You focus on assessing and managing IT security risks while developing standards and architecture, ensuring compliance, and guiding operations according to established security frameworks.
Anforderungen
- •Experienced and ambitious person
- •Bachelor or Academic degree
- •At least five years in security expert role
- •Working knowledge of cybersecurity principles
- •Experience in application and network security
- •Deep understanding of threat actors
- •Experience in secure software development lifecycle
- •Experience in Cloud Security on Microsoft Azure
- •Good understanding of Windows and Linux security
- •Experience in IT Security legislations in Europe
- •Good knowledge of standards like ISO27001/2, NIST
- •Relevant IT Security certifications are a plus
- •Other relevant cybersecurity certifications are a bonus
- •Structured and a good planner
- •Great collaboration skills
- •Trustworthy person with integrity
Deine Aufgaben
- •Identify and assess IT Security risks.
- •Conduct security reviews and threat modeling sessions.
- •Report findings based on risk assessment.
- •Develop IT security standards and guidelines.
- •Validate and assess risks for IT security changes.
- •Ensure compliance with IT security standards.
- •Embed security in architectural designs and solutions.
- •Develop IT security architecture and improvement initiatives.
- •Consult and guide Security Operations teams.
Original Beschreibung
## Job Description
**Do you want to work internationally on securing our IT landscape? Both act in projects as our IT Security Officer and in others provide internal Consultancy?**
IT Security is continuously increasing its importance at Vattenfall. Our highly secured assets spread over different European countries; the fast evolving digitalization; cyber threats and local security regulations makes our work both challenging and interesting.
**Your responsibilities**
You will work in an international team of experts in IT Security. We advise and steer on group policy towards all levels of the organization and external partners. You do this by:
* identifying, assessing and reporting IT Security risks
* performing security reviews and threat modelling sessions, as well as reporting the findings on a risk-based approach
* developing IT security standards and guidelines
* validating and assessing the risk for certain IT security changes
* ensuring compliance with IT Security standards
* embedding security in IT architectural building blocks and solution designs
* development of IT security architecture and initiating security improvement initiatives
* consulting and guiding the Security Operations teams based on the Cyber Kill Chain Models and Cyber Threat Intelligence.
## Qualifications
**We are looking for** an experienced and ambitious person who is not afraid of asking critical questions and that constantly strives for improvement. On top of that you will bring:
* a Bachelor or Academic degree
* at least five years of experience in a security expert role in an international or corporate environment
Furthermore ideally you bring:
* working knowledge of cybersecurity principles, techniques and technologies
* experience in application security and network security related concepts
* deep understanding on how threat actors operate, execute their kill chain and laterally move within the network.
* experience in the creation of a secure software development lifecycle
* experience in Cloud Security on Microsoft Azure
* good level understanding on how operating systems such as Windows and Linux work and how to implement security hardening
* experience in relevant IT/Information Security legislations in the European countries where Vattenfall operates
* good knowledge of relevant standards, such as ISO27001/2, NIST, CIS
* relevant IT Security certifications are plus. (e.g. CISSP, CSSLP, GWEB, GWAPT)
* other relevant cyber security relevant security certifications are bonus (e.g. CISM, CISA, CRISC, OSCP)
**As a person we are looking for you** who is structured and a good planner. In this position you will work together with a lot of different people and stakeholders, that's why we do value great collaboration skills. We believe you are a trustworthy person who is honest and have integrity.
## Additional Information
**Location:**
You can choose to be based in Stockholm, Amsterdam, Berlin, Hamburg, Katowice or Gliwice. Hybrid working is the norm, so you can combine home office, with visiting your main location and sometimes international travelling to one of the other locations above.
We are only considering candidates already working and living close to one of our above-mentioned locations.
Hybrid working is the norm, so you can combine home office, with visiting your main location and sometimes international travelling to one of the other locations above.