete med riskanalyser, incidenthantering och avvikelsehantering
Samordna och följa upp internrevisioner, externa revisioner och certifieringar
Tolka och omsätta regulatoriska krav, exempelvis Cybersäkerhetslagen, till praktiska arbetssätt och kontroller i organisationen
Stötta ledningen genom att tydligt rapportera risker, status och förbättringsområden
Vi söker dig som har
Har erfarenhet av att arbeta med ISO, informationssäkerhet och cybersäkerhet, och som trivs i en roll där du driver struktur, styrning och förbättringsarbete i organisationer.
Erfarenhet av att driva eller förvalta ISO arbete och/eller ISO-ledningssystem
Erfarenhet av informationssäkerhet och/eller cybersäkerhetsstyrning på governance-nivå
Erfarenhet av riskhantering, revisioner eller efterlevnadsarbete
Förmåga att omsätta regelverk och säkerhetskrav till konkreta processer, kontroller, åtgärder och uppföljning
Erfarenhet av att arbeta nära verksamhet och ledning i frågor kopplade till compliance och risk
Vi ser det som meriterande
Erfarenhet av arbete kopplat till Cybersäkerhetslagen eller liknande regulatoriska krav inom cybersäkerhet
Erfarenhet av internrevision eller samordning av externa revisioner eller certifieringar
Erfarenhet från SaaS-, fintech- eller andra driftkritiska miljöer
Erfarenhet av leverantörsgranskningar eller tredjepartsrisk
Som person är du självständig, strukturerad och analytisk, med en god förmåga att kommunicera komplexa frågor på ett tydligt, pedagogiskt och verksamhetsnära sätt. Du är trygg i att ställa krav, driva förändring och följa upp att beslut faktiskt genomförs i organisationen.
Övrig information
Start: så snart som möjligt
Plats: Stockholm norrort
Omfattning: Heltid
Anställningsform: Tillsvidare med inledande provanställning
Sök gärna så snart som möjligt då vi jobbar med löpande urval.
Om Wrknest
På Wrknest gör vi inte som alla andra. Vi tror på att hela tiden våga se nya möjligheter och tänka nytt. När vi startade var det för att utmana gamla sätt att rekrytera på.
Vi lever i en tid av snabb digital utveckling. Kunskap behöver förnyas kontinuerligt för att vara aktuell. Därför gäller det att kunna ställa om snabbt. Det här gör att vi inte enbart tittar på kandidatens CV vid en rekrytering. Istället ser vi till den samlade potentialen och erbjuder individanpassad upskilling. På så vis kan vi snabbt matcha de kunskapsbehov som finns just nu. Läs mer på www.wrknest.se .
Job Description Join our Cyber Security Engineering unit, where innovation and security drive us. We are transforming technology with modern Network Security, integrations and cloud services. We are looking for a highly skilled and experienced Senior Cyber Security Engineer to join our Network Security Engineering team. This role involves architecting, designing, implementing, and maintaining robust security measures to protect our global network infrastructure. The ideal candidate will blend theoretical knowledge with hands-on expertise. This role requires a deep understanding of cybersecurity principles, Network Security technologies, and the ability to collaborate across multiple globally dispersed stakeholders and teams. WHAT YOU’LL DO Lead the development, optimization and integration of network security policies, rules and monitoring across platforms such as NDR, SSE, SD‑WAN and proxy solutions Design and improve network security solutions across branches, stores and data centers, ensuring strong alignment with business and security needs Conduct security architecture reviews, risk assessments and threat modelling, and drive hardening initiatives across our network landscape Modernize network security by transitioning from legacy systems to modern SSE and ZTNA solutions, supported by clear roadmaps, policies and plans Monitor and enhance the performance, availability and reliability of network security solutions, ensuring compliance with ISO, NIST, GDPR and internal standards Design, configure and troubleshoot network security devices and services across on‑prem and cloud environments, providing advanced Level‑3 support when needed WHO YOU'LL WORK WITH You’ll join a friendly and collaborative Network Security Engineering team of seven, soon to be eight, working closely with colleagues across Business Tech. Your daily partners will include network SMEs, Cyber Security Advisors, Core Platforms and Global Infrastructure Services, as well as teams supporting stores, warehouses and new market entries. You’ll also connect with external partners and contribute to cross‑functional projects where network and cyber security come together. This is a highly collaborative environment where your expertise will help shape our security posture and uplift the team’s cyber maturity. WHO YOU ARE 6+ years of experience in cybersecurity engineering, with a focus on network environments Strong, practical knowledge of: Network security technologies (firewalls, IDS/IPS, SWG, SASE, VPN, CASB, ZTNA), Cloud platforms: Azure, GCP, Security architecture methodologies and governance frameworks Expertise in network security solutions and products provided by Cisco, HP Aruba, Zscaler and Citrix NetScaler (proven by certificates) Strong knowledge of risk assessment and security control frameworks (ISO 27001, NIST). Familiarity with security maturity models including C2M2 Excellent ability to translate security requirements into implementable engineering solutions. Strong understanding of IP networking and protocols, including IPsec, HSRP, BGP, OSPF, 802.11, and QoS. Understand regulatory and compliance requirements (GDPR, PCI-DSS, Schrems, etc.). Independent problem-solving, addressing complex security challenges with minimal supervision. Preferred qualifications: CCNP (Security) or higher-level certifications such as the CCIE. CISSP or OSCP security certifications. Azure Security Engineer, or GCP Security Engineer certification. Experience with Agile methodologies and tools (e.g., Jira/Confluence) WHO WE ARE H&M is a fashion brand that offers the latest styles and inspiration, from fashion pieces and unique designer collaborations to affordable wardrobe essentials. Our business idea is fashion & quality at the best price in a sustainable way. Learn more about H&M here. WHY YOU’LL LOVE WORKING HERE Benefits All our employees are included in our H&M Incentive Program (HIP) All our employees receive a staff discount card, which is usable on all our H&M Group brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET. Work-life balance, 30 days’ vacation and wellness allowance 4000 SEK/yearly Access to Benify, for discounts on e.g. Gym memberships, travel, hotels and many other great deals. Compensation boost during parental leave In addition to our global benefits, all our local markets offer different competitive perks and benefits. Please note that they may differ between employment type and countries. Inclusion & Diversity H&M is a part of H&M Group. At H&M Group, we’re determined to create and maintain inclusive, diverse and equitable workplaces throughout our organization. Our teams should consist of a variety of people that share and combine their knowledge, experience and ideas. Having a diverse workforce leads to a positive impact on how we address challenges, on what we perceive possible and on how we choose to relate to our colleagues and customers all over the world. Hence all diversity dimensions are taken into consideration in our recruitment process. We are committed to a recruitment process that is fair, equitable, and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
Job Description Join our Cyber Security Engineering unit, where innovation and security drive us. We are transforming technology with modern Network Security, integrations and cloud services. We are looking for a highly skilled and experienced Senior Cyber Security Engineer to join our Network Security Engineering team. This role involves architecting, designing, implementing, and maintaining robust security measures to protect our global network infrastructure. The ideal candidate will blend theoretical knowledge with hands-on expertise. This role requires a deep understanding of cybersecurity principles, Network Security technologies, and the ability to collaborate across multiple globally dispersed stakeholders and teams. WHAT YOU’LL DO Lead the development, optimization and integration of network security policies, rules and monitoring across platforms such as NDR, SSE, SD‑WAN and proxy solutions Design and improve network security solutions across branches, stores and data centers, ensuring strong alignment with business and security needs Conduct security architecture reviews, risk assessments and threat modelling, and drive hardening initiatives across our network landscape Modernize network security by transitioning from legacy systems to modern SSE and ZTNA solutions, supported by clear roadmaps, policies and plans Monitor and enhance the performance, availability and reliability of network security solutions, ensuring compliance with ISO, NIST, GDPR and internal standards Design, configure and troubleshoot network security devices and services across on‑prem and cloud environments, providing advanced Level‑3 support when needed WHO YOU'LL WORK WITH You’ll join a friendly and collaborative Network Security Engineering team of seven, soon to be eight, working closely with colleagues across Business Tech. Your daily partners will include network SMEs, Cyber Security Advisors, Core Platforms and Global Infrastructure Services, as well as teams supporting stores, warehouses and new market entries. You’ll also connect with external partners and contribute to cross‑functional projects where network and cyber security come together. This is a highly collaborative environment where your expertise will help shape our security posture and uplift the team’s cyber maturity. WHO YOU ARE 6+ years of experience in cybersecurity engineering, with a focus on network environments Strong, practical knowledge of: Network security technologies (firewalls, IDS/IPS, SWG, SASE, VPN, CASB, ZTNA), Cloud platforms: Azure, GCP, Security architecture methodologies and governance frameworks Expertise in network security solutions and products provided by Cisco, HP Aruba, Zscaler and Citrix NetScaler (proven by certificates) Strong knowledge of risk assessment and security control frameworks (ISO 27001, NIST). Familiarity with security maturity models including C2M2 Excellent ability to translate security requirements into implementable engineering solutions. Strong understanding of IP networking and protocols, including IPsec, HSRP, BGP, OSPF, 802.11, and QoS. Understand regulatory and compliance requirements (GDPR, PCI-DSS, Schrems, etc.). Independent problem-solving, addressing complex security challenges with minimal supervision. Preferred qualifications: CCNP (Security) or higher-level certifications such as the CCIE. CISSP or OSCP security certifications. Azure Security Engineer, or GCP Security Engineer certification. Experience with Agile methodologies and tools (e.g., Jira/Confluence) WHO WE ARE H&M is a fashion brand that offers the latest styles and inspiration, from fashion pieces and unique designer collaborations to affordable wardrobe essentials. Our business idea is fashion & quality at the best price in a sustainable way. Learn more about H&M here. WHY YOU’LL LOVE WORKING HERE Benefits All our employees are included in our H&M Incentive Program (HIP) All our employees receive a staff discount card, which is usable on all our H&M Group brands in stores and online. Brands covered by the discount are H&M (Beauty and Move included), COS, Weekday, Monki, H&M HOME, & Other Stories, ARKET. Work-life balance, 30 days’ vacation and wellness allowance 4000 SEK/yearly Access to Benify, for discounts on e.g. Gym memberships, travel, hotels and many other great deals. Compensation boost during parental leave In addition to our global benefits, all our local markets offer different competitive perks and benefits. Please note that they may differ between employment type and countries. Inclusion & Diversity H&M is a part of H&M Group. At H&M Group, we’re determined to create and maintain inclusive, diverse and equitable workplaces throughout our organization. Our teams should consist of a variety of people that share and combine their knowledge, experience and ideas. Having a diverse workforce leads to a positive impact on how we address challenges, on what we perceive possible and on how we choose to relate to our colleagues and customers all over the world. Hence all diversity dimensions are taken into consideration in our recruitment process. We are committed to a recruitment process that is fair, equitable, and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
Build the Future of Technology with Professional Galaxy AB Join a network of talented engineers, developers, cloud specialists, and AI innovators working on impactful projects across Sweden and Europe. At Professional Galaxy AB, we connect top tech talent with organizations driving digital transformation in areas like cloud computing, software engineering, data, cybersecurity, and artificial intelligence. Explore exciting opportunities and grow your career while working with cutting-edge technologies and forward-thinking teams. We are looking for a Cyber Security Advisor Responsibilities: Act as a trusted advisor to management and key stakeholders, ensuring cybersecurity considerations are integrated into decision-making Ensure cybersecurity best practices align with business objectives and delivery goals without hindering operational efficiency Provide cybersecurity expertise during projects and engagements to mitigate risks and enhance security controls Work with cross-functional teams to enhance the organization’s overall cybersecurity resilience Identify, assess, and provide guidance on mitigating cybersecurity risks across business functions Support compliance with relevant cybersecurity laws, regulations, and industry standards Contribute to the development and implementation of security strategies, policies, and frameworks Promote cybersecurity awareness and best practices among employees and stakeholders Qualifications: Typically 10+ years of experience in cybersecurity, information security, IT governance, risk management, or compliance Bachelor’s degree in Computer Science or related field (or equivalent experience) Proven leadership in security governance frameworks, policies, and strategies Experience aligning security and data privacy with business objectives at a strategic level Hands-on experience with enterprise risk management and compliance frameworks (e.g., GDPR, ISO 27001, NIST, PCI DSS) Strong expertise in third-party/vendor risk management Experience in security incident response and crisis management Ability to influence senior leadership and board-level stakeholders Additional qualifications (optional): Strong communication skills and stakeholder management Business understanding with security impact awareness Ability to analyze and mitigate security risks Certifications such as CISSP, CIPM, CISA, ISO/IEC 27001 Lead Auditor Specializations such as AI Governance, Cloud Security, or CIPP/E Uppdragsinformation: Uppdragslängd: 2026-05-04 – 2026-09-30 Placeringsort: Stockholm Svar önskas snarast, dock senast 2026-05-03. How to Apply: Please apply via the Professional Galaxy AB portal with: Your updated CV Your availability to start A motivation statement describing your suitability Please note: Applications via email will not be accepted. All applications must be submitted through the portal. Öppen för alla Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.