Senior Information Security Officer

Heimstaden Bostad AB

København

Hybrid

DKK 900,000 - 1,200,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Visible role engaging with senior领导
Collaboration with international teams
Inclusive working environment
Competitive compensation and benefits

Job summary

Heimstaden Bostad AB, Copenhagen-based, is expanding its Information Security function with a Senior Information Security Officer. You will shape governance, risk and assurance across a pan-European real estate portfolio and engage with C-suite and business leaders across Europe.

You will lead security governance, risk lifecycle and supplier security programs, driving practical controls and measurable improvements while embedding security into business processes and supplier relationships.

Qualifications

  • Enthusiasm for information security and continuous learning.
  • Substantial hands-on information security, GRC, risk management experience in a large/complex org.
  • Knowledge of ISO 27000 family and NIST CSF; ability to codify policies, standards and guidance.
  • Experience with security risk assessments and supplier security; ability to drive remediation.

Responsibilities

  • Develop and maintain information security governance model, control framework, policies, standards and practical guidance.
  • Coordinate information security risk lifecycle including assessments, treatment plans, risk acceptance, exceptions and reporting.
  • Lead security assessments of suppliers and services; review evidence; document security decisions; track remediation.
  • Plan and perform security assurance reviews to evaluate control design and operation.
  • Advise management on information security risks and safeguards; define security requirements across identity, cloud, data and suppliers.
  • Develop security awareness activities and measure their effectiveness.
  • Establish security metrics and clear reporting for the CISO and senior management.
  • Collaborate with IT, Compliance & Legal, Procurement and business owners to ensure shared understanding and accountability.

Skills

Information security
Governance & risk
Stakeholder management
Communication
English proficiency
Scandinavian language advantage

Education

CISSP
CISM
CRISC

Job description

Help shape information security across a large European organization

Heimstaden Group is a pan-European real estate investor,managerand operator. We manage approximately 155,500 homes across nine countries,representinga property value of around EUR 30 billion.

Our business is supported by close to 2,000 people across Czechia, Denmark, Finland, Germany, the Netherlands, Norway, Poland,Swedenand the United Kingdom.

Operating at this scale creates a broad and evolving information security landscape.We are strengthening our Information Security function with a Senior Information Security Officer who can help turn security requirements into practical controls, cleardecisionsand measurable improvements across the organization.

Job Description

The role

You will report to and work closely with the Director for Global IT Services & Cybersecurity (CISO) as part of the Information Security team, while engaging with senior leaders, technologyteamsand business functions across Europe.

This is a senior, hands-on role in a function that is still beingestablished. You will improve its structure and ways of working while delivering and coordinating governance,riskand assurance activities. You will influence how information security is embedded into business processes, technologydecisionsand supplier relationships.

Your responsibilities

Working closely with the CISO,you will:

  • Develop andmaintainour information security governance model, control framework, policies,standardsand practical guidance.
  • Coordinate the informationsecurity risk lifecycle, including assessments, treatment plans, risk acceptance, exceptions,follow-upand reporting.
  • Lead security assessments of suppliers and services by reviewing evidence,identifyingmaterial risks, documenting securitydecisionsand tracking remediation.
  • Plan and perform securityassurance reviews to evaluate whether controls are appropriately designed, implemented andoperatingeffectively.
  • Advise management and employees on informationsecurity risks,requirementsand proportionate safeguards.
  • Define and follow up security requirements in areas such as identity and privileged access, cloud and SaaS services, sensitiveinformationand critical suppliers.
  • Develop securityawareness activities and practical guidance, and measure whether they produce the intended results.
  • Establish meaningful security metrics and prepare clearreportinganddecision supportfor the CISO and senior management.
  • Work with IT, Compliance & Legal,Procurementand business owners to ensure that security requirements and decisions are understood, and that agreed actions have clear owners and are followed through.
  • Ensure that security plans, decisions and supporting evidence are clearly documented, and that agreed actions are tracked to completion.

Technical teams and business ownersremainresponsible for implementing andoperatingtheir controls. Your role is to define security requirements, provide informed professional challenge and assurance, and ensure that risks and actions are brought to theappropriate accountableowner for decision.

Qualifications

About you

Skills and experience can be developed indifferent ways, and we do not expect one candidate to match every point. You are likely to succeed if you bring:

  • A genuine enthusiasm for information security, with the drive to keep learning, stay current with the evolving threat and regulatory landscape, and turn new knowledge into practical improvements.
  • Substantialhands-onexperience with information security, GRC, security assurance or risk management in a large or complex organization, including independently leading complex assignments through to completion.
  • Practical knowledge of the ISO 27000 family and frameworks such as the NIST Cybersecurity Framework, with experience developing workable policies, standards,controlsand guidance.
  • Experience with securityrisk assessments, supplier security, controlassuranceand remediation follow-up.
  • Sufficient technical understanding to engagewithspecialists andthe abilityconnect technical,riskand business perspectives acrossvarious cybersecurity domains.
  • Strong written and verbal communication skills in English. The ability to speak and understand a Scandinavian language is a significant advantage.
  • Confidence working with senior stakeholders across countries and organizational boundaries, using your professional experience and judgmentto advise clearly, challenge constructively and build support for well-informed decisions.
  • A structured,analyticaland pragmatic approach, combined with curiosity and attention to detail.
  • A self-driven and independent working style, with the ability to structure and deliver complex assignments with limited direction while knowing when to seek input or escalate.

Relevant education or equivalent practical experience is expected. Certifications such as CISSP, CISM,CRISCor similarare beneficial but not essential.

Additional Information

What we offer

  • A visible and influential role helping mature Information Security across a sizeable pan-European organization, withdirectengagementwithseniorleadership.
  • Collaboration with experiencedcolleaguesand industry experts across several European countries, with good opportunities forprofessional development.
  • A collaborative and inclusive working environment that values initiative,innovationand excellence.
  • A competitive compensation and benefits package.

Workplace

This is an office-based position in Copenhagen, Denmark,locatednext to Copenhagen Central Station.Physical presence is an important part of the role because we believe close in-person collaboration enables better dialogue, fasterdecisionsand stronger shared ownership.

The roledoes not require regulartravel, although occasional travel mayoccur.

If you enjoy broad responsibility and want to turn security requirements into practical and measurable improvements, we would like to hear from you.

We welcome applications from candidates withdifferent backgroundsand experiences, and we encourage you to apply even if you do not meet every listed qualification.

Heimstadendoes not provide sponsorship for residence or work permits for this position. Applicants must already have the legal right to live and work in Denmark.

Applications are reviewed on an ongoing basis, and we aim to appoint the right candidate as soon as possible.

We conduct background checks as part of our recruitment process. If you have any questions regarding this, you are welcome to contact us!

At Heimstaden, we value diversity and believe that different perspectives create better decisions and a stronger work environment.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Job Location
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior InfoSec Leader - Governance & Risk
Senior InfoSec Leader - Governance & Risk

Heimstaden Bostad AB • København

Hybrid
DKK 900,000 - 1,200,000
Visible role engaging with senior领导
Collaboration with international teams
Inclusive working environment
+1
Information Security Analyst
Information Security Analyst

SkyCrew • Odense

Hybrid
DKK 69,000 - 116,000
Information Security Analyst
Information Security Analyst

Abroad Work • København

On-site
Visa sponsorship
Airfare for international candidates
Information Security Analyst
Information Security Analyst

EventMakers Entertainment • Denmark

On-site
DKK 112,000 - 134,000
Health insurance
Paid time off
Professional development
Information Security Analyst (Part-time)
Information Security Analyst (Part-time)

WaveSolutions • Denmark

On-site
DKK 66,000 - 79,000
Information Security Analyst
Information Security Analyst

MapleClass Education • København

On-site
Information Security Analyst - Cybersecurity Specialist
Information Security Analyst - Cybersecurity Specialist

BrightMark GmbH • Denmark

On-site
DKK 112,000 - 134,000
Information Security Analyst
Information Security Analyst

Woopel • Horsens

On-site
Information Security Manager
Information Security Manager

Plesner • København

On-site
DKK 900,000 - 1,300,000
Information Security Manager
Information Security Manager

Plesner • Denmark

On-site
DKK 900,000 - 1,200,000