Do you want to shape how the board and executive management understand cyber risk at Tryg? We are looking for someone who can deliver management reporting that works, communicate clearly about information security, and help us improve how we work!
About the Role | Management reporting, ways of working and communication for the CISO
The CISO Office in Tryg is looking for a specialist to lead our management reporting and the presentations we give in governance bodies, to help optimize our department's workflows, internal processes and documentation, and to support our infosec communication and awareness work.
You will join our Nordic team in Group IT Security and work closely with the CISO. Your main task is management reporting, communication and the presentations we deliver in governance bodies and committees, and you handle it from start to finish: writing the material, involving the right stakeholders, quality assuring the content, and keeping our baseline documentation up to date. You also develop the reporting concepts, so the material continues to improve from one reporting cycle to the next.
Alongside reporting, you help optimize how the department works: streamlining workflows, improving internal processes, and keeping our documentation structured and easy to use. You also contribute to the department's communication and awareness work, such as awareness articles, phishing reporting, and training aimed at all levels of the organization. You could also be the communication lead in the IT department's Contingency team, where the job is to keep communication clear during major incidents. The role gives you a seat close to the forums where decisions on cyber risk are made, and a direct influence on what the board and executive management read.
Key responsibilities:
- Lead the CISO's management reporting and all presentations to governance bodies and committees, from first draft to final quality check.
- Develop our reporting concepts: what we measure, how we show it, and how the formats evolve as management's questions change.
- Map, streamline and document the department's workflows and internal processes, and keep our documentation structured and current.
- Identify improvements in how we work, from reporting cycles to handovers between stakeholders, and follow them through.
- Contribute to training, campaigns, and activities that raise cyber and infosec awareness.
- Help keep the communication and awareness yearly plans on track.
- Help make the team's work visible in IT and across the business.
- Act as communication lead in contingency planning and during incidents.
About You | Reporter, optimizer, communicator
The most important qualification is experience with management reporting to senior stakeholders is the most important qualification. We imagine you have a relevant higher education, for example in IT, business administration, political science or communication, and you write and present with confidence. Some exposure to infosec governance, risk and compliance is a clear advantage. We expect you to build on that knowledge here, primarily through peer training.
We are looking for:
- Experience with management reporting and presenting to management.
- You can understand a complex technical topic and explain it clearly to specialists and executives alike.
- Experience improving workflows, processes or documentation, and a structured approach to doing it.
- An interest in infosec awareness.
- Initiative to identify improvements and follow up on them, and an eye for a good story.
- The ability to support communication in a crisis.
- Nice to have: exposure to infosec governance, risk and compliance (GRC), process improvement methods such as Lean, and change management or behavioral change principles, as well as confidence in PowerPoint, Confluence and Jira.
- Ability to build networks inside and outside the company.
About Us | CISO Office in Group IT Security
Group IT Security is a Nordic department of three teams and 14 people across Denmark, Norway and Sweden, working together on the Security, Risk, and Governance agenda. We protect one of the Nordics' largest insurers and our customers, in an industry where EU DORA sets the requirements for our reporting. You will be part of the CISO Office, which sets policy, oversees the infosec control environment, assesses infosec risk, and gives management what it needs to act on cyber threats across all three Scandinavian countries.
Curious?
If you have any questions regarding the role, you are welcome to contact Chief Information Security Officer Frederic Høgsberg Kristensen on fhk@tryg.dk.
We encourage you to apply as soon as possible, and no later than 19th of October, as we will be conducting interviews on an on-going basis.