About the role
You will develop and maintain Ambu’s governance, risk and compliance frameworks to support our mission of developing medical devices. You will drive key security controls, ensure compliance with standards like ISO 27001, NIS2 and UK CE+, and collaborate across functions to manage risk, deliver training and awareness, and build metrics.
Responsibilities
- Develop and maintain GRC frameworks, policies and procedures for Ambu’s internal and product operations.
- Lead implementation of key security controls and ensure compliance with ISO 27001, NIS2 and UK CE+.
- Drive supplier risk assessments, security training and awareness programmes, and track security metrics.
- Partner with business functions to integrate security and privacy requirements into project design and processes.
- Perform risk assessments and audits, identify gaps and coordinate remediation.
Requirements
- At least 8 years of experience in cybersecurity, with expertise in governance, risk management and compliance in MedTech or healthcare.
- Bachelor’s or Master’s degree in computer science, engineering or related field and certifications such as CISSP, CISM or CRISC.
- Proven experience designing and operating ISO 27001 certified management systems and understanding of regulatory frameworks.
- Strong stakeholder management, communication and collaboration skills with ability to influence across functions.
- Fluent in English and Danish; experience working internationally is a plus.
What we offer
- A visionary international organisation that brings healthcare innovations to life.
- Opportunities for professional development and learning.
- A diverse and inclusive work environment with global colleagues.
- Competitive benefits and flexible working arrangements.
About Ambu
Founded in 1937, Ambu develops single-use endoscopy, anaesthesia and patient monitoring products. Headquartered near Copenhagen, Ambu employs around 4,500 people worldwide and is committed to improving healthcare through innovative solutions.