IT Security & Risk Officer
Wroclaw, PL, 51-502
Transport is at the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with next-gen technologies and the sharpest collaborative teams, then we could be a perfect match.
Long Description
Enterprise Cybersecurity secures the IT journey for Volvo Group by working with Business Areas, Truck Divisions, and Group Functions in a global environment.
As IT Security & Risk Officer - Associate, you will help shape how we secure IT assets. You will advise Group Digital & IT on applying security requirements and architecture principles in solution designs, identify weaknesses, and propose mitigations. The role also includes awareness and education, working with developers, architects, and DevOps teams to build effective security measures, policies, procedures, and solutions.
Key responsibilities
- Drive strategic and tactical IT security direction.
- Assess risks, identify vulnerabilities, evaluate impact, and recommend mitigations.
- Advise on solution design and review solution blueprints.
- Develop, update, and enforce security policies, procedures, and guidelines in line with industry and regulatory requirements.
- Perform gap analyses against frameworks such as ISO, ISF, CSA [TS1.1], NIST, etc.
- Identify, assess, and implement IT/OT security controls across projects and organizations.
- Collaborate with stakeholders in a multicultural environment.
- Act as a trusted advisor on security best practices and integrate security into design and implementation.
- Monitor framework effectiveness and recommend improvements based on emerging threats.
- Ensure adherence to information protection laws and regulations.
- Review the coverage and effectiveness of IT and OT security controls.
- Stay current on IT security trends and advancements.
Your background
You have broad IT Security experience and understand the challenges facing large enterprises such as Volvo Group. Strong stakeholder management and the ability to build trusted relationships internally and externally are essential.
You have
- Strong critical thinking and analytical skills.
- Experience driving change and influencing others.
- Excellent communication and presentation skills.
- Adaptability and resilience in a changing security landscape.
- Strong listening, collaboration, and teamwork skills.
- Curiosity and enthusiasm for innovation and continuous improvement.
Hard skills and knowledge
- Knowledge of cybersecurity frameworks such as ISF, CSA, NIST, SCF, ISO 27x, OWASP, etc.
- Experience with Microsoft Azure services and cloud-based applications.
- Understanding of least privilege and Zero Trust in distributed IT/OT environments.
- Knowledge of on-premise and cloud network security technologies such as segmentation, firewalling, load balancing, and VPN.
- Understanding of on-premises, multicloud, and hybrid interconnecting solutions.
- Experience with AppSec and SDLC practices such as DevSecOps, SAST, SCA, DAST, and container security.
- Knowledge of cloud security, container security, API security, Infrastructure as Code, and IAM technologies such as OAuth2/OIDC.
- Security certification such as ISC2 CC/SSCP, CompTIA Security+, Microsoft Azure AZ-900/AZ-500, or similar.
Advantageous skills
- Practical experience with threat modelling using standards such as STRIDE, MITRE, OWASP, etc.
- Familiarity with AI development frameworks, model providers, open-source models, or model evaluation platforms.
Minimum education and experience
Bachelor’s or master’s degree in cybersecurity, IT, Information Systems, Engineering, or equivalent experience.
3+ years of experience in IT Operations, Security, Cloud, or Architecture.
Dear Candidate, we would like to kindly inform you that the Volvo Group companies in Poland have in place the "Internal Reporting Procedure". If you need more information, please contact us at the email address recruitment.poland@volvo.com.
We believe great results come from working together. At Volvo Group, our teams collaborate mainly from our sites, where innovation, learning, and teamwork thrive. Flexibility is possible and discussed with the manager based on business and role needs.
We value your data privacy and therefore do not accept applications via mail.
Volvo Group Digital Technology & Operations (DTO) is a new division established to integrate the capabilities of VG Digital & IT and VG Connected Solutions to accelerate the digital transformation in Volvo Group. The organizational set up is structured around domains, digital products with functions for digital excellence to deliver outstanding customer experience.
Joining the new DTO division means being part of a fast-moving digital product-oriented organization where teams truly own what they build from idea to delivery. In DTO, we work in agile, cross-functional teams, mastering the latest technology, and creating outstanding digital experiences that make a real difference for our colleagues and Volvo Group customers around the world. We put people first and build our culture on trust, passion, customer success, change, and performance. If you want to grow, collaborate across functions and entities, and help shape the future of digital products within Volvo Group, DTO is a great place to be.