Senior Cybersecurity GRC Specialist shaping Orion Pharma's cybersecurity governance, risk management, and compliance. Engaging with teams to enhance security posture and meet regulatory standards.
Responsibilities
Develop and operate Orion’s cybersecurity risk management process, including risk identification, assessment, treatment, management reporting, metrics, and effectiveness monitoring
Manage and continuously improve the security exception process, including reporting
Drive compliance activities against relevant cybersecurity frameworks, standards, and regulatory requirements
Operate and further develop the Information Security Management System (ISMS)
Maintain, update, and improve cybersecurity policies, instructions, and guidelines
Coordinate and support security assessments, audits, and control reviews
Provide GRC guidance to internal stakeholders to support informed, risk based decision making
Develop and support cybersecurity training and awareness
Requirements
Extensive experience in cybersecurity and strong knowledge of security frameworks (e.g. ISO/IEC 27001, NIST)
Proven experience in a cybersecurity GRC role
Relevant cybersecurity certifications (e.g. ISO 27001 Lead Implementer, CISM, CISSP)
Strong hands-on experience in cybersecurity risk management
A strong analytical mindset with a proactive approach to security challenges
Fluency in English; Finnish is considered an advantage
Excellent collaboration and communication skills, a positive can-do attitude, and a strong sense of responsibility
Benefits
Our culture of friendliness, respect, mutual appreciation and diversity creates a safe working environment where you can strive for excellence.
We offer a wealth of career paths and development opportunities that support the development of innovative solutions and improving the quality of life.
Business Development Representative at xorlab driving proactive lead generation in cybersecurity market. Collaborating closely with sales and marketing team to optimize lead development processes.
Cyber Security Architect responsible for IT security compliance and cyber - risk management at a Swiss utility firm. Engaging with cross - functional teams to implement 'Secure - by - design' strategies.
Information Security Officer ensuring cybersecurity at an IT service provider for food and beverage sector. Developing strategies and overseeing security protocols while reporting to management.
Head of Information Security at Aurora shaping security strategy and governance in a software - focused global business. Leading security efforts to ensure resilience and compliance across operations.
Senior Security Engineer specializing in penetration testing and security strategies for fintech. Collaborating with teams to enhance security for AI applications and financial systems.
Principal Cyber Security Engineer for Identity Access Management at MSK managing identity solutions and advanced identity platforms. Partnering with stakeholders to align identity strategy and lead IAM initiatives.
Join The Missing Link as a Security Engineer, leveraging 3 - 4 years of IT Security experience. Lead projects in a collaborative environment with a focus on innovation and impact.
Engineer in Health, Safety and Environment for ArianeGroup focusing on industrial risk management. Involves audits, assessments, and safety training participation.
Senior Product Security Engineer at Red Hat focusing on security and compliance for digital sovereign products while collaborating across global teams and enhancing automation.
Security Engineer safeguarding K - 12 student data in several locations for EduTech startup. Designing secure software systems and ensuring data protection to comply with privacy standards.