Cybersecurity Risk & QA Manager

at  Cubane Solutions AB

Malmö, Skåne län, Sweden -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate19 Dec, 2024Not Specified23 Sep, 2024N/AVulnerability,Quality Assurance Processes,English,Control Testing,Control Framework,CisspNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

REQUIREMENTS

  • Experience in cybersecurity risk management, security control frameworks, and quality assurance.
  • Expertise in overseeing and maintaining security frameworks (e.g., NIST CSF, CIS Controls) and conducting internal control testing, audits, and vulnerability assessments.
  • Strong capability in driving continuous improvement programs and ensuring operational effectiveness of cybersecurity controls.
  • Relevant certifications (CISSP, CISM, CRISC) and fluency in Swedish and English are essential.
  • Experience with hybrid environments (on-premise, cloud) and knowledge of Lean-Agile or DevSecOps methodologies.

Responsibilities:

  • Cybersecurity Risk Management: Integrate cybersecurity risk management into the Enterprise Risk Management (ERM) framework, ensuring risks are identified, assessed, and mitigated.
  • Security Control Framework: Oversee and maintain the Security Control Framework aligned with industry standards (e.g., NIST CSF, CIS Controls) to address risks and ensure effective security controls.
  • Threat Catalogue Management: Regularly update and manage the Threat Catalogue to account for evolving threats, guiding mitigation strategies.
  • Quality Assurance: Define and drive a robust cybersecurity quality assurance program, including penetration testing, red team exercises, vulnerability scanning, and control testing, ensuring operational effectiveness.
  • Continuous Improvement: Drive a cybersecurity continuous improvement program to adapt and enhance controls in response to emerging threats, audit findings, and business needs.
  • Regulatory Compliance: Ensure cybersecurity practices comply with regulatory requirements and support regulatory audits, reporting on compliance status.
  • Cybersecurity Reporting: Develop and report on Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and cybersecurity maturity assessments to measure effectiveness and guide decision-making.


REQUIREMENT SUMMARY

Min:N/AMax:5.0 year(s)

Financial Services

IT Software - Network Administration / Security

Software Testing, Finance

Graduate

Proficient

1

Malmö, Sweden