Do you want to take responsibility for information security, data protection, and GDPR in a socially important organization and be a central part of driving development forward? Here you'll have the chance to make an impact, improve processes, and make a real difference!
About the Position
This is a direct recruitment, which means the recruitment process is conducted through Bravura and you will be employed directly by Energiföretagen Sverige.
About the Company
Energiföretagen Sverige is the industry organization for electricity, heating, and cooling companies in Sweden. The organization brings together a large part of the energy sector's stakeholders and serves as a central voice in matters concerning the energy system's development, regulations, and transition to a fossil-free society.
Member companies are responsible for production, distribution, and trading of energy and work together toward the vision "Sustainable energy for all, always." As the energy system undergoes a comprehensive transformation, questions related to information security, data protection, and regulatory compliance are becoming increasingly important, both for the organization and for the industry as a whole.
Here you'll be part of an organization where experts in energy markets, policy, technology, and business development work together. The work takes place close to operations with many points of contact, both internally and externally, where you collaborate with colleagues, member companies, and other actors in Sweden's energy sector.
Responsibilities
As Information Security Manager, you have overall responsibility for the organization's work in information security and data protection. You serve as the Data Protection Officer and ensure that operations comply with applicable regulations, while developing methods, structures, and governance in the field.
You work closely with IT and other parts of the organization where you act as a supporter, advisor, and requirement setter. The role involves identifying areas for improvement and driving initiatives, with a clear mandate to ensure compliance.
The role combines strategic work with operational execution, from developing frameworks to conducting audits and handling ongoing inquiries.
Your areas of responsibility include:
• Drive and develop the organization's GDPR work and ensure compliance
• Manage ISMS (Stratsys), including implementation, administration, and development
• Drive, implement, and develop processes related to ISO 27001
• Conduct audits, monitor compliance, and drive improvement measures
• Support operations in information security and data protection matters
• Handle inquiries from member companies and external parties on regulatory matters, such as NIS2
• Monitor the external environment and identify areas for development
Education, Experience, and Personal Qualities
• Post-secondary education in IT, information security, law, or equivalent
• At least 3 years of experience in information security and GDPR
• Experience with ISO 27001 or similar frameworks
• Experience independently driving work in information security and data protection
• Excellent Swedish and good English, both spoken and written
Meritorious
• Experience in a DPO/DSA role
• Experience from regulated sectors
• Certifications in information security/data protection
• Experience with ISMS, specifically Stratsys
• Experience related to NIS2/CSL
To succeed in this role, you work both independently and in close collaboration with others. You take responsibility for driving your work forward, structure what needs to be done, and follow up on execution.
You are analytical and can switch between the big picture and details when assessing risks and needs. At the same time, you are confident in your expertise and stand by your judgments, even when it means setting requirements on the organization.
Your communication skills mean you can explain complex matters in a way that makes them understandable to everyone, both internally and externally. You build trust and bring the organization along in matters concerning information security and data protection.
Other Information
Start: By agreement | Location: Stockholm | Salary: By agreement
We use a competency-based methodology in all recruitment processes to ensure unbiased selection. We also work with ongoing selection, which means we remove the ad when we have received a sufficient number of applications. If you become a candidate for the position, we will contact you for an initial phone interview. Regardless of whether you advance in the process or not, you will receive feedback on your application.
Questions? Feel free to reach out!
📧 [email protected]
📞 010-171 47 10
We recommend that you submit your application immediately as we are conducting ongoing selection.
We look forward to your application!
#BrillanteDo you want to take responsibility for information security, data protection, and GDPR in a socially important organization and be a central part of driving development forward? Here you'll have the chance to make an impact, improve processes, and make a real difference!
About the Position
This is a direct recruitment, which means the recruitment process is conducted through Bravura and you will be employed directly by Energiföretagen Sverige.
About the Company
Energiföretagen Sverige is the industry organization for electricity, heating, and cooling companies in Sweden. The organization…