Job Description
At Tieto Caretech you’ll get a chance to provide patients and end users with product offerings that help them in their life, reinventing the world for good. If that sounds interesting, please keep on reading.
About us
Tieto Caretech is modernizing the Nordic health and social care sector with modular, open, and interoperable software. We develop and deliver high quality software solutions and services that enable healthcare and welfare professionals to do their work even better and with higher efficiency - have more time to care.
We are a global team of professionals working on providing products and services to different sectors from intensive care to laboratory and social care. In addition to working closely with our customers, we also have our own products that we build and develop for various fields in society. From enabling healthcare professionals to spend more valuable time with their patients to providing data for professional athletes to achieve even better results, we make all that possible. With us you can build technology for the good of society and make your mark on the health and wellbeing of people in need.
About the role
As the Security and Privacy Lead at Tieto Caretech, you will ensure our products and services fulfill security and privacy related requirements, support different teams with their security and privacy related matters as well as create security and privacy frameworks and principles to be shared across our unit. You will lead the design of a security and privacy driven strategy for our diverse healthcare IT product portfolio. You will closely follow the direction of Nordic healthcare (public organizations and authorities) and ensure our security and privacy policies are aligned with the requirements.
Your main goal will be to ensure the security, privacy and robustness of our solutions while aligning them with industry standards and best practices. You will set clear security and privacy related goals, ensuring teams are accountable for delivering high-quality, secure, and scalable solutions. You will have the main responsibility for all security and privacy related matters in our unit.
You will collaborate closely with different architects, development teams, development managers and product management.
In this role you will
- Work together with the Tieto Caretech Security & Privacy experts to define and follow-up alignment to relevant security and privacy frameworks and policies.
- Ensure security and privacy are aligned with our strategy
- Create frameworks, principles and policies that will support our development teams
- Ensure compliance, legislation and regulation related requirements are followed
- Assist with security and privacy related audits
- Create policies and controls for security and privacy related matters
- Execute threat modelling and risk assessment for our portfolio
- Lead security architecture and support our architects with security and privacy related matters
We are looking for someone with
- Experience in Secure by design and Privacy by design approaches
- Experience in threat modelling and risk assessments
- Experience in creating and driving security and privacy related policies, standards and controls
- A strong ability to create strategical targets and goals regarding to security and privacy
- In-depth knowledge in relevant compliance, legislation and regulation (Nordic Healthcare)
- Experience in executing or supporting privacy audits and assessments
- Experience in designing Security architecture
- In-depth knowledge in relevant directives, processes, frameworks, standards, controls and models such as CIS, NIST, GDPR, ISO 27001, DPIA, NIS2
- Hands-on technical expertise and experience to resolve security and privacy related tasks to support our development teams
It would be beneficial if you also have
- Knowledge in Medical Device Regulation (MDR)
- Knowledge regarding regulation and requirements specifically in the Nordic Healthcare sector
- Knowledge in recent or upcoming European Union level directives and action plans, such as European Health Data Space (EHDS), EU Artificial Intelligence Act, European action plan on the cybersecurity of hospitals and healthcare providers, EU Cyber Solidarity Act and EU Cyber Resilience Act
- Knowledge in Microsoft technologies and solutions such as Azure, Windows Server, .NET Framework, .NET, SQL Server etc.
- Knowledge and experience in Data Governance best practices and models
What’s in it for you?
With us you will be part of the important and meaningful work of developing healthcare for all of us. You have an important mission to make a difference that really matters. In addition, as a company we offer you professional growth, open and friendly culture, and an outstanding work-life balance! We believe that our organizational culture is an important part of enabling you to be successful. We provide a flexible hybrid work model as part of our culture and way of working.
Finally, we also believe in curiosity and learning as a lifestyle. We want to encourage you to keep up that curiosity and deepen your knowledge on topics you’re interested in. For example, we host an annual ‘Keep Learning Week’, a week where everyone at Tieto has the possibility to join different training courses in a truly global setting.
Could you be our new colleague?
We look forward to hearing from you! We will fill the position as soon as we find the right person, so we encourage you to apply today. If you have any questions regarding this role, please contact the hiring manager Daniel Westerlund (daniel.m.westerlund@tietoevry.com)
We perform background checks on all final candidates.
Tieto declines calls from recruitment companies.
Additional Information
At Tieto, we believe in the power of diversity, equity, and inclusion. We encourage applicants of all backgrounds, genders (m/f/d), and walks of life to join our team, as we believe that this fosters an inspiring workplace and fuels innovation. Our commitment to openness, trust, and diversity is at the heart of our mission to create digital futures that benefit businesses, societies, and humanity.
Diversity, equity and inclusion (tietoevry.com)