Strength. Care. Growth
You will know we are the right place for you, if you are driven by:
- Opportunities to learn and build your career.
- Meaningful work in a stable and fast-paced company.
- Diversity of people, projects, and platforms.
- A supportive, fun, and inspiring place to work.
This job can be performed by all countries within our A1 footprint.
Role Overview:
Conduct security assurance and compliance assessments against internal policies, ISO 27001/27002, 27017, 27701 standards, and regulatory frameworks such as NIS2, identifying control gaps and driving remediation efforts to strengthen cybersecurity governance, control effectiveness, and organizational security maturity across the A1 Group.
Role Insightst:
- Evaluate and assess the effectiveness of cyber security controls against internal policies, ISO 27001/27002, 27017, 27701 standards, and regulatory frameworks such as NIS2.
- Perform security assurance reviews, compliance assessments, and gap evaluations across systems, processes, and business areas.
- Identify control gaps, weaknesses, and non-conformities, providing clear and actionable recommendations to improve security maturity.
- Collaborate with system owners, security teams, and business stakeholders to define remediation plans and drive closure of identified risks.
- Support internal and external audits, regulatory inspections, and assurance activities by providing documentation, evidence, and expert guidance.
- Monitor remediation progress and contribute to assurance reporting, dashboards, metrics.
- Support the continuous development and improvement of assurance methodologies, security control frameworks, and assessment approaches.
- Contribute to knowledge sharing, collaboration, and the development of a strong security culture across the A1 Group.
What Makes You Unique:
- Bachelor’s degree in Information Security, Computer Science, Information Technology, Business Informatics, Organizational Sciences, or a related field.
- 4+ years of experience in cybersecurity, security compliance, IT audit, risk management, security consulting, assurance, or a similar area.
- Strong understanding of security topics, ISO 27001/27002, other ISO standards and information security control frameworks.
- Knowledge of regulatory requirements such as NIS2, DORA, GDPR, and other relevant cybersecurity regulations.
- Experience with security assessments, audit findings management, and remediation tracking.
- Good understanding of security governance models, and control effectiveness evaluation.
- Good analytical, communication, documentation, and stakeholder management skills.
- Fluent in English.
Job code:AFU020P209
Job classification: P2 - 9, KV4, PT 3/2