Information Risk and Compliance Officer
We at WeQuel are now looking for an Information Risk and Compliance Officer in Södertälje, where you will become an important part of the Production & Logistics organisation with a focus on information security governance, risk management and compliance. In the role you act as Information Security Officer, combining strategic and operational security governance with risk management, compliance and structured documentation activities. You contribute to strengthening security processes, supporting risk assessments and ensuring that procedures, guidelines and documentation are clear, accurate and aligned with security requirements and the client's Information Security Management System (ISMS).
As a consultant with us, you get the opportunity to work with one of our clients – leading companies within manufacturing, production and logistics – where you contribute to strengthening security processes, implementing structured ways of working and creating sustainable, compliant solutions.
Your responsibilities
Governance and continuous improvement of the ISMS within Production & LogisticsSupport and execution of IRAM assessments and related follow-up activitiesContribution to information security governance, processes and coordination activitiesPreparation and maintenance of security-related documentation, reports and presentationsReview, rewriting and improvement of shopfloor IT procedures and guidelinesCollaboration with stakeholders across Production Units (PRUs), P&L IT (IN), Maintenance and LogisticsLeading and coordinating the network of Local Information Security Officers (LISOs)Support to stakeholders in understanding and addressing information security and compliance requirementsAssessment of the implications of the Cyber Resilience Act (CRA) for Production & LogisticsEnsuring structured, consistent documentation and governance activities aligned with the ISMS
You work in close collaboration with the Cybersecurity Manager and a broad range of stakeholders, in an environment where you independently drive your activities forward while coordinating across multiple technical and operational interfaces within the organisation.
Requirements
Experience within information security, cybersecurity support, risk management or compliance-related activitiesExperience of information security governance, risk and compliance workExperience of supporting or implementing structured security processes and ways of workingExperience of conducting or supporting risk assessments and follow-up activitiesExperience of supporting governance processes, documentation activities or coordination of security-related workRelevant academic degree or equivalent professional experience within information security, cybersecurity, risk management, compliance or a related fieldFluent Swedish and English, both spoken and writtenStrong ability to produce professional documentation and deliverables in EnglishStrong documentation and analytical skills, with the ability to structure complex information clearlyAbility to develop, review and improve security-related procedures, guidelines and documentationAbility to translate complex security and compliance requirements into clear, practical documentationAbility to coordinate activities across multiple stakeholders, functions and organisational areasStrong stakeholder management and communication skills, towards both technical and operational stakeholdersStructured, proactive and solution-oriented, with a high focus on quality and accuracyComfortable taking ownership and working across multiple parallel activities
Meriting
ISO 27000 certification and/or practical experience of ISO 27001 frameworksKnowledge of the Cyber Resilience Act (CRA) and NIS2Experience of Cybersecurity Management Systems (CSMS)Experience from industrial, production or manufacturing environmentsExperience of IT/OT environments
Who you are
You are a structured and detail-oriented information security professional with strong analytical skills and a high focus on quality. You take a proactive and solution-oriented approach and are comfortable taking ownership of your activities while collaborating closely with stakeholders across different functions and areas of expertise. You communicate clearly with both technical and operational stakeholders and can translate complex information, security requirements and governance needs into structured and understandable documentation.
Assignment details
Location: Södertälje, SwedenStart – End date: 2026-09-14 – 2027-03-31 (September 2026 – March 2027)Workload: 100% (full-time)Remote: 100% ONSITEInterview format: Remote / Teams interviewLanguage: Fluent Swedish and English, both spoken and written
We offer
At WeQuel you become part of a consultant team that values people first – we believe success is created through commitment, collaboration and development. We offer a flat organisation with short decision paths, a strong sense of community and the opportunity to influence your own development.
