ISO/IEC 27001 Implementation Lead (interim / consultant) – POSTNORD GROUP

september 15, 2026
Roll Informationssäkerhetsspecialist
Kompetensområde Data/IT
Startdatum 2026-09-21
Slutdatum 2027-01-31
Omfattning 100%
Ort Stockholm Sweden
Land Sweden
Sista svarsdatum 2026-09-18 (Offerter kommer att behandlas löpande)
Kontaktperson Melita Landgraff (postnord@keyman.se | )
Referensnummer #16323
Övergripande uppdragsbeskrivning

Assignment: ISO/IEC 27001 Implementation Lead (interim / consultant) — PostNord TPL
Reports to: CIO, PostNord TPL
Background
PostNord TPL (third-party logistics) is pursuing its own ISO/IEC 27001:2022 certification — including an in-house-developed warehouse management system (WMS) and warehouse operational technology (OT) (scope not decided). A full gap analysis of all 118 requirements is complete: the operational and technical security foundation is genuinely strong, but it is largely undocumented and unevidenced (the majority of controls are ”partially in place”). The parent, PostNord Group, is already ISO 27001 certified, so much of the framework can be adopted or localised rather than built from scratch.
The assignment
Drive and implement the remediation programme that turns the completed gap analysis into an implemented, evidenced, audit-ready ISMS. This is a hands-on delivery role, not an advisory one: the consultant builds artefacts, runs the programme, and coordinates the owning teams to close the gaps — working within PostNord TPL’s phased strategy and alongside the Group’s certified ISMS.
Key responsibilities
  • Own and drive the ISO 27001:2022 implementation programme for TPL toward certification-readiness, reporting progress to the CIO and steering.
  • Build the risk-management engine — establish the risk method (localising the Group’s), populate and score the risk register with owners, and produce the Statement of Applicability (the critical-path deliverable).
  • Develop and localise the ISMS documentation set — policies, procedures and operating procedures — adopting from the Group where possible and creating what’s missing (~36 documents identified).
  • Close the prioritised gaps across the management-system clauses and all four Annex A domains, coordinating IT, Regional IT, HR, Legal, DPO, Procurement and Facilities.
  • Stand up the key processes — access governance / joiner-mover-leaver, incident management, tested disaster recovery and continuity, supplier security, and secure-development documentation for the in-house WMS.
  • Establish the assurance cycle — security metrics/KPIs, the internal audit (with Group Internal Audit), and the management review.
  • Build the evidence base (~55 audit artefacts) so the ISMS is demonstrably operating.
  • Support tool selection and rollout — access-governance (IAM) and asset inventory/CMDB.
  • Prepare for and support the certification audit (Stage 1 and Stage 2) with an accredited certification body.
What success looks like
A documented, operating ISMS with a signed-off SoA, a populated risk register, a completed internal audit and management review, and an evidence base that passes a Stage 2 certification audit for the agreed scope.

Skallkrav

Proven track record implementing ISO/IEC 27001 to certification — not just auditing or advising; ideally 2+ ISMS implementations taken through to a passed certification audit.
Demonstrated ability to build the mandatory core — risk-assessment methodology, risk register and Statement of Applicability, plus producing and operationalising ISMS documentation.
Strong cross-functional delivery experience — driving a programme with dependencies across IT, HR, Legal, Procurement and Facilities, ideally in a group/subsidiary structure (certifying a subsidiary under/alongside a group-certified ISMS).
Professional working proficiency in Swedish and English (Nordic stakeholder environment and Group documentation).
Hands-on experience preparing organisations for, and supporting, external Stage 1/2 audits.

Börkrav

ISO/IEC 27001 Lead Implementer certification (e.g. PECB / BSI / IRCA), with current, hands-on knowledge of the 2022 revision and its Annex A controls.
ISO 27001 Lead Auditor certification (in addition to Lead Implementer).
Experience in logistics, warehousing or supply chain, and/or operational-technology (OT) / industrial environments.
Familiarity with the Microsoft security stack (Entra ID/AD, Defender, Intune, Purview) and with IAM/access-governance and CMDB tooling.
Working knowledge of NIS2 and GDPR.

Övriga krav

Attach English CV in Word format under the Documents tab.
PLEASE REMOVE company logos and supplier contact details. The CV is an important part of the evaluation of the consultant. It must clearly show that the consultant has the competence and experience required for the current assignment.
Provide consultant’s Date of Birth in the following format: YYYY – MM – DD by writing it in the Comment field after selecting Yes
Offers for this assignment must be submitted via KeySourcingTool. Responses via email will receive limited feedback.
Please briefly describe in the ’Comment’ section how the consultant meets the various requirements.
The supplier certifies that consulting and liability insurance is in place that covers this type of assignment according to industry standards.
The supplier hereby confirms that they are aware of feedback on Offers will primarily come via KeySourcingTool on the submitted offer (notification via e-mail from KST).
The Supplier hereby warrants that all consultants provided within the scope of the Call-off Request, in accordance with the Supplier’s internal procedures applicable at any given time, have undergone customary and relevant background checks. To the best of the Supplier’s knowledge, such checks have not revealed any circumstances that would affect the Consultant’s suitability to perform the assignment
The Supplier further certifies that all information contained in each consultant’s curriculum vitae (CV), as well as any other documents provided to the Client, is, to the best of the Supplier’s knowledge at the time of submission of the tender or call-off, are correct, complete and truthful.

Personliga egenskaper

A doer who drives delivery — comfortable building the artefacts personally, not just directing.
Pragmatic and proportionate — adopts and right-sizes rather than over-engineering; reuses the Group’s framework.
Structured and self-directed — can run a multi-workstream programme with dependencies and keep it moving.
A credible influencer — gets busy technical and business stakeholders to deliver, including during the operational peak period.
Evidence-minded and detail-oriented — thinks in terms of what an auditor will sample.

Övrig information

PostNord operates based on the principle of a flexible workplace, with physical presence 3 days per week, as agreed upon with the PostNord manager.

NOTE: We will not provide an expected rate for this role but we look forward to recieve tenders with competitive market rates.

 


(Om du är helt ny användare och vill registrera dig och ditt bolag i KeySourcingTool – Klicka här)

(Om ditt bolag redan är registrerat i KeySourcingTool men behöver bli affärspartner med KeyMan – Klicka här)

 

Prenumerera på nyhetsbrev

Logga in