Senior Security Governance, Risk, and Compliance (GRC) Specialist
Asker, Norway
Tomra
TOMRA's mission is to transform how we all obtain, use and reuse the planet's resources to enable a world without waste.Company Description
TOMRA was founded in 1972, based on the design, manufacturing and sale of reverse vending machines (RVMs) for automated collection of used beverage containers. Today TOMRA provides technology-led solutions for transforming how society and industries obtain, use and reuse the planet’s resources to enable a world without waste
We believe that through challenging status quo, we inspire our customers, lead by example, and take part in the beauty of transformation. Want to learn more about TOMRA? Please visit us at www.TOMRA.com.
Job Description
Senior Security GRC Specialist
The TOMRA Group Security function is seeking a skilled and experienced GRC specialist to join the Security GRC team in Asker. The successful candidate will work closely with the Head of the Security GRC department to develop and standardize a best practice approach to information security governance, risk management, and compliance across the organization. This role involves working closely with stakeholders to ensure the necessary policies, frameworks, and tools are in place to protect the confidentiality, integrity, and availability of our most valuable assets.
Key Responsibilities:
Develop and implement security policies, standards, and procedures to ensure compliance with regulatory requirements and industry best practices.
Conduct risk assessments and develop risk mitigation strategies to address identified vulnerabilities.
Monitor and report on the effectiveness of the security program, including compliance with internal policies and external regulations, conducting maturity assessments, and driving continuous improvement initiatives.
Collaborate with various departments to ensure security controls are integrated into business processes and systems.
Stay up-to-date with the latest security trends, threats, and technologies to continuously improve the security posture of the organization.
Qualifications
Bachelor's degree in Information Security, Computer Science, or a related field.
Minimum of 5 years of experience in information security, with a focus on governance, risk management, and compliance.
Strong knowledge of security frameworks and standards such as ISO/IEC 27001, NIST, and ISF Standard of Good Practice.
Experience with security policy development and implementation, risk assessment methodologies and tools, and assurance activities.
Excellent communication and interpersonal skills, with the ability to work effectively with stakeholders at all levels of the organization.
Relevant certifications such as ISO 27001or CISM / CISA are highly desirable.
Preferred Skills:
Knowledge of operational technology (OT) security and secure software/system development processes.
Familiarity with security maturity models such as ISF related maturity tools, NIST CSF, C2M2, ISO 27001, CIS Controls and NIS2.
Additional Information
We encourage interested candidates to apply as soon as possible. Reviewing candidates and interviews will be conducted on an ongoing basis, and the process may be closed if the right candidate is found before the deadline.
Deadline for applications: 10.02.2025
TOMRA is proud to be an Equal Opportunity Employer and provides equal employment opportunities to all employees and applicants regardless of race, color, religion, gender, gender identity, age, national origin, disability, parental or pregnancy status, marriage and civil partnership, sexual orientation, veteran status, or any other characteristic protected by law.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CISA CISM Compliance Computer Science Governance ISO 27001 NIS2 NIST Risk assessment Risk management Vulnerabilities
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.