Cybersecurity Lead, Colosseum Dental Group
Oral Hammaslääkärit Oy
✨ Miksi tämä sopiiEtsimme kyberturvallisuusjohtajaa Colosseum Dental Groupille Espooseen. Tehtävä vaatii kokemusta kyberturvallisuudesta ja johtajuutta kasvavassa kansainvälisessä ympäristössä.
Kuvaus
WE ARE HIRING
CYBERSECURITY LEAD
ABOUT COLOSSEUM DENTAL GROUP
Colosseum Group is one of Europes leading multi-site healthcare services groups, operating across 11 countries with over 650 clinics and over 12500+ colleagues.
Headquartered in Zurich and backed by a long-term family office investor, the group is in an exciting phase of growth, expansion via M&A and transformation.
The group has a strong presence in markets including the Nordics, Germany, and Switzerland, with a growing reputation for clinical excellence and patient-centric care, serving over 6 million patients a year.
THE ROLE
As Cybersecurity lead, you are the owner of cybersecurity across the entire Colosseum Dental group. You set direction, manage risk, and are equally comfortable getting hands-on with the system to actively support our Country IT managers in execution, while representing Cybersecurity to our Board and Country senior management. You will report directly to the Group Director Technology & IT Operations and work alongside the Group CIO, country IT Managers and external partners.
WHAT YOU WILL OWN
Cybersecurity Strategy & Governance
Develop, own, and continuously mature the CDG cybersecurity strategy, aligned to the Colosseum strategy and the ISO 27001 / NIST CSF frameworks
Define and enforce cybersecurity policies, standards, and baselines across all 11 operating countries
Own the cybersecurity risk register; present risk posture and remediation roadmaps to the Group CFO, Group CIO and executive leadership
Lead annual assessments, continuous penetration tests and manage any statutory or regulatory obligations (NIS2, GDPR cybersecurity provisions)
Own the third-party / supplier cybersecurity assessment process for our technology vendors and SaaS solutions
Hands-On Cybersecurity Operations
Run a structured vulnerability management programme
Personally configure, tune, and audit cybersecurity controls across our Cybersecurity stack (SentinelOne, Microsoft security stack, Entra ID and more)
Maintain and continuously improve secure baselines (CIS Benchmarks / Microsoft security Baselines) for Windows, Azure Landing Zones, and M365 tenants
Drive Zero Trust adoption across identity, device, network, and data layers
Incident Response & Crisis Management
Own and together with Country IT Management lead the IT incident response process end-to-end, from detection through containment, eradication, and post-incident review
Maintain and test an up-to-date Incident Response Plan and Business Continuity provisions for cyber events
Coordinate and supervise the external CDC partner; define SLAs, runbooks, review alert quality, and escalation thresholds
Culture & Enablement
Build and sustain a cybersecurity-aware culture: design and run targeted awareness campaigns, phishing simulations, and role-based training
Act as a trusted advisor to country CFOs and country IT Managers, making cybersecurity understandable and actionable
Help grow the cybersecurity capability within the broader Group IT team to make cybersecurity a habit
WHAT YOU BRING
Non-negotiable
5+ years of hands-on information- and cybersecurity experience, with 3+ years in a senior or lead role
Technical expert in the Microsoft security stack (Defender, Azure, Entra ID, M365, etc.)
Experience managing XDR solutions, preferably SentinelOne, in a large environment of 5,000+ users
Knowledge of Zero Trust principles and practical implementation
Led or co-led real cyber incident responses
Proficient in cybersecurity frameworks and regulations like NIS2 directive, ISO 27001, NIST CSF or CIS Controls
Strongly preferred
Experience in multi-country/multi-entity organisations, ideally with a distributed IT model
Experience managing or overseeing a CDC relationship
Background in healthcare, dental, or a regulated industry (advantageous but not required)
Relevant and preferred certifications: SC-100 (Microsoft Cybersecurity Architect), SC-200, SC-300, SC-400, CISSP, CISM, or ISO 27001 Lead Implementer/Auditor
You as a person
Hands-on, self-sufficient and a pragmatic risk thinker
Practical approach in establishing robust controls rather than merely creating compliance frameworks
Comfortable operating with ambiguity in a fast-scaling organisation
Collaborative and direct to influence without authority across country IT teams
Capable of clearly communicating risk to non-technical senior stakeholders
WHAT WE OFFER
A part in one of Europes leading and fastest-growing dental care groups
An opportunity to grow and build a mature cybersecurity function across 11 countries and have an effect on the tooling we are going to use
A modern technology environment with an appetite for cybersecurity investment
Competitive compensation commensurate with seniority and market and opportunities for professional development
A purpose-driven organisation: Our mission is to provide modern, quality dentistry services for the benefit of patients, dentists, colleagues and shareholders, striving for continuous growth and excellence
HOW TO APPLY?
Please submit your CV and a short cover letter describing your relevant experience and certifications. We review applications on a rolling basis and encourage early submissions.
FOR FURTHER INFORMATION
Petteri Pasanen
Group Director, Technology & IT Operations
petteri.pasanen@colosseumdental.com [petteri.pasanen@colosseumdental.com]
Any questions on your mind regarding the position or the process? Reach out to me anytime via email. Please note: we don't process any applications via email, all applications must be submitted through our recruitment portal.
Colosseum Dental Group is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Katso ilmoitus ja hae →
Lähde: Työmarkkinatori