OBS! Ansökningsperioden för denna annonsen har
passerat.
Arbetsbeskrivning
Mission
Monitor and drive cybersecurity initiatives across Natural Cycles both from a technical and a compliance perspective.
Responsibilities
Cybersecurity Champion
Being on constant lookout for weaknesses and quick-wins, both those that can be addressed directly or via definition of cybersecurity requirements for other teams.
Threat Intelligence & SIEM
Establish and maintain centralized system for monitoring security events
Gather data from relevant sources (e.g. endpoint security, SaaS, production logs)
Establish and maintain security event monitoring with multiple steps of severity
Review security events to determine severity and follow up actions
Cybersecurity Compliance
ISO27001 - Focus for 2023 is GAP analysis and bringing NC on par with ISO27001 during the year, preparing for ISO certification
Work with security risk evaluation, documentation and remediation according to existing risk management system.
Incl. TIR57 - Security risk management for medical devices
Cybersecurity support to employees
Response to security events reported by employees as well as slack response to questions.
Work together with IT admin on ensuring employee compliance of WI03 - Security Controls
Follow-up on security events for SaaS. E.g. password quality in Lastpass, various events from Gsuite
Security Training for employees
Prepare and hold relevant cybersecurity training for employees
IT-admin
Manage employee accounts (create accounts, set proper access level, verify compliance with security policies etc.)
During periods of high demand, e.g. during hardware trials, you may be asked to assist with things like technical onboarding for trial participants which requires being in the Stockholm office
Requirements
Strong understanding of the field of cybersecurity
Previous experience in working with technical implementation of cybersecurity initiatives (SIEM, log aggregation, alerting)
Previous experience in working with cybersecurity compliance such as for example ISO27001
As a professional you work independently and proactively
Great analytical skills to conduct root cause analysis and similar investigations
Collaborate with R&D teams as well as stakeholders from other teams, such as regulatory