Do you want to work internationally on securing our IT landscape? Both act in projects as our IT Security Officer and in others providing internal consultancy?
IT Security is continuously increasing in it’s importance at Vattenfall. Our highly secured assets spread over different European countries; the fast evolving digitalization; cyber threats and local or EU security regulations makes our work both challenging and interesting.
Your responsibilities
You will work in an international team of experts in IT Security. We advise and steer on group security policy towards all levels of the organization and external partners. You do this by:
- identifying, assessing and reporting IT Security risks
- performing security reviews and threat modelling sessions, as well as reporting the findings on a risk-based approach
- developing IT security standards and guidelines
- validating and assessing the risk for certain IT security changes
- ensuring compliance with IT Security standards
- embedding security in IT architectural building blocks and solution designs
- development of IT security architecture and initiating security improvement initiatives
- consulting and guiding the Security Operations teams based on the Cyber Kill Chain Models and Cyber Threat Intelligence.
We are looking for an experienced and ambitious person who is not afraid of asking critical questions and that constantly strives for improvement. On top of that you will bring:
- a Bachelor or Academic degree
- at least five years of experience in a security expert role in an international or corporate environment
Furthermore, ideally you bring:
- working knowledge of cybersecurity principles, techniques and technologies
- experience in application security and network security related concepts
- deep understanding on how threat actors operate, execute their kill chain and laterally move within the network.
- experience in the creation of a secure software development lifecycle
- experience in Cloud Security on Microsoft Azure
- good level understanding on how operating systems such as Windows and Linux work and how to implement security hardening
- experience in relevant IT/Information Security legislations in the European countries where Vattenfall operates
- good knowledge of relevant standards, such as ISO27001/2, NIST, CIS
- relevant IT Security certifications are plus. (e.g. CISSP, CSSLP, GWEB, GWAPT), other relevant cyber security relevant security certifications are bonus (e.g. CISM, CISA, CRISC, OSCP)