The client is looking for an Information Security Specialist specializing in cloud services to conduct a comprehensive assessment of approximately 30 cloud services.
The objective is to establish a complete, consistent, and quality-assured overview of the cloud services, including their ownership, responsibilities, information handling, contractual status, risks, compliance requirements, and supplier dependencies.
The assignment will result in a main report and decision-support document for the responsible manager, highlighting the current state, identified risks and gaps, and recommended actions.
Key Responsibilities
The consultant will:
- Inventory and assess approximately 30 cloud services
- Analyze ownership, responsibilities, and governance
- Review contracts, agreements, terms, and supplier arrangements
- Assess information handling, classification, retention, archiving, and public records
- Review personal data processing and GDPR/data protection requirements
- Assess information security controls and regulatory compliance
- Identify supplier dependencies and associated risks
- Review existing documentation and decision-support material
- Conduct interviews with relevant stakeholders
- Consolidate findings into structured management-level decision material
- Produce a comprehensive final report with:
- Current-state assessment
- Identified risks
- Gaps/non-compliance
- Recommendations
- Proposed actions
Mandatory Skills
Candidates must demonstrate:
- 4+ years of recent/current experience in information security and information classification
- Proven experience with cloud service inventory, assessment, and governance
- Proven experience in data protection and personal data processing
- Proven experience with contract review and supplier/vendor management
- Experience conducting stakeholder interviews
- Ability to prepare and present decision-support material at management level
- Swedish language proficiency
Preferred / Meritorious Experience
Candidates with the following experience are particularly relevant:
- Similar cloud-service assessments within a government authority or public-sector organization
- Assessment of cloud services concerning:
- Freedom of information / public access
- Confidentiality and secrecy
- Archiving requirements
- Third-country data transfers
- Experience working with regulatory requirements applicable to Swedish public-sector organizations