Cybersecurity Specialist – Log Management and SOC in a Critical Societal Environment
Workplace: Stockholm, Sverige
Expires: September 14, 2025
Lead the development of log management and SOC functionality at Socialstyrelsen to protect systems, data, and users in a complex IT environment impacting society. Work both operationally and strategically to detect, monitor, and handle security events, while collaborating closely with the organization.
Main requirements:
  • Relevant education or equivalent experience in the field
  • Multi-year experience in IT/cybersecurity handling complex technical issues
  • Experience working in complex IT environments
  • Experience investigating and managing security incidents
  • Good knowledge of log analysis and SIEM tools
  • Understanding of information security principles, vulnerability identification and protection measures
  • Ability to translate business requirements into technical solutions
  • Basic network knowledge
  • Knowledge of identity security in local and cloud environments
  • Familiarity with security principles and methods like SoD, Least Privilege, Zero Trust
  • Knowledge of security standards and frameworks such as OWASP, NIST, MITRE ATT&CK
  • Familiarity with cybersecurity control frameworks including CIS, COBIT, NIST, ISO 2700x
  • Good Swedish and English proficiency, both spoken and written
  • Swedish citizenship
Responsibilities:
  • Lead development of log management and core SOC functionality
  • Define structures, processes, and technical solutions to enhance detection, monitoring, and handling of security events
  • Engage actively in daily cybersecurity operations including incident handling and vulnerability assessments
  • Document work clearly to foster structure and long-term security effectiveness
  • Collaborate closely with the organization to align security initiatives with business needs
Required hard skills:
  • Log analysis and SIEM tools
  • Security incident investigation and handling
  • Information security and vulnerability assessment
  • Network fundamentals
  • Identity security in local and cloud environments
  • Security principles: SoD, Least Privilege, Zero Trust
  • Security standards/frameworks: OWASP, NIST, MITRE ATT&CK
  • Cybersecurity control frameworks: CIS, COBIT, NIST, ISO 2700x
Recommended hard skills:
  • Certifications such as OSCP, OSWE, CISSP, CEH or equivalent
  • Experience with Microsoft Sentinel
  • Scripting for log analysis
  • Knowledge of NIS2 and CER regulations
  • Experience in forensics
Soft skills:
  • Proactive and responsible with initiative to complete tasks
  • Self-driven with strong planning and structuring skills
  • Strong analytical skills for problem breakdown and solution proposal
  • Clear and structured documentation skills
  • Ability to work both independently and collaboratively
Coding languages:
  • Scripting languages related to log analysis (not specified)
Frameworks:
  • OWASP
  • NIST
  • MITRE ATT&CK
  • CIS
  • COBIT
  • ISO 2700x
Operating systems:
  • Not explicitly specified
Natural languages:
  • Swedish (Proficient)
  • English (Proficient)
Cultural skills:
  • Ability to work in a team-oriented and flexible environment with focus on work-life balance
  • Commitment to societal benefit through technology