Head of Information Security
Paço de Arcos, PT, 2770-131
Job ID: 6339
Would you like to be part of taking NAM IT to the next level? We are now looking for a Head of Information Security to maintain our Information Security framework with the aim of becoming a best in class.
Nordea Asset Management (NAM) is the centre of investment management in the Nordea Group and in the Asset & Wealth Management division. NAM is the largest asset manager in the Nordics with the vision of being a leading European Asset Manager. We want to do this by delivering returns with responsibility. We meet customer demands and guide our customers in the right direction in asset selection while ensuring prudent ESG practices. NAM has around 900 employees and more than 475 Nordic and international institutional clients.
About this opportunity
Welcome to the NAM IT. We add value by ensuring that all IT applications within Nordea Asset management are running efficiently, supporting the organisation to deliver first class products and services to our clients. The department has a appr. 50 employees split in 4 sub-teams. As Head of NAM Information Security, you’ll manage a team of 5 people and play a valueable role in ensuring how we run out IT Security when it comes to scale and efficiency, whilst keeping stability at a very high level. It is also a vital part of the role to ensure that we do prudent and that we live up to regulation, e.g. the new DORA regulation or new technologies, e.g A.I.
What you’ll be doing:
- Steer and develop NAM IT and create a culture of collaboration both within the teams in NAM IT, but equally important towards the rest of the Technology organisation
- As part of the Technology management team, be part of further developing our organisation by scoping needed changes and making tangible plans that can be executed upon.
- Undertake internal security assessments and facilitate creation of action plans with key busines.
- Ensure that our applications are living up to the security requirements set out by legislators and Nordea Bank.
- Perform information security operational tasks and day to day follow up of actions with the overall objective of ensuring the operational effectiveness of existing security controls, improve the overall control environment and reduce risk exposure.
- Assist with the review and maintenance of existing Information Security controls and the design of new ones in line with evolving business, security or legal/regulatory requirements.
- Be a significant stakeholder towards our main supplier of IT services (Nordea Group IT), to ensure we get the delivered services with the right amount of quality and within the agreed timeline.
- Support AI on-boarding
- Work with internal and external auditors in relation to information security audits.
- Conduct risk assessment activities and execute risk treatment plans.
- Manage vulnerability management and patching processes (inc. end of life software)
- Collaborate with application providers about access management, including priviledged access
- Review and approve security designs for new systems and new projects.
- Develop and maintain relationships with business units, to emphasise and promote the importance of information security, risk and governance management.
- Analyse and support the remediation of information security incidents.
The function has employees in Lisbon but some traveling is expected in this role. The role is based in Lisbon.
Who you are
Collaboration. Ownership. Passion. Courage. These are the values that guide us in being at our best – and that we imagine you share with us.
To do well in this role, we believe that you:
- Define, develop and maintain NAM Information Security framework and operating model.
- Assist and advise stakeholders on Information Security matters ranging from practical implementation of Security policies and standards to educating about NAM’s IT Governance framework.
- Act as liaison between business and technology teams to investigate and resolve matters related to Information Security areas.
- Advise on the implementation and monitoring of relevant areas for controls in operational business processes.
- Act as an ambassador and promote security management throughout the NAM organization.
- Communicate with NAM’s clients professionally when required.
- Actively collaborate with relevant stakeholders and actively communicate about daily business and matters and structural issues within team.
- Interact professionally with key stakeholders and fact-based on service deliveries in order to ensure best operation practice.
- Take responsibility on team KPIs.
- Support the organization in implementing compliant and relevant cyber security capabilities and monitoring adherence to cyber, and information security.
- Ensure that compliant information security framework is in place.
- Support business in implementing information security requirements.
- Ensure that the status and implementation of the information security framework is monitored and reported on.
- Ensure that compliant Security frameworks are in place, support the organisation in assessing and addressing Security risk
- Ensure monitoring and reporting on the status for Security governance framework
Competence:
- Have leadership experience to set the direction and grow the team.
- Strong experience in Information Security domain with great results when it comes to assessments and documentations.
- Good communication skills and proven ability to report to senior management about security and governance topics.
- Good understanding of IT Governance and ability to the right level of implementation in the organisation.
- A great communicator and motivator, both spoken and written in English.
Your experience and background:
- Relevant Masters degree with good results.
- Great leadership skills, with the ability to develop a collaborative culture and be an excellent sparring partner for the team.
- Ensure that the team as a whole is considered a proffesional unit and natural place to go for IT services.
- 5+ years of experience leading an Information Security unit.
- Knowledge of the financial industry is a merit.
- Documented history of efficiently leading and delivering complex Security solutions supporting the business to deliver great customer experiences.
- Structured and analytical mindset and ability to challenge status quo, in order to gain efficiencies.
If this sounds like you, get in touch!
If this sounds like you, get in touch!
Next steps
Submit your application no later than 30/09/2026.
At Nordea, we know that an inclusive workplace is a sustainable workplace. We deeply believe that our diverse backgrounds, experiences, characteristics and traits make us better at supporting our customers and communities. So please come as you are.
#NAM
#NAM-Portugal