Cybersecurity Risk & QA Manager
at Cubane Solutions AB
Malmö, Skåne län, Sweden -
Start Date | Expiry Date | Salary | Posted On | Experience | Skills | Telecommute | Sponsor Visa |
---|---|---|---|---|---|---|---|
Immediate | 19 Dec, 2024 | Not Specified | 23 Sep, 2024 | N/A | Vulnerability,Quality Assurance Processes,English,Control Testing,Control Framework,Cissp | No | No |
Required Visa Status:
Citizen | GC |
US Citizen | Student Visa |
H1B | CPT |
OPT | H4 Spouse of H1B |
GC Green Card |
Employment Type:
Full Time | Part Time |
Permanent | Independent - 1099 |
Contract – W2 | C2H Independent |
C2H W2 | Contract – Corp 2 Corp |
Contract to Hire – Corp 2 Corp |
Description:
REQUIREMENTS
- Experience in cybersecurity risk management, security control frameworks, and quality assurance.
- Expertise in overseeing and maintaining security frameworks (e.g., NIST CSF, CIS Controls) and conducting internal control testing, audits, and vulnerability assessments.
- Strong capability in driving continuous improvement programs and ensuring operational effectiveness of cybersecurity controls.
- Relevant certifications (CISSP, CISM, CRISC) and fluency in Swedish and English are essential.
- Experience with hybrid environments (on-premise, cloud) and knowledge of Lean-Agile or DevSecOps methodologies.
Responsibilities:
- Cybersecurity Risk Management: Integrate cybersecurity risk management into the Enterprise Risk Management (ERM) framework, ensuring risks are identified, assessed, and mitigated.
- Security Control Framework: Oversee and maintain the Security Control Framework aligned with industry standards (e.g., NIST CSF, CIS Controls) to address risks and ensure effective security controls.
- Threat Catalogue Management: Regularly update and manage the Threat Catalogue to account for evolving threats, guiding mitigation strategies.
- Quality Assurance: Define and drive a robust cybersecurity quality assurance program, including penetration testing, red team exercises, vulnerability scanning, and control testing, ensuring operational effectiveness.
- Continuous Improvement: Drive a cybersecurity continuous improvement program to adapt and enhance controls in response to emerging threats, audit findings, and business needs.
- Regulatory Compliance: Ensure cybersecurity practices comply with regulatory requirements and support regulatory audits, reporting on compliance status.
- Cybersecurity Reporting: Develop and report on Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and cybersecurity maturity assessments to measure effectiveness and guide decision-making.
REQUIREMENT SUMMARY
Min:N/AMax:5.0 year(s)
Financial Services
IT Software - Network Administration / Security
Software Testing, Finance
Graduate
Proficient
1
Malmö, Sweden