Information Security Specialist
Lokki Henkilöstöpalvelut Oy
| Company | Lokki Henkilöstöpalvelut Oy |
| Category | Security |
| Location | FI |
| Remote | Hybrid |
| Employment | Full-time |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 9 Aug 2026 |
| Last verified | 10 Aug 2026 |
| Source | Public employment agency (eures) |
Description
We are looking for a Information Security Specialist for our clients public sector tender. Customer industry is in Environmental Services.
Description:
The Information Security Specialist is responsible for developing, maintaining, and monitoring the organizations information security. The specialist ensures that information systems, networks, and services are protected against threats and that information security practices are up to date.
Tasks may include:
· Preparation and maintenance of information security policies and guidelines
· Threat and vulnerability analyses and risk management
· Management and reporting of information security incidents
· Information security monitoring and audits (e.g., SIEM, SOC)
· User training and increasing information security awareness
Required Skills:
· Experience in information security management and development
· Understanding of information security standards and requirements (e.g., ISO 27001, NIS2) · Experience with information security tools and solutions (e.g., SIEM, EDR)
· Fluent Finnish and English language skills
· Certifications (e.g., CISSP, CISM, Microsoft Security, CompTIA Security+)
· Experience in cloud environment security
· Knowledge of information security audits and testing
Required experience and competence (within the last 60 months) Minimum requirement:
1. Experience in designing and implementing information security solutions:
The expert has experience from at least three (3) information security solution design and implementation projects that have included both cloud-based and traditional infrastructure environments. Each assignment has had a scope of at least 30 person-days.
2. Microsoft Sentinel competence:
The expert has experience in implementing Microsoft Sentinel, configuring rules and alerts, automation, threat detection, and response in at least two (2) customer assignments.
3. Security of cloud and hybrid environments:
The expert has experience in designing and implementing security for modern Microsoft Azure environments, including Conditional Access, identity management, and data protection, in at least two (2) customer assignments.
4. Security of traditional infrastructure:
The expert has experience in managing the security of on-premises environments (e.g., firewalls, antivirus, AD security, segmentation) in at least two (2) customer assignments.
5. Threat modeling and risk management:
The expert has experience in threat modeling, risk assessment, and planning control measures in at least two (2) customer assignments.
6. Certification:
The expert has a valid information security-related certificate, such as Microsoft Cybersecurity Architect Expert, SC-200, CISM or CISSP, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Security Operations Analyst Associate, Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Security - Specialty, Google Cloud Certified Professional Cloud Security Engineer, Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), EC-Council Certified Chief Information Security Officer (C|CISO), CompTIA Cybersecurity Analyst (CySA+), CompTIA Advanced Security Practitioner (CASP+), GIAC Certified Incident Handler (GCIH), GIAC Security Essentials Certification (GSEC), Cisco Certified CyberOps Associate, Cisco Certified Network Professional Security (CCNP Security), Certified Ethical Hacker (C|EH), Offensive Security Certified Professional (OSCP).
7. Information security monitoring and response:
The expert has experience with SOC operating models, alert handling, and implementing incident response processes in at least one (1) customer assignment.
8. Use of automation tools:
The expert has experience with automation tools (e.g., KQL, Logic Apps, PowerShell) supporting information security processes in at least one (1) customer