Your responsibilities
Welcome to Group Technology, where we pride ourselves on engineering solutions and direct Nordea's transformation by providing a holistic technological view and structured understanding of the bank, and its surrounding environment to enable the Customer Vision and the Business Strategy.
Nordea is a place where traditions meet tomorrow. We're not just a bank, we're a tech employer on a mission to evolve finance securely and responsibly. Together, we impact millions of people's daily lives by ensuring they can access our solutions anytime, anywhere, while safeguarding their personal data and wealth. Join us in making an impact on the banking industry.
About our team
Meet the Cloud Security team. As a part of Cyber Security we act as the primary advisory body for Nordea teams implementing cloud solutions, ensuring security is built-in from the initial planning phases.
What you'll be doing
We are now looking for a Cloud Security Expert specialist to join our team and help us stay up to date with everchanging world of risks, security and compliance requirements in cloud and AI. Person who understands security best practices for applications, servers and networks and can translate that into Cloud security requirements and standards.
Main responsibilities in this role:
* Provide expert guidance on selecting security controls across SaaS, PaaS, and IaaS models, ensuring alignment with industry frameworks and internal compliance.
* Participate in Third Party Risk Assessments (TPRM) and Quality Risk Assessments (QRA) to provide senior leadership with a comprehensive risk picture.
* Act as a central coordinator for AI Security, synthesizing use cases and assessing the security implications of emerging AI implementations.
* Function as a strategic liaison between Cyber Security org. and project teams, translating complex technical requirements into business-aligned security strategies.
* Review architectural designs and recommend enhancements to ensure "security by design" rather than "bolted-on" solutions.
* Monitor and approve security changes in Nordea main cloud providers, to ensure Nordea security posture isn't weakened and risks are properly captured and approved.
Our requirements
Who you are
This is the right role for you if you have:
* 5+ years' experience in IT security, compliance, and risk management with a focus on cloud-native environments.
* Strong understanding of Cloud Provider security best practices (AWS, Azure, or GCP) and how to apply them to diverse business projects.
* Proven experience in risk leadership, specifically coordinating with legal, procurement, and technical teams during risk evaluation evaluations.
* Familiarity with AI security threats, governance frameworks, and the security implications of Large Language Models (LLMs) or AI integrations.
* Ability to translate technical risks into "business-friendly" language for non-technical stakeholders.
Nice to have certifications: Preferably AWS/Azure/GCP Security, CCSP.
It would be ideal if you also:
* Have security or architecture certification from one (or more)of three main cloud providers AWS/Azure/GCP. For this role GCP is preferable.
* Have an experience in deployment or governance of cloud CNAPP tool e.g. Wiz.