We are looking for an experienced Cybersecurity GRC Lead to strengthen our cybersecurity governance foundation across SSAB and enable our business to grow with confidence.
In this position, you will act as a primary expert and lead our efforts to further develop our Cybersecurity Management System (ISMS) closely aligned with aligned with ISO 27001 standards. You will be driving audit and compliance activities targeted at improving cybersecurity maturity and reducing business risks. You will act as a trusted advisor to business leaders, IT teams, and cybersecurity stakeholders globally and ensure customers, regulators, and shareholders have high trust in how we run our business.
This is a highly visible expert role with a significant impact on our cybersecurity maturity enhancement journey, enhancing customer trust, and ensuring regulatory compliance.
This role can be based in our Helsinki or Stockholm office and will be reporting to Markus Lalla, Group CISO. Please note that we cannot provide relocation support for this position.
Main Responsibilities
- Lead cybersecurity governance, risk, and compliance (GRC) program across the Group and foster shared accountability for cybersecurity matters across all business divisions
- Develop, implement and maintain the Group wide Cybersecurity Management System (ISMS) to ensure that SSAB’s information assets are adequately protected at all times
- Drive ISO 27001 standard alignment, customer requirements, and other cybersecurity regulations compliance, including compliance with NIS2 and TISAX and associated risk remediation activities
- Develop and maintain cybersecurity directives and instructions, enhance our cybersecurity risk management process and establish clear ownership and accountability for security controls across the organization
- Lead supplier cybersecurity assurance together with Procurement
- Take leadership over internal and external audits and 3rd party risk management activities as the primary liaison with auditors, regulators, customers, and certification bodies on cybersecurity governance matters
- Coordinate cybersecurity reporting, KPI monitoring and management reviews for executive leadership
About You
- You have significant experience (typically 10+ years) in cybersecurity governance, risk, compliance, information security, or IT audit roles preferrable from a manufacturing industry background
- You have proven hands-on experience leading an ISO 2701 implementation or certification journey in a larger organization
- You have many times managed and successfully lead external and internal audits, compliance programs, and risk management processes
- You have a track record of operating and improving an ISMS in a complex organization
- You possess a strong understanding of ISO 27001, ISO 27002, risk management, and other security management frameworks and are good at driving compliance topics in a matrix environment where maturity around cyber security varies across the organization
- You have good experience evaluating supplier security and third-party risk management
- You act as a trusted advisor and are able to establish lasting working relationships and move the agenda forward with a variety of stakeholders who often highlight your exceptional communication skills
- Your colleagues often describe you as someone with strong judgment, integrity, and personal accountability
- You hold certifications such as CISM, CISA, CRISC, CISSP or ISO 27001 LI/LA
- You are fluent in English, both written and spoken. Proficiency in one or more Nordic languages is considered an advantage.
Recruitment Process
- First call with a Recruiter
- Meet the Hiring Manager
- Meet the Team and key stakeholders
- Pre-Offer Checks
Julia Källmar, Group Talent Acquisition Partner, Julia.kallmar@ssab.com