Information Security Specialist

Caverion

Helsinki

On-site

EUR 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid office model
Nordic market salary and benefits
Professional development opportunities

Job summary

Assemblin Caverion Group is a leading northern European provider of technical services and installations, delivering smart and sustainable solutions across the built environment. Join us in strengthening cybersecurity across a modern European IT environment.

This role is based in Vantaa or Stockholm with an office‑first hybrid model. The role focuses on ISO27001 ISMS operations, risk assessments and incident response, collaborating with IT teams to elevate our security posture, including work

Qualifications

  • Experience in information security, security operations and/or GRC.
  • Good understanding of information security principles, controls and risk management.
  • Experience with Microsoft security solutions or similar enterprise platforms.
  • Experience with risk assessments, documentation and security processes.
  • Understanding of incident detection, response and remediation processes.
  • Structured and organized way of working.

Responsibilities

  • Support the operation, maintenance and continuous improvement of the ISO27001‑based ISMS.
  • Implement and maintain security controls, policies, standards and procedures.
  • Conduct and support risk assessments, audits and compliance activities.
  • Maintain security documentation and governance artefacts.
  • Drive security awareness and security culture initiatives across the organization.
  • Work with Microsoft security technologies including EntraID, Defender and Sentinel.
  • Participate in threat monitoring, detection, investigation and incident response activities.
  • Coordinate incident follow‑up, remediation and lessons‑learned activities.
  • Collaborate with IT teams to strengthen the overall security posture.
  • Contribute to security initiatives involving MFA, Privileged Access Management (PAM) and Zero Trust principles.
  • Support continuous enhancement of security detection and response capabilities.

Skills

Information security
Security operations
Risk management
Communication
Independent working
Initiative
Curiosity

Education

Bachelor's degree in information security
Certifications such as CISSP, CISM

Tools

Microsoft Defender
Microsoft Sentinel
EntraID

Job description

About the Role

Assemblin Caverion Group is a leading northern European provider of technical services and installations, delivering smart and sustainable solutions across the full lifecycle of the built environment. Join us in strengthening cybersecurity across a modern European IT environment. This role is based in Vantaa or Stockholm with an office‑first hybrid model.

Key Responsibilities
  • Support the operation, maintenance and continuous improvement of the ISO27001‑based ISMS.
  • Implement and maintain security controls, policies, standards and procedures.
  • Conduct and support risk assessments, audits and compliance activities.
  • Maintain security documentation and governance artefacts.
  • Drive security awareness and security culture initiatives across the organization.
  • Work with Microsoft security technologies including EntraID, Defender and Sentinel.
  • Participate in threat monitoring, detection, investigation and incident response activities.
  • Coordinate incident follow‑up, remediation and lessons‑learned activities.
  • Collaborate with IT teams to strengthen the overall security posture.
  • Contribute to security initiatives involving MFA, Privileged Access Management (PAM) and Zero Trust principles.
  • Support continuous enhancement of security detection and response capabilities.
Required Qualifications
  • Experience in information security, security operations and/or GRC.
  • Good understanding of information security principles, controls and risk management.
  • Experience with Microsoft security solutions or similar enterprise platforms.
  • Experience with risk assessments, documentation and security processes.
  • Understanding of incident detection, response and remediation processes.
  • Structured and organized way of working.
Preferred Qualifications
  • Experience working with ISO27001‑based ISMS environments.
  • Familiarity with CIS Controls and other recognized security frameworks.
  • Understanding of audit and compliance processes.
  • Experience with SIEM/SOAR platforms such as Microsoft Sentinel.
  • Exposure to AI security, AI governance or emerging technology risk topics.
  • Certifications such as CISSP, CISM, SC‑200 or ISO27001 Lead Implementer.
Personal Attributes
  • Analytical and risk‑aware mindset.
  • Strong collaboration and communication skills.
  • Ability to work independently, take initiative and drive improvements.
  • Curiosity and willingness to stay current with the evolving threat landscape.
Position Context

Part of the Information Security function, reporting to the CISO. Works closely with Group IT, the IAM Service Owner and business stakeholders. The role balances security governance responsibilities with operational security activities and contributes to maintaining a secure and compliant IT environment.

Compensation and Benefits

Competitive salary aligned with Nordic market levels, together with benefits, flexibility and professional development opportunities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec Specialist - ISO27001, SIEM & Zero Trust
InfoSec Specialist - ISO27001, SIEM & Zero Trust

Caverion • Helsinki

Hybrid
EUR 70,000 - 110,000
Hybrid office model
Nordic market salary and benefits
Professional development opportunities
Security compliance specialist
Security compliance specialist

GleSYS AB • Helsinki

Hybrid
EUR 50,000 - 70,000
30 days of vacation
Parental leave top-ups
Wellness allowance
+3
Cybersecurity Operations Lead
Cybersecurity Operations Lead

Neste • Espoo

On-site
EUR 90,000 - 120,000
Development Manager, Information and Cybersecurity
Development Manager, Information and Cybersecurity

Aalto-yliopisto • Espoo

Hybrid
EUR 90,000 - 130,000
Flexible working hours
Location arrangements
Professional development opportunities
Software Architect (Security)
Software Architect (Security)

Digia Plc • Jyväskylä

Hybrid
EUR 90,000 - 125,000
Occupational healthcare
Holiday cottages
€2,000 referral bonus
+2
Cybersecurity Manager
Cybersecurity Manager

Metso Oyj • Espoo

Hybrid
EUR 110,000 - 150,000
Chief Information Security Officer, Tieto Banktech (m/f/d)
Chief Information Security Officer, Tieto Banktech (m/f/d)

Tieto • Vantaa

Hybrid
EUR 90,000 - 120,000
Chief Information Security Officer, Tieto Banktech (m/f/d)
Chief Information Security Officer, Tieto Banktech (m/f/d)

Tieto • Finland

Hybrid
EUR 90,000 - 120,000
Professional growth
Flexible hybrid work model
Outstanding work-life balance
Staff Security Engineer
Staff Security Engineer

Supermetrics • Helsinki

On-site
EUR 90,000 - 130,000
Equity
Home office allowance
Annual personal learning budget
+1
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Sympa Oy • Espoo

Hybrid
EUR 120,000 - 180,000
Lunch and cultural benefits
Professional growth support