Global Information Security Director Embla Medical

ossur iceland ehf

📍 reykjavik iceland eindhoven netherlands iceland🕐 2mo ago🔗 workday

Job Description

**Global Information Security Director** **| Embla Medical**  ============================================================= Join us in our mission to improve people’s mobility.  **Embla Medical seeks a Global Director of Information Security to lead the Company’s global information security framework and strategy.**  This role is responsible for ensuring organizational compliance with international standards (such as ISO 27001, ISO 27701), regulatory requirements (including HIPAA, GDPR, NIS2), and internal governance frameworks. The Director of Information Security coordinates efforts among security, compliance, and data protection teams to promote security by design and operational resilience. The position involves protecting the organization's information assets, developing security strategies, and maintaining adherence to relevant regulations.   This role demands a blend of technical proficiency, strategic vision, and proven leadership to effectively mitigate security risks and safeguard sensitive information. The ideal candidate will possess extensive experience in senior information security leadership positions, preferably within regulated or healthcare sectors. Relevant expertise includes conducting internal audits, performing risk assessments, and developing robust policies. In-depth knowledge of ISO 27001/27701, GDPR, HIPAA, and other pertinent global compliance standards is essential, along with exceptional leadership, communication, and stakeholder management abilities.   This role will report to the VP of Corporate Governance, and work within a team of leaders and experts committed to building an exceptional future for Embla Medical.  We offer flexible working arrangements, with headquarters in Reykjavík. Some international travel might be required.     **The position can be located either in Reykjavík or Eindhoven.**  **Key Responsibilities**  * **Strategic Planning:** Formulate and execute a comprehensive global information security strategy that aligns with the organization’s business goals and risk appetite. Responsibilities include identifying key security initiatives and establishing a clear implementation roadmap.   * **Risk Management**: Conduct regular risk assessments to identify potential security threats and vulnerabilities. Develop and implement risk mitigation strategies, including security controls and policies.    * **Policy Development**: Establish and enforce information security policies, standards, and procedures. Ensure that these align with industry best practices and regulatory requirements.   * **Incident Response**: Oversee incident response activities in the event of a security breach, ensuring that the organization is prepared to respond effectively.   * **Compliance**: Stay updated on relevant laws, regulations, and industry standards related to information security, ensuring that the organization's practices comply with these requirements.   * **Collaborate** closely with IT and business leaders within the organization’s business areas and functions.    **Qualifications**  * Relevant university degree in Computer Science, Cybersecurity or related/relevant fields, and/or 10+ years' experience within the field of information security. This includes experience in risk assessment, security architecture, and security operations. At least 5 years experience in a leadership role is required.  * Recognized certifications such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) are preferred.   * Experience of project/program management planning.   * Experience of collaborating with business stakeholders across various levels and functions of an organization.   * Professional communication skills, with a high level of both written and spoken English.   * Experience of working within a global company is highly preferred.   We encourage people to apply for the position regardless of gender or origin. Application period ends on August 3rd, 2026.  ///  Viltu taka þátt í verkefnum með það að markmiði að bæta hreyfanleika fólks?   **Embla Medical leitar að Global Director of Information Security til að leiða alþjóðlegt svið upplýsingaöryggis og vinna að stefnu fyrirtækisins í upplýsinga- og netöryggismálum.**   Director of Information Security ber ábyrgð á að fyrirtækið starfi í samræmi við alþjóðlega staðla (t.d. ISO 27001, ISO 27701), reglugerðir (t.d. HIPAA, GDPR, NIS2) og innri reglur og ferla. Viðkomandi vinnur m.a. með netöryggis-, regluvörslu\- og persónuverndarteymum að því að efla öryggi og viðnámsþrótt innviða og rekstrarþol fyrirtækisins. Markmiðið er að vernda þær upplýsingar sem fyrirtækið á, býr yfir eða ber ábyrgð á, þróa öryggisstefnur og tryggja fylgni við lög og reglur á sviðinu.   Við leitum að aðila sem býr yfir tæknilegum skilningi, stefnumótandi framtíðarsýn og starfsreynslu sem nýtist til að draga úr áhættu tengdri upplýsingaöryggi á áhrifaríkan hátt. Viðkomandi þarf að hafa víðtæka reynslu á sviði upplýsingaöryggis, helst innan eftirlitsskyldra geira eða heilbrigðisgeirans. Til dæmis má nefna reynslu af innri endurskoðun, áhættugreiningu og stefnumótun á sviði öryggismála. Góð þekking á ISO 27001/27701, GDPR, HIPAA og öðrum viðeigandi alþjóðlegum eftirlitsstöðlum er nauðsynleg, ásamt framúrskarandi leiðtoga- og samskiptafærni.   Director of Information Security heyrir undir VP of Corporate Governance og mun starfa innan öflugs teymis leiðtoga og sérfræðinga sem saman vinna af krafti að framtíðarsýn Embla Medical.   Við bjóðum upp á sveigjanlegt vinnufyrirkomulag og umhverfi, með höfuðstöðvar í Reykjavík. Það má búast við einhverjum alþjóðlegum ferðalögum.   **Um er að ræða starf sem er staðsett í Reykjavík eða Eindhoven.**   **Helstu ábyrgðarsvið**   • **Stefnumótun:** Að móta, stýra og framkvæma alþjóðlega stefnu fyrirtækisins á sviði upplýsingaöryggis sem er í samræmi við viðskiptamarkmið og áhættuvilja fyrirtækisins. Þetta felur meðal annars í sér að skilgreina lykilaðgerðir á sviði upplýsingaöryggis og gera skýra innleiðingaráætlun.   • **Áhættustjórnun:** Að framkvæma reglulega áhættumat til að bera kennsl á hugsanlegar öryggisógnir og veikleika. Að þróa, uppfæra og innleiða áhættuvarna\- og viðbragðsáætlanir, þar á meðal öryggisráðstafanir og ferla.   • **Stefna um net- og upplýsingaöryggi:** Að koma á og framfylgja upplýsingaöryggisstefnu, stöðlum og verklagsreglum í samræmi við viðurkennda bestu framkvæmd á sviðinu og gildandi reglur.   • **Viðbrögð við atvikum**: Að stýra viðbrögðum við öryggisbrestum og tryggja að fyrirtækið sé undir það búið að bregðast við á skilvirkan hátt.   • **Reglufylgni**: Að fylgjast með þróun löggjafar og staðla sem tengjast upplýsingaöryggi og tryggja að starfshættir fyrirtækisins þróist í samræmi við slíkar kröfur.   • **Samstarf** við stjórnendur og sérfræðinga á upplýsingatæknisviði og öðrum sviðum fyrirtækisins.   **Hæfniskröfur**  • Háskólamenntun sem nýtist í starfi, t.d. í tölvunarfræði eða netöryggi og/eða 10+ ára reynsla á sviði upplýsingaöryggis. Að lágmarki 5 ára stjórnunar eða leiðtogareynsla er skilyrði.   • Viðurkenndar vottanir eins og Certified Information Systems Security Professional (CISSP) eða Certified Information Security Manager (CISM) eru æskilegar.   • Reynsla af verkefnastjórnun og áætlanagerð.   • Reynsla af því að vinna náið með fjölbreyttum hópi stjórnenda og sérfræðinga frá mismunandi sviðum fyrirtækis er kostur.   • Framúrskarandi samskiptahæfni og mjög góð enskukunnátta.   • Reynsla af því að starfa í alþjóðlegu umhverfi er æskileg.    Við hvetjum fólk til að sækja um starfið óháð kyni eða uppruna.   Umsóknarfrestur er til og með 3. ágúst, 2026. Embla Medical is committed to sustainable business practices and renowned for positively impacting people‘s health and well-being _Embla Medical is an equal opportunity employer and makes employment decisions on the basis of merit. We want to have the best available individual in every job._ _Embla Medical's equal opportunity policy prohibits all discrimination (based on race, color, creed, sex, religion, marital status, age, national origin or ancestry, physical disability, mental disability, military service, pregnancy, child birth or related medical condition, actual or perceived sexual orientation, or any other consideration made unlawful by local laws around the world)._ _Embla Medical is committed to complying with all applicable laws providing equal employment opportunities. This commitment applies to all individuals involved in the operations of Embla Medical and prohibits discrimination by any emplo​yee of Embla Medical, including supervisors and co-workers._ **Important Warning:** Beware of fraudulent recruiters impersonating our company. Please take extra caution when asked for any sensitive personal information, such as social security numbers or bank account details. We will never ask you for any form of payment during the recruitment process. Please make sure you refer to our [official website](https://www.emblamedical.com/about-us/careers).