This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Do you want to work internationally on securing our IT landscape? Both act in projects as our IT Security Officer and in others provide internal Consultancy? IT Security is continuously increasing its importance at Vattenfall. Our highly secured assets spread over different European countries; the fast evolving digitalization; cyber threats and local security regulations makes our work both challenging and interesting. You will work in an international team of experts in IT Security. We advise and steer on group policy towards all levels of the organization and external partners.
Job Responsibility:
identifying, assessing and reporting IT Security risks
performing security reviews and threat modelling sessions, as well as reporting the findings on a risk-based approach
developing IT security standards and guidelines
validating and assessing the risk for certain IT security changes
ensuring compliance with IT Security standards
embedding security in IT architectural building blocks and solution designs
development of IT security architecture and initiating security improvement initiatives
consulting and guiding the Security Operations teams based on the Cyber Kill Chain Models and Cyber Threat Intelligence
Requirements:
a Bachelor or Academic degree
at least five years of experience in a security expert role in an international or corporate environment
working knowledge of cybersecurity principles, techniques and technologies
experience in application security and network security related concepts
deep understanding on how threat actors operate, execute their kill chain and laterally move within the network
experience in the creation of a secure software development lifecycle
experience in Cloud Security on Microsoft Azure
good level understanding on how operating systems such as Windows and Linux work and how to implement security hardening
experience in relevant IT/Information Security legislations in the European countries where Vattenfall operates
good knowledge of relevant standards, such as ISO27001/2, NIST, CIS
relevant IT Security certifications are plus (e.g. CISSP, CSSLP, GWEB, GWAPT)
other relevant cyber security relevant security certifications are bonus (e.g. CISM, CISA, CRISC, OSCP)
structured and a good planner
great collaboration skills
trustworthy person who is honest and have integrity
Nice to have:
relevant IT Security certifications are plus (e.g. CISSP, CSSLP, GWEB, GWAPT)
other relevant cyber security relevant security certifications are bonus (e.g. CISM, CISA, CRISC, OSCP)
What we offer:
Hybrid working is the norm, so you can combine home office, with visiting your main location and sometimes international travelling