Senior Information Security Officer

  • Full-time

Company Description

Help shape information security across a large European organization 

Heimstaden Bostad is a pan-European real estate investor, manager and operator. We manage approximately 155,500 homes across nine countries, representing a property value of around EUR 30 billion. 

Our business is supported by close to 2,000 people across Czechia, Denmark, Finland, Germany, the Netherlands, Norway, Poland, Sweden and the United Kingdom. 

Operating at this scale creates a broad and evolving information security landscape. We are strengthening our Information Security function with a Senior Information Security Officer who can help turn security requirements into practical controls, clear decisions and measurable improvements across the organization. 

Job Description

The role 

You will report to and work closely with the Director for Global IT Services & Cybersecurity (CISO) as part of the Information Security team, while engaging with senior leaders, technology teams and business functions across Europe. 

This is a senior, hands-on role in a function that is still being established. You will improve its structure and ways of working while delivering and coordinating governance, risk and assurance activities. You will influence how information security is embedded into business processes, technology decisions and supplier relationships. 

Your responsibilities 

Working closely with the CISO, you will: 

  • Develop and maintain our information security governance model, control framework, policies, standards and practical guidance. 
  • Coordinate the information security risk lifecycle, including assessments, treatment plans, risk acceptance, exceptions, follow-up and reporting. 
  • Lead security assessments of suppliers and services by reviewing evidence, identifying material risks, documenting security decisions and tracking remediation. 
  • Plan and perform security assurance reviews to evaluate whether controls are appropriately designed, implemented and operating effectively. 
  • Advise management and employees on information security risks, requirements and proportionate safeguards. 
  • Define and follow up security requirements in areas such as identity and privileged access, cloud and SaaS services, sensitive information and critical suppliers. 
  • Develop security awareness activities and practical guidance, and measure whether they produce the intended results. 
  • Establish meaningful security metrics and prepare clear reporting and decision support for the CISO and senior management. 
  • Work with IT, Compliance & Legal, Procurement and business owners to ensure that security requirements and decisions are understood, and that agreed actions have clear owners and are followed through. 
  • Ensure that security plans, decisions and supporting evidence are clearly documented, and that agreed actions are tracked to completion. 

Technical teams and business owners remain responsible for implementing and operating their controls. Your role is to define security requirements, provide informed professional challenge and assurance, and ensure that risks and actions are brought to the appropriate accountable owner for decision.

Qualifications

About you 

Skills and experience can be developed in different ways, and we do not expect one candidate to match every point. You are likely to succeed if you bring: 

  • A genuine enthusiasm for information security, with the drive to keep learning, stay current with the evolving threat and regulatory landscape, and turn new knowledge into practical improvements. 
  • Substantial hands-on experience with information security, GRC, security assurance or risk management in a large or complex organization, including independently leading complex assignments through to completion. 
  • Practical knowledge of the ISO 27000 family and frameworks such as the NIST Cybersecurity Framework, with experience developing workable policies, standards, controls and guidance. 
  • Experience with security risk assessments, supplier security, control assurance and remediation follow-up. 
  • Sufficient technical understanding to engage with specialists and the ability connect technical, risk and business perspectives across various cybersecurity domains. 
  • Strong written and verbal communication skills in English. The ability to speak and understand a Scandinavian language is a significant advantage. 
  • Confidence working with senior stakeholders across countries and organizational boundaries, using your professional experience and judgment to advise clearly, challenge constructively and build support for well-informed decisions. 
  • A structured, analytical and pragmatic approach, combined with curiosity and attention to detail. 
  • A self-driven and independent working style, with the ability to structure and deliver complex assignments with limited direction while knowing when to seek input or escalate. 

Relevant education or equivalent practical experience is expected. Certifications such as CISSP, CISM, CRISC or similar are beneficial but not essential. 

Additional Information

What we offer 

  • A visible and influential role helping mature Information Security across a sizeable pan-European organization, with direct engagement with senior leadership. 
  • Collaboration with experienced colleagues and industry experts across several European countries, with good opportunities for professional development. 
  • A collaborative and inclusive working environment that values initiative, innovation and excellence. 
  • A competitive compensation and benefits package. 

Workplace 

This is an office-based position in Copenhagen, Denmark, located next to Copenhagen Central Station. Physical presence is an important part of the role because we believe close in-person collaboration enables better dialogue, faster decisions and stronger shared ownership. 

The role does not require regular travel, although occasional travel may occur. 

If you enjoy broad responsibility and want to turn security requirements into practical and measurable improvements, we would like to hear from you. 

We welcome applications from candidates with different backgrounds and experiences, and we encourage you to apply even if you do not meet every listed qualification. 

Heimstaden does not provide sponsorship for residence or work permits for this position. Applicants must already have the legal right to live and work in Denmark. 

Applications are reviewed on an ongoing basis, and we aim to appoint the right candidate as soon as possible. 

We conduct background checks as part of our recruitment process. If you have any questions regarding this, you are welcome to contact us!

At Heimstaden, we value diversity and believe that different perspectives create better decisions and a stronger work environment.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice