
Consilium Safety Group AB · Hisings Backa
About Consilium Safety Group At Consilium Safety Group, we don’t just build technology, we create solutions that protect people, assets, and the planet. As a g...
About Consilium Safety Group
At Consilium Safety Group, we don’t just build technology, we create solutions that protect people, assets, and the planet. As a
global leader in fire and gas safety, we serve critical industries such as marine, energy, rolling stock, and infrastructure.
With more than 100 years of expertise, we combine deep industry knowledge with cutting-edge innovation to shape the future of
Safety Tech. Headquartered in Gothenburg, Sweden, and operating in over 55 locations worldwide, we are a fast-growing global
organization backed by Antin Infrastructure Partners.
With strong financial support and a clear strategic vision, we are on an ambitious journey of growth and transformation, investing
in innovation, operational excellence, and talent.
This is an exciting time to join us.
We are now looking for an Information Security Engineer to join the information security team at Consilium!
About the Role
As an Information Security Engineer at Consilium, you will combine hands-on security operations with strategic governance and
compliance work.
Operational Excellence: Working hands-on to implement security controls, managing daily security activities, and acting as an
internal subject matter expert.
Strategic and Compliance-Oriented Leadership: Developing and driving our security strategy, ensuring we meet regulatory
requirements, and continuously strengthening our security posture.
You will help protect Consilium’s information assets, lead compliance efforts related to NIS2, and support alignment with
frameworks such as NIST CSF, ISO 27001, the EU CRA, and the AI Act. The role works closely with teams across IT, HR, R&D, Sales,
and Marketing.
Your Main Responsibilities
In this role, you will manage day-to-day security operations activities as well as strengthening the ISMS, implement controls
aligned with ISO 27001, NIS2, and NIST CSF, coordinate audits, develop policies, and provide risk reporting and advisory support
across the business.
Qualifications and Experience
To succeed in this role, you bring strong technical security knowledge, incident-handling capability, and an interest in
governance and compliance.
Requirements
Technical Environment: Solid understanding of Microsoft Defender suite, Azure/O365, Windows, and Linux.
Networking & Security Tools: Strong knowledge of TCP/IP, segmentation, firewalls, SIEM, EDR/EPP, and patch management.
Automation: Basic to intermediate scripting skills (PowerShell, Python, Bash, KQL, or Graph API).
Incident & Frameworks: Experience with log analysis, incident lifecycles, and frameworks like ISO 27001 or NIST CSF.
Communication: Ability to explain technical security concepts clearly to non-technical stakeholders.
Meriting
Hands-on experience with Microsoft's advanced security stack (Sentinel, XDR, Entra, Intune, Purview/Priva).
Cloud security controls (Azure), DevSecOps (GitHub Advanced Security), or direct audit-evidence collection experience.
Previous experience working with audits and evidence collection linked to ISO 27001/NIS2/NIST CSF.
Who Are We Looking For?
We are looking for someone with hands-on experience in IT security and information security compliance, along with a solid
understanding of relevant regulations and security frameworks. You are structured, analytical, and able to communicate clearly
with a wide range of stakeholders.
Personal Attributes
You are analytical, proactive, and solution-oriented, with high integrity and a structured way of working. You communicate
clearly, work well independently, and build strong relationships across technical and non-technical teams.
What We Offer
At Consilium Safety Group, you will join an innovative international environment where quality and safety come first. This is a
high-impact role with opportunities to shape global security initiatives, along with a competitive salary, benefits, and career
development.
Apply Now
Does this sound like your next challenge? Submit your application as soon as possible, as we review applications on a rolling
basis.
Consilium Safety Group is an equal opportunity employer committed to diversity and inclusion.
Ready to learn more about our journey? Hear from our CEO: Philip Isell Lind af Hageby, Consilium, en mästare på turnarounds -
Värdeskaparna | En podd om riskkapital av OPX Partners | Podcast on Spotify
Vill du ta nästa steg i karriären inom cybersäkerhet? Vill du jobba med komplexa problem i teknisk framkant och bidra till samhällsnyttiga projekt? Ta nu chansen i rollen som Information Secuity Engineer hos vår kund inom försvarsindustrin. Om tjänsten Du kommer att spela en central roll inom utveckling och säkerställande av interna IT-system. Ditt arbete kommer att kretsa kring att implementera och förbättra IT-säkerhetsåtgärder, vilket innebär ett nära samarbete med flera tvärfunktionella team. Ett av huvudansvaren är att säkerställa att organisationen ligger i framkant avseende tekniska innovationer och säkerhetsstandarder. Du kommer även att hantera tekniska gränssnitt för att säkerställa att systemen uppfyller både behov och kravställningar inom olika verksamhetsområden. Dina dagliga uppgifter kommer bland annat att inkludera säkerhetstestning, kravanalys och regeltolkning. Arbetet omfattar flera globala regelverk såsom NIST 800-171 Rev.2, NIS2, ISO-standarder samt andra internationella säkerhetsramverk. Du kommer också att vara ansvarig för att följa och implementera regelverk som ISO-standarder och GDPR, vilket är avgörande för att säkerställa organisationens compliance. För att lyckas i rollen krävs det att du har intresse för ny teknologi och en vilja att ständigt utöka din kunskap. Teamet arbetar ibland remote där virtuella verktyg används för samarbete. Det förekommer gemensamma teamdagar där det krävs fysisk närvaro on-site. Det finns möjlighet att arbeta från olika kontor/hubbar beroende på geografisk placering. Sammanfattningsvis erbjuder denna roll en rik möjlighet att bidra till och växa i en dynamisk och framåttänkande IT-miljö, där din insats kommer att vara avgörande för att framtidssäkra verksamheten och dess tekniska lösningar. Vi söker dig som har erfarenhet av en eller flera av följande områden:Säkerhetspraxis (te.x OWASP) Regelverk såsom ISO27xxx, GDPR, SOC2, DORA Kravställning och kravanalys IAM-roll-och-policybaserade behörighetssystem Praktisk erfarenhet av säkerhetstestning (t.ex. MITM) God kommunikation förmåga på svenska och engelska i tal och skrift Det kommer även läggas stor vikt vid personlig lämplighet i rekryteringen. För att trivas i rollen tror vi att du är en engagerad lagspelare med ett driv och vilja att utvecklas. Du kommer ingå i ett team där nyfikenhet och kreativitet uppmuntras, därför tror vi att du gillar innovation och gillar att komma med nya idéer och lösningar. Befattningen kräver att du genomgår och godkänns enligt gällande säkerhetsskyddsbestämmelser. För vissa roller kan detta innebära krav på säkerhetsklassning och i förekommande fall specifika medborgarskapskrav. Urval sker löpande och uppdraget kan komma att tillsättas innan sista ansökningsdatum Om anställningen: Detta är ett konsultuppdrag vilket innebär att du kommer vara anställd av Friday och arbeta som konsult ute hos vår kund. På Friday tror vi att människor som är på rätt plats har störst möjlighet att nå sin fulla potential. Vi är övertygade om att rätt människor, i rätt roller, skapar morgondagar värda att längta till. Övrig info: Omfattning: Heltid Start: Enligt överenskommelse Placering: Utångspunkt i Linköping men går att utgå från andra platser i landet Lön: Marknadsmässig månadslön Kontaktperson: Hampus Kindgren, hampus.kindgren@Friday.se Om Friday På Friday brinner vi för att ge dig som Tech-talang en riktigt bra start på karriären. Genom att lyssna på vad just du vill och drivs av, matchar vi dig med företag och möjligheter som får dig att se fram emot att gå till jobbet. Vi värderar ambition och potential högt och arbetar aktivt för en fördomsfri rekrytering, där alla ges samma chans att lyckas. Vi finns i Stockholm, Göteborg, Malmö, Linköping och Örebro. Varje år genomför vi över 5 000 karriärmöten och matchar kandidater med allt från globala företag till innovativa startups. Öppen för alla Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.
ABOUT BUREAU Bureau is a unified risk decisioning platform for Compliance, Fraud, and Transaction risks. Our platform is a single decision-making engine, powered by a 1 billion+ identity knowledge graph. Over 150 Banks, fintechs, retailers, and digital platforms use Bureau to verify identities faster and stop fraud earlier globally. Bureau has raised $50M+ from renowned Silicon Valley and global investors including Sorenson Capital and PayPal Ventures and is expanding rapidly from APAC to Americas, Europe, and beyond. WHY BUREAU? Bureau is building the infrastructure that makes digital identities and transactions safe and trustworthy for billions of people. The mission is big, the problems are complex, and the impact is real. We hire people who want that level of responsibility. People who move fast, build systems from scratch, and care deeply about turning strategy into execution. If you want predictability or narrow scope, this won't be your place. If you want to shape how a scaling global company operates—keep reading. ABOUT THE ROLE - INFORMATION SECURITY ENGINEER We are looking for a Security Engineer who can own both the hands-on technical security stack and our governance/compliance programs. What you’ll be doing In this role, you will: * Harden and monitor our cloud & container infrastructure (AWS/EKS, endpoints, network). * Run vulnerability management, security tooling and incident response. * Help maintain our ISMS and support audits (ISO 27001, SOC 2, RBI, DPDP, etc.). This is ideal for someone who doesn’t want to be only “checklist GRC” or only “pure blue-team”, but wants a blended role across security engineering + GRC.Key Responsibilities 1. Cloud & Infrastructure Security (Hands-on) * Work with DevOps to secure our AWS/EKS environment: * IAM hardening, security groups, VPC, KMS, S3, RDS, etc. * Review infra-as-code (Terraform/Helm) for security issues and misconfigurations. * Own or co-own key security tools: * Endpoint / EDR (e.g., CrowdStrike / SentinelOne), * Cloud security (CSPM / CNAPP, GuardDuty, Security Hub, WAF, etc.), * Container / runtime security where applicable. * Implement and maintain logging & monitoring for security events (CloudTrail, ALB/NLB logs, K8s logs, etc.), and integrate them with SIEM / alerting. 2. Vulnerability Management & Security Operations * Own the vulnerability management lifecycle: * Run periodic scans for cloud, endpoints, containers and apps. * Triage findings, prioritise based on risk, and drive closure with engineering. * Coordinate external pentests / bug bounties and track remediation. * Support incident response: * Help investigate alerts, gather evidence, and contribute to RCA and CAPA. * Maintain and update incident runbooks. 3. Governance, Risk & Compliance (ISMS, Audits, DPDP) * Maintain and enhance the Information Security Management System (ISMS): * Policies, procedures, SoA, risk register, control evidence and audit trails. * Support internal and external audits: ISO 27001, SOC 2, RBI/CERT-In, Data Protection. * Prepare and manage audit evidence, observations, closure reports and certification documentation. * Assist with risk assessments: * Maintain the risk register, risk treatment plans and residual risk reviews. * Conduct vendor security due diligence and maintain vendor security records (MSA, NDA, DPA, DPIA, etc.). * Support privacy & regulatory compliance operations (GDPR/DPDP basics: retention, consent, grievance logging). 4. Access, Asset & Control Assurance * Participate in and help automate access reviews, asset inventory checks, and configuration compliance checks. * Track control performance (vuln SLAs, access reviews, backup tests, etc.) and ensure gaps are documented and closed. * Maintain security awareness and training trackers (onboarding, annual refreshers, phishing simulations). What You’ll Bring * Bachelor’s degree in Computer Science, IT, Cybersecurity or related discipline. * ~4 years of experience in security engineering, cloud security, or GRC/compliance (any mix, but must be comfortable hands-on). * Good understanding of: * Security engineering fundamentals: Linux, networking, IAM, encryption, least privilege. * Cloud platforms (AWS preferred; GCP/Azure a plus) and their security services. * Core frameworks: ISO 27001, SOC 2, basic risk management and audit lifecycle. * Comfortable with: * Writing/debugging basic scripts (Bash/Python) for automation and data extraction. * Tools like Jira, Confluence, Excel/Sheets and at least one GRC / security platform (e.g., Scrut/Drata/Secureframe, etc.). * Strong documentation skills and ability to talk to both engineers and non-technical stakeholders. Preferred (Good to Have) / Willing to Learn * Cloud security certifications (e.g., AWS Security / AWS Cloud Practitioner). * ISO 27001:2022 Lead Auditor/Implementer, CompTIA Security+, ISC2 CC. * Experience with: * EDR/XDR tools, * CSPM/CNAPP (e.g., Wiz, Prisma, Defender for Cloud), * SIEM, WAF, runtime/container security (Falco, etc.). * Exposure to GDPR/DPDP or other data protection regimes. Who You Are * You enjoy both: * Getting your hands dirty in logs, configs and cloud consoles, and * Keeping things clean in policies, risk registers and audit trackers. * You’re structured and process-oriented, but still pragmatic and capable of shipping improvements. * You’re comfortable collaborating with DevOps, backend, data, HR and legal to get security actually implemented, not just written down. * You want to grow into either Security Engineering leadership (owning tools/architecture) or GRC leadership (owning audits and certifications) over the next few years. OUR CULTURE * We hire self-motivated people and get out of their way * We value performance, not hours worked * Speed, ownership, and impact matter most COMPENSATION * Competitive salary + potential equity * Health benefits, flexible PTO, learning budget
The information security team is responsible for protecting IMC’s intellectual property, IT infrastructure and business operations against external and internal threats. We work closely with technology, risk, compliance, internal audit and business leaders to reduce cyber risk to acceptable levels. We are looking for an Information Security Engineer to grow and mature our Security Operations Center function that uses EDR, SIEM, SOAR, CSPM, IAM, firewalls, NIDS/NIPS and various other security controls. We offer an environment that allows you to broaden and deepen your information security knowledge and skills, with access to advanced security technology, frequent training and a culture of knowledge sharing. As you gain experience with our existing SOC technology and processes, you will be given a lot of freedom to further mature the SOC with your own initiatives. Your Core Responsibilities: * Analyse security logs, alerts and reported events. Respond to or assist with the remediation of incidents * Using various threat intelligence sources, hunt for potential compromise across the infrastructure * Report discovered vulnerabilities to technology owners and suggest remediation steps * Support and improve technical security controls * Leverage automation and orchestration solutions to automate repetitive tasks * Leverage AI-assisted tooling to enhance alert triage, event summarisation, and investigation workflows, with a pragmatic view of its limitations * Develop reporting for assessing the effectiveness of security controls * Develop and improve incident response playbooks Your Skills and Experience: * Relevant tertiary and/or security qualifications with previous SOC experience and/or 3+ years of hands-on experience in an enterprise IT environment, managing endpoints and applications on-prem or in the cloud * Strong analytical and problem-solving skills * Self-starter and a passion for cybersecurity * Exposure to security controls like identity and access management, vulnerability management, endpoint detection and response * Automation using basic coding skills or low code / no code automation tools * Awareness of AI and machine learning applications in security operations is a plus; any hands-on experience with AI-assisted security tooling or LLM-based workflows is highly regarded. * Understanding of common attack techniques and frameworks such as MITRE ATT&CK About Us IMC is a global trading firm powered by a cutting-edge research environment and a world-class technology backbone. Since 1989, we’ve been a stabilizing force in financial markets, providing essential liquidity upon which market participants depend. Across our offices in the US, Europe, Asia Pacific, and India, our talented quant researchers, engineers, traders, and business operations professionals are united by our uniquely collaborative, high-performance culture, and our commitment to giving back. From entering dynamic new markets to embracing disruptive technologies, and from developing an innovative research environment to diversifying our trading strategies, we dare to continuously innovate and collaborate to succeed.