Sr Information Security Advisor, Third Party Risk Management

Novo Nordisk

Ballerup

On-site

DKK 743,000 - 1,092,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Novo Nordisk is seeking a Senior Information Security Advisor to lead and mature the Third-Party Risk Management programme. You will ensure supplier and external partner risks are identified, assessed and managed across the lifecycle, strengthening supply chain security for Novo's information, systems and services.

You will work in a global environment, collaborating with Procurement, Legal and the broader Information Security team to drive secure vendor engagements and maintain regulatory

Qualifications

  • 10+ years in Information Security with extensive Third-Party Risk Management in global orgs.
  • Experience in supplier security assessments, due diligence, and risk evaluations.
  • Knowledge of ISO 27001/27002, ISO 27036, NIST CSF and SOC 2 reporting.

Responsibilities

  • Mature the TPRM programme and embed security in procurement and ERM.
  • Develop governance, processes, reporting, and tooling for TPRM.
  • Align with Novo security requirements, NIS2, and industry standards.
  • Integrate third-party security into procurement, contracting, and onboarding.
  • Advise on security requirements and mitigation plans with contract owners.
  • Collaborate cross-functionally to reduce third-party risk exposure and monitor suppliers.

Skills

Third-Party Risk Management
Information Security
Supplier Security Assessments
Stakeholder Management
Risk Management
Security Frameworks

Job description

Location

Ballerup, Denmark

Job category

Information Security / Product & Portfolio Strategy

Your impact begins here

As Senior Information Security Advisor, you will lead and mature Novo's Third-Party Risk Management programme, making sure the information security, operational resilience and regulatory risks tied to suppliers and external partners are identified, assessed and managed across the supplier lifecycle. Your work strengthens supply chain security today, protecting the company information, systems and services that keep Novo delivering for people living with serious chronic diseases.

What You'll Bring
  • 10+ years of experience in Information Security, including significant hands‑on Third-Party Risk Management in large, global organisations.
  • Practical experience conducting supplier security assessments, due diligence activities and risk evaluations.
  • Strong knowledge of information security principles, risk management and industry frameworks such as ISO 27001 / 27002, ISO 27036, NIST CSF and SOC 2 audit reporting.
  • An understanding of regulatory and industry requirements affecting third-party and supply chain security, including NIS2 and other relevant cybersecurity obligations.
  • Excellent stakeholder management, communication, facilitation and influencing skills, with the ability to collaborate across diverse business and technology teams and drive change without direct authority.
  • A team-player mindset built on support and collaboration.
Useful, But Not Essential

Relevant certifications such as CISSP, CISM, CRISC or ISO 27001 Lead Auditor / Implementer, or equivalent information security and risk management certifications.

What You'll Do

You will drive and continuously mature the TPRM programme, embedding security requirements into procurement, the ISMS framework and enterprise risk management, and advising on critical and high-risk supplier engagements.

  • Contribute to the ongoing development of TPRM governance, processes, methodologies, reporting and tooling.
  • Keep the programme aligned with Novo security requirements, legal and regulatory obligations including NIS2, industry standards and enterprise risk management practices.
  • Integrate third-party security requirements into procurement, sourcing, contracting, supplier onboarding and lifecycle management.
  • Advise contract owners and stakeholders on security requirements, supplier risk treatment and regulatory obligations, and support the implementation of contractual security requirements and mitigation plans.
  • Collaborate across business and technology areas to strengthen supply chain security and reduce third-party risk exposure.
  • Monitor supplier security and compliance performance and facilitate reassessment activities.
Who You'll Work With

You will join the Cyber, Risk & Resilience team within Infrastructure and Information Security, focused on governance, compliance and assurance, and risk management. The team spans corporate governance, ISMS management, board risk reporting, regulatory compliance and Third-Party Risk Management, supporting the Novo CISO and Top Management with high-quality deliveries.

Your closest partners will be business stakeholders, Procurement, Legal and the broader Information Security team, alongside external partners and suppliers. This is a collaborative group that supports one another informally and works together to make information security a vital part of Novo's business. Bringing clarity and momentum across these relationships is how you will reduce risk and move work forward.

What You Can Expect Here

You will work in a global environment where your expertise shapes how Novo manages supplier and supply chain risk. You will be trusted to take ownership, make your voice heard and drive change, while being supported to keep growing through cross-functional collaboration and continuous learning.

What We Offer

At Novo, you'll join a global healthcare company with a distinctive culture and strong results, with career development and benefits tailored to your life and career stage.

Salary

For this role, the Annual Base Salary ranges from 742,600.00 to 1,091,600.00 DKK, corresponding to the level of the position. The placement within the salary range will be assessed during the recruitment process based on the candidate's skills, competencies, knowledge and relevant experience.

Incentives and Benefits

The salary package may include short-term and/or long-term incentives as well as other employee benefits based on position level, location, functional area and relevant market benchmarks.

For more information about the role, please contact Ronnie Lykke Madsen at +45 30790930.

We commit to an inclusive recruitment process and equality of opportunity for all our job applicants.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr Information Security Advisor, Risk Management & Reporting
Sr Information Security Advisor, Risk Management & Reporting

Novo Nordisk A/S • Ballerup

Remote
DKK 847,000 - 1,245,000
Senior IT Security Architecture (Denmark, Ballerup)
Senior IT Security Architecture (Denmark, Ballerup)

Novo Nordisk A/S • Ballerup

On-site
DKK 743,000 - 1,092,000
Senior Third-Party Risk Security Advisor
Senior Third-Party Risk Security Advisor

Novo Nordisk • Ballerup

On-site
DKK 743,000 - 1,092,000
Senior IT Project Manager (Denmark, Måløv)
Senior IT Project Manager (Denmark, Måløv)

Novo Nordisk A/S • Måløv

On-site
DKK 743,000 - 1,092,000
Associate Director - P&O and Quality AI Solutions
Associate Director - P&O and Quality AI Solutions

Novo Nordisk A/S • Ballerup

Remote
DKK 941,000 - 1,449,000
IT Security Manager
IT Security Manager

Novo Nordisk A/S • Pederstrup

On-site
DKK 651,000 - 957,000
Associate Director - P&O and Quality AI Solutions
Associate Director - P&O and Quality AI Solutions

Novo Nordisk • Ballerup Kommune

On-site
DKK 941,000 - 1,449,000
Associate Vice President, Global Security, Novo
Associate Vice President, Global Security, Novo

Novo Nordisk • Gladsaxe Kommune

On-site
DKK 2,000,000 - 3,200,000
Senior IT Project Manager
Senior IT Project Manager

Novo Nordisk • Måløv

On-site
DKK 743,000 - 1,092,000
Associate Vice President, Global Security, Novo
Associate Vice President, Global Security, Novo

Novo Nordisk A/S • Gladsaxe Kommune

On-site
DKK 1,200,000 - 2,000,000