Information Risk and Compliance Officer
NewBe an early applicantemagine is looking for an experienced Information Risk and Compliance Officer to act as an Information Security Officer within Production & Logistics for our amazing client in the automotive industry.
Start – End Date: September 2026 – March 2027
Allocation: 100% (full-time)
Location: Södertälje, Stockholm
Interview Format: Remote / Teams interview
Language: Fluent Swedish and English required, both spoken and written
Description
We are looking for an experienced Information Risk and Compliance Officer to act as an Information Security Officer within Production & Logistics.
The assignment combines strategic and operational information security governance with risk management, compliance, and structured documentation activities. You will contribute to strengthening security processes, supporting risk assessments, and ensuring that procedures, guidelines, and documentation are clear, accurate, and aligned with applicable security requirements and the organization's Information Security Management System (ISMS).
You will work in close collaboration with the Cybersecurity Manager and a broad range of stakeholders across Production & Logistics, including Production Units, IT, Maintenance, and Logistics.
The role requires a structured and proactive approach, with the ability to independently drive activities while coordinating across multiple technical and operational stakeholders.
Key Responsibilities
Govern and support the continuous improvement and implementation of the Information Security Management System (ISMS) within Production & Logistics.
Support and perform IRAM assessments and related follow-up activities.
Contribute to information security governance, processes, and coordination activities.
Prepare and maintain security-related documentation, reports, presentations, and other supporting materials.
Review, rewrite, and improve shopfloor IT procedures and guidelines to ensure clarity, accuracy, and compliance with relevant security requirements.
Collaborate with stakeholders across Production Units, IT, Maintenance, and Logistics.
Lead and coordinate the network of Local Information Security Officers (LISOs).
Support stakeholders in understanding and addressing information security and compliance requirements.
Assist in assessing and understanding the implications of the Cyber Resilience Act (CRA) for Production & Logistics.
Ensure that security-related documentation and governance activities are structured, consistent, and aligned with the ISMS.
Education & Technical Skills
Relevant academic degree or equivalent professional experience within information security, cybersecurity, risk management, compliance, or a related field.
Experience working with information security, cybersecurity support, risk management, or compliance-related activities.
Experience supporting governance processes, documentation activities, or coordination of security-related work.
Strong documentation and analytical skills with the ability to structure complex information clearly.
Ability to work effectively with both technical and operational stakeholders.
Fluent Swedish and English, both spoken and written.
Strong ability to produce professional documentation and deliverables in English.
Experience & Skills
Experience working with information security governance, risk, and compliance activities.
Experience supporting or implementing structured security processes and ways of working.
Experience conducting or supporting risk assessments and associated follow-up activities.
Strong ability to develop, review, and improve security-related procedures, guidelines, and documentation.
Ability to coordinate activities across multiple stakeholders, functions, and organizational areas.
Strong stakeholder management and communication skills.
Ability to translate complex security and compliance requirements into clear and practical documentation.
Ability to independently structure, prioritize, and drive assigned activities forward.
Meriting Experience
ISO 27000 certification and/or practical experience working with ISO 27001 frameworks.
Knowledge of the Cyber Resilience Act (CRA) and NIS2.
Experience working with Cybersecurity Management Systems (CSMS).
Experience from industrial, production, or manufacturing environments.
Experience working with IT/OT environments.