Senior IT Security Officer
Katowice, Silesian Voivodeship, Poland
Vattenfall
Vattenfall is a leading European energy company and we are working for fossil freedom. Read more about us here.Company Description
Vattenfall is one of Europe’s largest producers and retailers of electricity and heat. Our main markets are Sweden, Germany, the Netherlands, Denmark, and the UK. The Vattenfall Group has approximately 21 000 employees. We have been electrifying industries, powering homes and transforming life through innovation for more than 100 years.
Job Description
Do you want to work internationally on securing our IT landscape? Both act in projects as our IT Security Officer and in others provide internal Consultancy?
IT Security is continuously increasing its importance at Vattenfall. Our highly secured assets spread over different European countries; the fast evolving digitalization; cyber threats and local security regulations makes our work both challenging and interesting.
Your responsibilities
You will work in an international team of experts in IT Security. We advise and steer on group policy towards all levels of the organization and external partners. You do this by:
- Developing IT security standards and guidelines
- Identifying, rating and reporting IT Security risks
- Validating and assessing the risk for certain IT security changes
- Performing security reviews and threat modelling sessions, as well as reporting the findings on a risk based approach
- Ensuring compliance with IT Security standards
- Embedding security in IT architectural building blocks and solution designs
- Development of IT security architecture and initiating security improvement initiatives
- Consulting and guiding the Security Operations teams based on the Cyber Kill Chain Models and Cyber Threat Intelligence.
Qualifications
We are looking for an experienced and ambitious person who is not afraid of asking critical questions and that constantly strives for improvement. On top of that you will bring:
- A Bachelor or Academic degree
- At least five years of experience in a security expert role in an international or corporate environment
- Experience in the creation of a secure software development lifecycle.
- Experience in implementation of automated security testing in the CI/CD pipeline.
- Experience in application security and related concepts.
Furthermore ideally you bring:
- Experience in Cloud Security on Microsoft Azure
- Good knowledge of relevant standards, such as ISO27001/2, NIST, CIS
- Relevant IT Security certifications are plus. (e.g. CISSP, CSSLP, GWEB, GWAPT)
- Other relevant cyber security relevant security certifications are bonus (e.g. CISM, CISA, CRISC, OSCP)
As a person we are looking for you who is structured and a good planner. In this position you will work together with a lot of different people and stakeholders, that's why we do value great collaboration skills. We believe you are a trustworthy person who is honest and have integrity.
Additional Information
Location: Katowice or Gliwice. Hybrid working is the norm, so you can combine home office, with visiting your main location and sometimes international travelling to one of the other locations above.
For more information about the position you are welcome to contact a recruiter Marta Jura via e-mail: marta.jura@vattenfall.com
We welcome your application in English. We kindly request that you do not send applications by any means other than via our website.
At Vattenfall we are convinced that diversity contributes to build a more profitable and attractive company and we strive to be a good role model regarding diversity. Vattenfall works actively for all employees to have the same opportunities and rights regardless of gender, ethnicity, age, transgender identity or expression, religion or other belief, disability or sexual orientation. Click here for further information.
We look forward to receiving your application!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Azure CI/CD CISA CISM CISSP Cloud Compliance CRISC CSSLP Cyber Kill Chain GWAPT ISO 27001 NIST OSCP SDLC Threat intelligence
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.