About this role
Cyber Instincts is a Gothenburg-based cybersecurity consultancy helping organizations build digital resilience across IT, OT, and automotive environments. We work with clients across automotive, manufacturing, banking and finance, retail, and healthcare - including public sector organizations navigating new cybersecurity legislation. We're building our senior bench for governance, risk, and compliance engagements centered on Sweden's Cybersäkerhetslag (CSL) and NIS2, with a particular focus on clients in municipal, regional, and public administration contexts.
What the work looks like:
- Conducting gap analyses between clients' current practices and CSL/NIS2 requirements
- Translating legislation into concrete, actionable roadmaps - not theoretical reports
- Supporting governance, risk management, and incident reporting processes required under CSL
- Assessing third-party and supply chain risk, including vendor and subcontractor dependencies
- Integrating cybersecurity compliance work with existing information security, data protection, and continuity functions
- Supporting procurement processes where cybersecurity requirements need to be defined or clarified in contracts and agreements
- Presenting findings and recommendations to steering groups, management, and non-technical stakeholders
What you'll bring:
- 8+ years of experience in governance, risk & compliance, information security, or IT risk management
- Documented, current knowledge of NIS2 and Swedish cybersecurity legislation (CSL)
- Solid grounding in ISO 27001, NIST, or COBIT frameworks
- Proven reference engagements with Swedish municipalities, regions, or government agencies - this is essential, not preferred
- Experience conducting GAP and risk analyses and turning them into concrete, auditable requirements
- Fluent Swedish and English, spoken and written - you'll be presenting directly to Swedish public sector stakeholders
A plus, not a requirement:
- Experience with public procurement (LOU) or framework agreements
- Background in critical infrastructure or samhällsviktig verksamhet
- Incident reporting process design experience
This is a Sweden-based, on-site role with placements at client sites across the country. Applicants must currently reside in Sweden. You'll be employed or engaged on a freelance basis and placed directly with our clients for the duration of each engagement.
