Senior Security Governance, Risk, and Compliance (GRC) Specialist

Asker, Norway

Tomra

TOMRA's mission is to transform how we all obtain, use and reuse the planet's resources to enable a world without waste.

View all jobs at Tomra

Apply now Apply later

Company Description

TOMRA was founded in 1972, based on the design, manufacturing and sale of reverse vending machines (RVMs) for automated collection of used beverage containers. Today TOMRA provides technology-led solutions for transforming how society and industries obtain, use and reuse the planet’s resources to enable a world without waste 

We believe that through challenging status quo, we inspire our customers, lead by example, and take part in the beauty of transformation. Want to learn more about TOMRA? Please visit us at www.TOMRA.com

Job Description

Senior Security GRC Specialist 

The TOMRA Group Security function is seeking a skilled and experienced GRC specialist to join the Security GRC team in Asker. The successful candidate will work closely with the Head of the Security GRC department to develop and standardize a best practice approach to information security governance, risk management, and compliance across the organization. This role involves working closely with stakeholders to ensure the necessary policies, frameworks, and tools are in place to protect the confidentiality, integrity, and availability of our most valuable assets. 

Key Responsibilities: 

  • Develop and implement security policies, standards, and procedures to ensure compliance with regulatory requirements and industry best practices. 

  • Conduct risk assessments and develop risk mitigation strategies to address identified vulnerabilities. 

  • Monitor and report on the effectiveness of the security program, including compliance with internal policies and external regulations, conducting maturity assessments, and driving continuous improvement initiatives. 

  • Collaborate with various departments to ensure security controls are integrated into business processes and systems. 

  • Stay up-to-date with the latest security trends, threats, and technologies to continuously improve the security posture of the organization. 

Qualifications

  • Bachelor's degree in Information Security, Computer Science, or a related field. 

  • Minimum of 5 years of experience in information security, with a focus on governance, risk management, and compliance. 

  • Strong knowledge of security frameworks and standards such as ISO/IEC 27001, NIST, and ISF Standard of Good Practice. 

  • Experience with security policy development and implementation, risk assessment methodologies and tools, and assurance activities. 

  • Excellent communication and interpersonal skills, with the ability to work effectively with stakeholders at all levels of the organization. 

  • Relevant certifications such as ISO 27001or CISM / CISA are highly desirable. 

Preferred Skills: 

  • Knowledge of operational technology (OT) security and secure software/system development processes. 

  • Familiarity with security maturity models such as ISF related maturity tools, NIST CSF, C2M2, ISO 27001, CIS Controls and NIS2. 

Additional Information

    We encourage interested candidates to apply as soon as possible. Reviewing candidates and interviews will be conducted on an ongoing basis, and the process may be closed if the right candidate is found before the deadline.

    Deadline for applications: 10.02.2025 

    TOMRA is proud to be an Equal Opportunity Employer and provides equal employment opportunities to all employees and applicants regardless of race, color, religion, gender, gender identity, age, national origin, disability, parental or pregnancy status, marriage and civil partnership, sexual orientation, veteran status, or any other characteristic protected by law. 

    Apply now Apply later

    * Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

    Job stats:  4  2  0
    Category: Compliance Jobs

    Tags: CISA CISM Compliance Computer Science Governance ISO 27001 NIS2 NIST Risk assessment Risk management Vulnerabilities

    Region: Europe
    Country: Norway

    More jobs like this

    Explore more career opportunities

    Find even more open roles below ordered by popularity of job title or skills/products/technologies used.