Jobs and Careers
H&

Senior Cyber Security GRC (Governance, Risk and Compliance) Specialists

H&M Group
Swedenfull_timeVerifiedPosted 13 Jun 2024

About the role

<h3>Job Description</h3><p>Cyber Security GRC (Governance, Risk and Compliance) unit plays a crucial role embedding defined standards and regulatory frameworks within information and IT security to H&amp;M Group, as well as ensuring risk supervision and business continuity. This includes e.g. a responsibility for auditing compliance, as well as overseeing the identification, assessment and mitigation of technology and cyber security risks.    </p><p><strong>We work determinedly within the following areas:  </strong></p><p><strong>Governance: </strong>Ability to build a structured way of working with cyber security by aligning processes and functions in order to achieve organizational objectives and improve the security culture.  </p><p><strong>Risk:</strong> Ability to identify, address, assess, mitigate and follow-up on cyber security and technology risks.  </p><p><strong>Compliance:</strong> Ability to meet global and local existing and new laws, standards and other regulatory requirements within cyber security.  </p><p><strong>Resilience:</strong> Ability to continue delivering intended outcomes despite experiencing challenging cyber events.   </p><p>We collaborate closely with other departments within the organization and constantly commit to enhancing our services and processes.     </p><p>Our goal is to have a unified, systematic and risk-based way of working that helps H&amp;M Group to reach a robust and resilient cyber security that comply to all applicable regulations. The benefits include e.g. reduced costs, less duplicate work, greater visibility into risks, increased data accuracy and consistency, and more alignment across stakeholders. </p><p><strong>For the GRC unit, we are looking for four new senior team members with the following focus areas.</strong> In this role, you will report directly to the Unit Manager for Cyber Security GRC. </p><p><strong>Risk Officer: </strong> <br/> Strategically responsible for keeping H&amp;M Group’s Cyber Security Risk Management Framework up to date on a global market, as well as driving the continuous risk work on an enterprise and operational level within BT Cyber Security.   </p><p><strong>Compliance Officer:  </strong><br/> Strategically responsible for keeping H&amp;M Group’s Cyber Security Common Control Framework (CCF) and its related exception and exemption management processes up to date for all applicable markets, as well as strategically designing the annual Audit Plan and Program for H&amp;M Group and our vendors.  </p><p><strong>Resilience Officer: </strong> <br/> Strategically responsible for keeping H&amp;M Group’s Cyber Security Resilience Work up to date for all applicable parts of the organization, including a systematic risk-based approach with Business Continuity, Disaster Recovery and Crisis &amp; Incident Management.   </p><p><strong>GRC Officer:  </strong><br/> Working within all GRC areas, assisting in the day-to-day work as well as with specific improvement initiatives and projects.  </p><p>All four roles are expected to:  </p><ul><li><p>Defining policies, processes and procedures, as well as creating and maintaining instructions, guidelines and templates.  </p></li><li><p>Closely collaborating with internal and external stakeholders within the area of responsibility.  </p></li><li><p>Incessantly looking for opportunities to introduce more effective and efficient controls and ways of working within cyber security. </p></li></ul><h3>Qualifications</h3><p>You must be an expert with 5-10 years of experience within cyber security in general and/or GRC-related work in specific. This includes e.g. having documented knowledge for the focus area that you’re applying to:  </p><p><strong>Risk Officer:  </strong><br/> Implement risk management associated with cyber security, including identification, analyses and mitigation plans on both an enterprise and operational level.  </p><p><strong>Compliance Officer:  </strong><br/> Comply with legal requirements, best practices and standards associated with cyber security, and work with Qualified Security Assessors (QSA) and auditors.  </p><p><strong>Resilience Officer:  </strong><br/> Build a robust and resilient cyber security environment with the help from business continuity and disaster recovery strategies as well as expedient incident and crisis management systematics.  </p><p><strong>GRC Officer:  </strong><br/> A general experience from GRC-related work tasks.   </p><p><br/> <strong>To succeed in the role, we see that you have:  </strong></p><ul><li><p>Strong experience in helping a global organization to adopt a robust, resilient and maintainable approach to modern tech or cyber security.   </p></li><li><p>Very high knowledge of legal regulations, international standards and best practice within cyber security risk management, such as ISO 27000/22301/31000, NIST 800, PCI-DSS, GDPR, NIS2, DORA.  </p></li><li><p>Strong experience of implementing and operating cyber security focused controls.  </

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

H&M Group

View company profile →