About the Role
Assemblin Caverion Group is a leading northern European provider of technical services and installations, delivering smart and sustainable solutions across the full lifecycle of the built environment. Join us in strengthening cybersecurity across a modern European IT environment. This role is based in Vantaa or Stockholm with an office‑first hybrid model.
Key Responsibilities
- Support the operation, maintenance and continuous improvement of the ISO27001‑based ISMS.
- Implement and maintain security controls, policies, standards and procedures.
- Conduct and support risk assessments, audits and compliance activities.
- Maintain security documentation and governance artefacts.
- Drive security awareness and security culture initiatives across the organization.
- Work with Microsoft security technologies including EntraID, Defender and Sentinel.
- Participate in threat monitoring, detection, investigation and incident response activities.
- Coordinate incident follow‑up, remediation and lessons‑learned activities.
- Collaborate with IT teams to strengthen the overall security posture.
- Contribute to security initiatives involving MFA, Privileged Access Management (PAM) and Zero Trust principles.
- Support continuous enhancement of security detection and response capabilities.
Required Qualifications
- Experience in information security, security operations and/or GRC.
- Good understanding of information security principles, controls and risk management.
- Experience with Microsoft security solutions or similar enterprise platforms.
- Experience with risk assessments, documentation and security processes.
- Understanding of incident detection, response and remediation processes.
- Structured and organized way of working.
Preferred Qualifications
- Experience working with ISO27001‑based ISMS environments.
- Familiarity with CIS Controls and other recognized security frameworks.
- Understanding of audit and compliance processes.
- Experience with SIEM/SOAR platforms such as Microsoft Sentinel.
- Exposure to AI security, AI governance or emerging technology risk topics.
- Certifications such as CISSP, CISM, SC‑200 or ISO27001 Lead Implementer.
Personal Attributes
- Analytical and risk‑aware mindset.
- Strong collaboration and communication skills.
- Ability to work independently, take initiative and drive improvements.
- Curiosity and willingness to stay current with the evolving threat landscape.
Position Context
Part of the Information Security function, reporting to the CISO. Works closely with Group IT, the IAM Service Owner and business stakeholders. The role balances security governance responsibilities with operational security activities and contributes to maintaining a secure and compliant IT environment.
Compensation and Benefits
Competitive salary aligned with Nordic market levels, together with benefits, flexibility and professional development opportunities.