Interim NIS2 Program Lead & IT Governance
Interim Search has been tasked with recruiting a business-driven and pragmatic Interim NIS2 Program Lead for an international medical technology company in Skåne. In this role, you will be responsible for driving the company’s NIS2 implementation and establishing a sustainable IT governance structure. You will step into a key role to translate the new cybersecurity law into practical processes within an international environment accustomed to high levels of regulatory oversight. Since the company’s IT operations are fully outsourced, the role involves extensive responsibility for leading and setting requirements for external service providers. The role works closely with the steering committee, as well as the CFO, Legal Director, and external experts.
Main duties
- Be responsible for managing and implementing the company’s NIS2 program based on the completed gap analysis and the existing project plan.
- Translate regulatory requirements from the new Cybersecurity Act and the MCF’s (formerly MSB) guidelines into practical, business-oriented processes (Governance).
- Act as a client representative and requirements specifier in dealings with external IT partners to ensure that identified security measures and contract amendments are implemented operationally.
- Coordinate with key internal personnel in the legal and quality departments to ensure that the IT environment (including systems such as Navision and Master Control) is documented and validated in accordance with applicable requirements.
- Ensure a clear ”audit trail” and prepare the organization for future audits and the permanent handover at the end of the year.
To be eligible for the assignment
- You have a strong background as a Program or Project Manager in IT security and governance, with documented experience in regulatory implementations (e.g., ISO 27001, NIS, GDPR, or MDR).
- You have a strong ability to translate legal requirements into practical controls that work in day-to-day operations. Documented experience successfully managing and setting requirements for major external IT partners (third parties).
- You are accustomed to navigating outsourced environments and understand how to drive change through service agreements and external delivery organizations.
- Experience working in a lean, fully outsourced organization where self-management and the ability to coordinate external parties are essential.
- Proven experience in stakeholder management at the executive level, with the ability to communicate risk and compliance in a pragmatic manner.
- Excellent proficiency in Swedish and English is required, as the role involves an international infrastructure with a shared AD environment for Europe and the United States.
About the process
This is a full-time assignment expected to last through the end of the year, starting immediately. The position is based in Southern Sweden and follows a hybrid work model. We will present candidates to the client on March 4. Client interviews are scheduled for March 5 and March 6.
Do you have the right profile and are you available? Apply now!