
Information & Cyber Security Architect
- Stockholm Vårgårda, Västra Götaland
- Permanent
- Heltid
- Own and evolve the target state security architecture for manufacturing environments (OT/IoT/edge/cloud).
- Translate strategic security goals into actionable architecture blueprints, capabilities, and reference models.
- Coordinate across manufacturing, operations, infrastructure, and security to ensure aligned, scalable implementations.
- Support the integration of security into design, engineering, and deployment of lifecycles of manufacturing systems.
- Work closely with security solution architects and system owners to ensure the effective adoption of secure designs.
- Provide expert input to threat modeling, risk assessments, and architecture reviews specific to manufacturing systems.
- Champion the development and adoption of reusable patterns, standards, and frameworks across global manufacturing sites.
- Lead capability maturity assessments, define improvement roadmaps, and track progress across divisions.
- Act as the security architecture representative in global forums related to smart manufacturing, product development and digital engineering.
- Communicate complex technical concepts in business-relevant language to drive executive buy-in and adoption.
- Security Governance & Architecture Lifecycle - Deep understanding of architecture governance, capability modeling, and lifecycle integration across IT, OT, and Edge.
- Cybersecurity Management Systems - Familiarity with integrated management systems (e.g., ISO/IEC 27001, IEC 62443-2-1) and their application in industrial environments.
- Cybersecurity Frameworks & Standards - Working knowledge of NIST CSF, ISA/IEC 62443, ISO/SAE 21434, SCF, and Zero Trust principles.
- Risk Modeling and Evaluation - Application of both qualitative and quantitative risk models to inform architecture choices. Strong grasp of risk acceptance, residual risk handling, and communication of trade-offs.
- Regulatory and Compliance Landscape - Awareness of current and upcoming legislation relevant to industrial ecosystems: GDPR, NIS2, CRA, TISAX, ISO/SAE 21434.
- Technical Domains - Broad technical expertise in IT infrastructure security, cloud platforms (especially edge deployments), OT security, embedded/IoT systems, and data protection.
- Business & Organizational Awareness - Ability to map business models, stakeholder roles, and organizational dynamics to security architecture needs.
- Trends and Adaptation - Analyze emerging threats, regulatory trends, and industry innovation to continuously refine architecture posture.
- Security Architecture Development
- Capability & Service Definition
- Architecture & Solution Assessment
- Risk Methodology Application
- Cross-Functional Facilitation
- Training & Enablement
- Influence & Negotiation
- Change Leadership
- Integration with ERM & Business Continuity
- Interpretation of Complex Requirements
- Critical & Strategic Thinking
- Stakeholder Management
- Strategic Communication
- Cultural Leadership
- Adaptability and Innovation
- Integration Across Domains