← Zurück zur Liste
Stelle

Cybersecurity Inspector

Sonstige • Remote • Vollzeit Schweden Schweden

Läkemedelsverket (the Swedish Medical Products Agency), designated as the supervisory authority under the NIS2 directive and the cybersecurity law, is looking for a cybersecurity inspector to supervise medical device manufacturers and other actors.

Responsibilities

  • Be part of a team building up and conducting supervision under the cybersecurity law, mainly within medical technology but also in the medicines area
  • Answer incoming questions and collaborate with other agencies
  • Carry out cybersecurity supervision of manufacturers by requesting and reviewing documentation on their IT environments, process environments, cyber-physical systems and management systems
  • Conduct on-site inspections at manufacturers and other actors, involving some travel
  • Make well-founded risk assessments and formulate conclusions from a regulatory perspective

Requirements

  • Several years of experience in information and IT security work, planning and conducting structured reviews
  • Ability to make independent, well-founded and proportional assessments based on requirements and risk
  • Technical understanding of cybersecurity, network architectures, identity and access management, cryptography and communication
  • Experience conducting risk analyses and assessing cybersecurity measures
  • Communication skills: able to explain complex cybersecurity issues to both technical and non-technical audiences, fluent in Swedish and English, spoken and written

Nice to have

  • Experience independently conducting audits or reviews under established frameworks such as the ISO/IEC 27000 series, CIS, SOC2, PCI DSS, DORA, IEC-62443, the Protective Security Act or NIST CSF
  • Experience in supervision, audit or other controlling activity in the public or private sector, or operational experience implementing and managing security measures in complex technical environments
  • Experience with incident handling, continuity planning and recovery, and with implementing ISO 27001, NIST CSF or PCI DSS
  • Knowledge of the cybersecurity law's requirements on security measures, or experience from critical infrastructure or another regulated sector
  • Certifications such as 27001 Lead Auditor, QSA, CISA or similar
  • Knowledge of medical device regulations

Soft skills

High integrityGood analytical ability

About the company

Läkemedelsverket is the Swedish Medical Products Agency, working for the health of people and animals. Its medical technology area has close to 80 employees and carries out supervision, supports access to medical devices, provides guidance and develops regulations.

Languages: Svéd: folyékony, Angol: folyékony

Ähnliche Stellen