CISO / Information Security Lead
Assignment Description We are looking for an experienced freelance Fractional CISO / Information Security Lead for a private client with international operations. The engagement will initially be part-time, with the scope potentially increasing over time. The consultant will be accountable for the organisation’s information security agenda, covering both strategic advice and hands-on implementation and follow-up. The work includes overseeing security monitoring, vulnerability management and patch management, as well as reviewing the security of new systems, solutions and suppliers. Guidance will also be provided in areas including IAM, security architecture, data protection and encryption. Another central part of the assignment is to develop the information security strategy based on the organisation’s risk appetite and lead its preparations for NIS2 and continued compliance. The consultant will maintain the enterprise risk register, associated risk treatment plans and management reporting, coordinate security audits conducted internally and externally, and manage security risks connected to suppliers and other third parties. The role also covers the development and maintenance of incident response, business continuity and disaster recovery plans. In addition, the consultant will create security awareness activities, contribute to a stronger security culture, support GDPR compliance and participate in developing AI security policies and preparations relating to the EU AI Act. The assignment requires the ability to operate independently, explain security risks and recommendations to management, and convert regulatory requirements into practical initiatives. Required Qualifications: A broad technical understanding covering IAM, security architecture, cloud security, infrastructure and data protection. Experience of assessing supplier security and managing risks connected to third parties. Previous experience working as a CISO, Information Security Lead, Security Manager or in a comparable role. Hands-on experience of implementing or operationalising NIS2. Enterprise risk management experience, including maintaining security risk registers. Experience covering incident response, business continuity and disaster recovery. It is considered advantageous if you have experience of reporting directly to a board, practical experience of the EU AI Act or experience gained within international organisations.
Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.
Visa jobbet och ansökUrsprunglig annons: upgraded.se