Information Risk and Compliance Officer

WeQuelSwedenOn-siteFull-timeListed 1 day ago

Apply now

About this role

We at WeQuel are now looking for an experienced Information Risk and Compliance Officer in Södertälje. You will act as Information Security Officer within the client's Production & Logistics, with a focus on information security governance, risk management and compliance. The assignment combines strategic and operational information security governance with risk management, compliance and structured documentation. You will help strengthen security processes and support risk assessments. You will also make sure procedures, guidelines and documentation are clear, accurate and aligned with security requirements and the client's Information Security Management System (ISMS). You will work closely with the Cybersecurity Manager and a broad range of stakeholders across Production & Logistics, including Production Units, P&L IT, Maintenance and Logistics.

As a consultant with us, you will have the opportunity to work with one of our clients, who are leading companies within the automotive, manufacturing and industrial sectors. There you will help strengthen information security, improve governance and compliance processes, and create sustainable, secure ways of working.

Your responsibilities:

- Governance and continuous improvement of the ISMS within Production & Logistics
- Implementation of the ISMS within Production & Logistics
- IRAM assessments and follow-up
- Information security governance, processes and coordination
- Preparation and maintenance of security documentation, reports, presentations and supporting materials
- Review, rewriting and improvement of shopfloor IT procedures and guidelines for clarity, accuracy and compliance
- Collaboration with Production Units (PRUs), P&L IT (IN), Maintenance and Logistics
- Leadership and coordination of the Local Information Security Officers (LISOs) network
- Stakeholder support on information security and compliance requirements
- Assessment of Cyber Resilience Act (CRA) implications for Production & Logistics
- Structured, consistent security documentation and governance, aligned with the ISMS

The role calls for a structured, proactive approach. You will drive activities independently while coordinating across multiple technical and operational stakeholders.

Requirements:

- Experience in information security, cybersecurity support, risk management or compliance
- Experience in information security governance, risk and compliance (GRC)
- Experience supporting governance processes, documentation or coordination of security work
- Experience supporting or implementing structured security processes and ways of working
- Experience conducting or supporting risk assessments and follow-up
- Relevant academic degree, or equivalent professional experience, in information security, cybersecurity, risk management, compliance or a related field
- Fluent Swedish and English, spoken and written
- Strong ability to produce professional documentation and deliverables in English
- Strong documentation and analytical skills, with the ability to structure complex information clearly
- Strong ability to develop, review and improve security procedures, guidelines and documentation
- Able to translate complex security and compliance requirements into clear, practical documentation
- Able to work effectively with technical and operational stakeholders
- Able to coordinate activities across multiple stakeholders, functions and organisational areas
- Strong stakeholder management and communication skills
- Able to structure, prioritise and drive assigned activities independently
- Structured and detail-oriented, with strong analytical skills and a high focus on quality
- Proactive and solution-oriented; comfortable owning your activities while collaborating across functions and areas of expertise
- Communicates clearly with technical and operational stakeholders
- Able to turn complex information, security requirements and governance needs into structured, understandable documentation
- Comfortable handling multiple parallel activities with high accuracy and quality

Meriting:

- ISO 27000 certification and/or hands-on experience with ISO 27001 frameworks
- Knowledge of the Cyber Resilience Act (CRA) and NIS2
- Experience with Cybersecurity Management Systems (CSMS)
- Experience from industrial, production or manufacturing environments
- Experience with IT/OT environments

Assignment details

- Start date: September 2026
- End date: March 2027
- Location: Södertälje, Sweden
- Workload: 100% (full-time)
- Remote: 100% ONSITE
- Interview format: Remote / Teams interview

We offer

At WeQuel, you become part of a consulting team that values people first. We believe success comes from engagement, collaboration and development. We offer a flat organisation with short decision paths, a strong sense of community and the opportunity to shape your own development.