Security & Compliance Lead
Om jobbet
Join our TeamAbout this opportunity:
We are seeking a highly skilled Security and Compliance Lead to join our team. As the Security and Compliance Lead for Product Area (PA) Employee Experience, your role is to ensure the security and compliance of IT products throughout their entire lifecycle - where built-in security and compliance capabilities are prioritized over bolt-on. As part of this role, you will lead the integration of security practices, collaborate with cross-functional teams, and foster a security-aware culture.
The Security and Compliance Lead position is reporting to the Head of PA Employee Experience and is part of the PA Employee Experience Leadership Team. Security clearance is required for this role.
Product Area Employee Experience - a part of Enterprise IT
PA Employee Experience is end-to-end accountable for delivery and development of Enterprise IT capabilities for Employee Experience at Ericsson - including IT capabilities for functional domains People/Human Resources and Real Estate as well as company-wide employee IT capabilities for Productivity & Collaboration, Unified Communications, Computer & Mobile, and Digital Experience.
What you will do:
- Integration of Security Practices: Lead the integration of security practices into the Product Area (PA) workflow, ensuring security is embedded at every stage of the development process. Collaborate with development, operations, and security teams to implement security controls, automate security testing, and establish security checkpoints within the CI/CD pipeline.
Built-in Security Features:
Work closely with product development teams to design and implement built-in security features and controls. Conduct threat modeling exercises and integrate security controls directly into the product architecture and design.
Security Automation and Orchestration:
Utilize automation and orchestration tools to streamline security processes and workflows. Automate security scans, vulnerability assessments, and compliance checks, while orchestrating security tasks and responses to security incidents.
Security Training and Awareness:
Collaborate with the IT Security & Compliance team to provide tailored security training and awareness programs. Educate developers, operators, and other stakeholders about secure coding practices, cloud security fundamentals, and DevSecOps principles.
Security Governance and Compliance Reporting:
Adhere to governance frameworks for IT security practices and develop compliance reporting mechanisms to ensure alignment with industry standards and regulatory requirements.
The skills you bring:
- Analytical skills with proficiency in understanding information flows and strong analytical abilities
- In-depth knowledge of security standards such as ISO 27000, NIST SP 800-53,
- NIST 800-171, GDPR, NIS 2, SSDF.
- Leadership experience leading global teams with high integrity and collaboration skills
- Excellent communication skills, both written and verbal
- Deep understanding of the operational interface between business and IT
- Solid understanding of business and financial management
- Ability to prioritize and collaborate with various stakeholders to align IT-Security Solution delivery with organizational strategy.
Preferred Certifications:
- CISA, CISM, CISSP, ISO Lead Auditor, SAP Certification.
Valuable Experience:
- Several years of experience in implementing IT Security Architecture standards.
- Experience in a similar role within a large, complex organization.
Application
We look forward to your application with CV/Resume in English.
Last day to apply: 24th of January 2025
Location: Stockholm, Sweden
Flexibility of work: We target 60% attendance at office.
Please note that we do not accept, progress, or respond to applications sent via e-mail.
If you have specific questions, you are welcome to contact Nina Juthage, Sr. Recruiter, at [email protected]
Why join Ericsson?
At Ericsson, you'll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what's possible. To build solutions never seen before to some of the world's toughest problems. You'll be challenged, but you won't be alone. You'll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?
Click Here to find all you need to know about what our typical hiring process looks like.
Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we nurture it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity and Affirmative Action employer, learn more.
If you need assistance or to request an accommodation due to a disability, please contact Ericsson at [email protected]
DISCLAIMER: The above statements are intended to describe the general nature and level of work being performed by employees in this position. They are not an exhaustive list of all responsibilities, duties and skills required for this position, and you may be required to perform additional job tasks as assigned.
Primary country and city:
Sweden (SE) || Stockholm
Job details:
IT Business Operations Manager
Ericsson AB
FöretagEricsson AB
Visa alla jobb för Ericsson AB