{"id":31542,"date":"2026-09-15T00:00:00","date_gmt":"2026-09-14T22:00:00","guid":{"rendered":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/"},"modified":"2026-09-15T00:00:00","modified_gmt":"2026-09-14T22:00:00","slug":"iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323","status":"publish","type":"post","link":"https:\/\/www.keyman.se\/sv\/data-it\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/","title":{"rendered":"ISO\/IEC 27001 Implementation Lead (interim \/ consultant) &#8211;  POSTNORD GROUP"},"content":{"rendered":"<table width=\"100%\">\n<tbody>\n<tr>\n<td style=\"text-align: left;\" align=\"left\" valign=\"top\" width=\"20%\"><strong>Roll<\/strong><\/td>\n<td style=\"text-align: left;\" align=\"left\" valign=\"top\" width=\"80%\">Informationss\u00e4kerhetsspecialist<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Kompetensomr\u00e5de<\/strong><\/td>\n<td style=\"text-align: left;\">Data\/IT<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Startdatum<\/strong><\/td>\n<td style=\"text-align: left;\">2026-09-21<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Slutdatum<\/strong><\/td>\n<td style=\"text-align: left;\">2027-01-31<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Omfattning<\/strong><\/td>\n<td style=\"text-align: left;\">100%<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Ort<\/strong><\/td>\n<td style=\"text-align: left;\">Stockholm Sweden<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Land<\/strong><\/td>\n<td style=\"text-align: left;\">Sweden<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Sista svarsdatum<\/strong><\/td>\n<td style=\"text-align: left;\" width=\"312\">2026-09-18\u00a0<em>(Offerter kommer att behandlas l\u00f6pande)<\/em><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Kontaktperson<\/strong><\/td>\n<td style=\"text-align: left;\">Melita Landgraff (<a href=\"mailto:postnord@keyman.se\">postnord@keyman.se<\/a> | )<\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: left;\"><strong>Referensnummer<\/strong><\/td>\n<td style=\"text-align: left;\">#16323<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h5>\u00d6vergripande uppdragsbeskrivning<\/h5>\n<p style=\"padding-left: 30px;\">\n<div>Assignment: ISO\/IEC 27001 Implementation Lead (interim \/ consultant) \u2014 PostNord TPL<\/div>\n<div><strong>Reports to:<\/strong> CIO, PostNord TPL<\/div>\n<div><strong>Background<\/strong><\/div>\n<div>PostNord TPL (third-party logistics) is pursuing its own ISO\/IEC 27001:2022 certification \u2014 including an in-house-developed warehouse management system (WMS) and warehouse operational technology (OT) (scope not decided). A full gap analysis of all 118 requirements is <strong>complete<\/strong>: the operational and technical security foundation is genuinely strong, but it is largely undocumented and unevidenced (the majority of controls are &#8221;partially in place&#8221;). The parent, PostNord Group, is already ISO 27001 certified, so much of the framework can be adopted or localised rather than built from scratch.<\/div>\n<div><strong>The assignment<\/strong><\/div>\n<div>Drive and implement the remediation programme that turns the completed gap analysis into an implemented, evidenced, audit-ready ISMS. This is a <strong>hands-on delivery role<\/strong>, not an advisory one: the consultant builds artefacts, runs the programme, and coordinates the owning teams to close the gaps \u2014 working within PostNord TPL&#8217;s phased strategy and alongside the Group&#8217;s certified ISMS.<\/div>\n<div><strong>Key responsibilities<\/strong><\/div>\n<ul>\n<li><strong>Own and drive<\/strong> the ISO 27001:2022 implementation programme for TPL toward certification-readiness, reporting progress to the CIO and steering.<\/li>\n<li><strong>Build the risk-management engine<\/strong> \u2014 establish the risk method (localising the Group&#8217;s), populate and score the risk register with owners, and produce the <strong>Statement of Applicability<\/strong> (the critical-path deliverable).<\/li>\n<li><strong>Develop and localise the ISMS documentation set<\/strong> \u2014 policies, procedures and operating procedures \u2014 adopting from the Group where possible and creating what&#8217;s missing (~36 documents identified).<\/li>\n<li><strong>Close the prioritised gaps<\/strong> across the management-system clauses and all four Annex A domains, coordinating IT, Regional IT, HR, Legal, DPO, Procurement and Facilities.<\/li>\n<li><strong>Stand up the key processes<\/strong> \u2014 access governance \/ joiner-mover-leaver, incident management, tested disaster recovery and continuity, supplier security, and secure-development documentation for the in-house WMS.<\/li>\n<li><strong>Establish the assurance cycle<\/strong> \u2014 security metrics\/KPIs, the internal audit (with Group Internal Audit), and the management review.<\/li>\n<li><strong>Build the evidence base<\/strong> (~55 audit artefacts) so the ISMS is demonstrably operating.<\/li>\n<li><strong>Support tool selection and rollout<\/strong> \u2014 access-governance (IAM) and asset inventory\/CMDB.<\/li>\n<li><strong>Prepare for and support the certification audit<\/strong> (Stage 1 and Stage 2) with an accredited certification body.<\/li>\n<\/ul>\n<div><strong>What success looks like<\/strong><\/div>\n<div>A documented, operating ISMS with a signed-off SoA, a populated risk register, a completed internal audit and management review, and an evidence base that passes a Stage 2 certification audit for the agreed scope.<\/div>\n<\/p>\n<h5>Skallkrav<\/h5>\n<p style=\"padding-left: 30px;\">Proven track record implementing ISO\/IEC 27001 to certification \u2014 not just auditing or advising; ideally 2+ ISMS implementations taken through to a passed certification audit.<br \/>\nDemonstrated ability to build the mandatory core \u2014 risk-assessment methodology, risk register and Statement of Applicability, plus producing and operationalising ISMS documentation.<br \/>\nStrong cross-functional delivery experience \u2014 driving a programme with dependencies across IT, HR, Legal, Procurement and Facilities, ideally in a group\/subsidiary structure (certifying a subsidiary under\/alongside a group-certified ISMS).<br \/>\nProfessional working proficiency in Swedish and English (Nordic stakeholder environment and Group documentation).<br \/>\nHands-on experience preparing organisations for, and supporting, external Stage 1\/2 audits.<\/p>\n<h5>B\u00f6rkrav<\/h5>\n<p style=\"padding-left: 30px;\">ISO\/IEC 27001 Lead Implementer certification (e.g. PECB \/ BSI \/ IRCA), with current, hands-on knowledge of the 2022 revision and its Annex A controls.<br \/>\nISO 27001 Lead Auditor certification (in addition to Lead Implementer).<br \/>\nExperience in logistics, warehousing or supply chain, and\/or operational-technology (OT) \/ industrial environments.<br \/>\nFamiliarity with the Microsoft security stack (Entra ID\/AD, Defender, Intune, Purview) and with IAM\/access-governance and CMDB tooling.<br \/>\nWorking knowledge of NIS2 and GDPR.<\/p>\n<h5>\u00d6vriga krav<\/h5>\n<p style=\"padding-left: 30px;\">Attach English CV in Word format under the Documents tab. &#13;<br \/>\nPLEASE REMOVE company logos and supplier contact details. The CV is an important part of the evaluation of the consultant. It must clearly show that the consultant has the competence and experience required for the current assignment.<br \/>\nProvide consultant&#8217;s Date of Birth in the following format: YYYY &#8211; MM &#8211; DD by writing it in the Comment field after selecting Yes<br \/>\nOffers for this assignment must be submitted via KeySourcingTool. Responses via email will receive limited feedback.<br \/>\nPlease briefly describe in the &#8217;Comment&#8217; section how the consultant meets the various requirements.<br \/>\nThe supplier certifies that consulting and liability insurance is in place that covers this type of assignment according to industry standards.<br \/>\nThe supplier hereby confirms that they are aware of feedback on Offers will primarily come via KeySourcingTool on the submitted offer (notification via e-mail from KST).<br \/>\nThe Supplier hereby warrants that all consultants provided within the scope of the Call-off Request, in accordance with the Supplier&#8217;s internal procedures applicable at any given time, have undergone customary and relevant background checks. To the best of the Supplier&#8217;s knowledge, such checks have not revealed any circumstances that would affect the Consultant&#8217;s suitability to perform the assignment<br \/>\nThe Supplier further certifies that all information contained in each consultant&#8217;s curriculum vitae (CV), as well as any other documents provided to the Client, is, to the best of the Supplier&#8217;s knowledge at the time of submission of the tender or call-off, are correct, complete and truthful.<\/p>\n<h5>Personliga egenskaper<\/h5>\n<p style=\"padding-left: 30px;\">A doer who drives delivery \u2014 comfortable building the artefacts personally, not just directing.<br \/>\nPragmatic and proportionate \u2014 adopts and right-sizes rather than over-engineering; reuses the Group&#8217;s framework.<br \/>\nStructured and self-directed \u2014 can run a multi-workstream programme with dependencies and keep it moving.<br \/>\nA credible influencer \u2014 gets busy technical and business stakeholders to deliver, including during the operational peak period.<br \/>\nEvidence-minded and detail-oriented \u2014 thinks in terms of what an auditor will sample.<\/p>\n<h5>\u00d6vrig information<\/h5>\n<p style=\"padding-left: 30px;\">\n<div>PostNord operates based on the principle of a flexible workplace, with physical presence 3 days per week, as agreed upon with the PostNord manager.<\/p>\n<p><strong>NOTE:<\/strong> <strong>We will not provide an expected rate for this role but we look forward to recieve tenders with competitive market rates.<\/strong><\/div>\n<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n\t\t<div data-elementor-type=\"section\" data-elementor-id=\"21413\" class=\"elementor elementor-21413\" data-elementor-post-type=\"elementor_library\">\n\t\t\t<div class=\"elementor-element elementor-element-dbbd2a4 e-flex e-con-boxed e-con e-parent\" data-id=\"dbbd2a4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-db64379 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"db64379\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-info-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119.043 8 8 119.083 8 256c0 136.997 111.043 248 248 248s248-111.003 248-248C504 119.083 392.957 8 256 8zm0 110c23.196 0 42 18.804 42 42s-18.804 42-42 42-42-18.804-42-42 18.804-42 42-42zm56 254c0 6.627-5.373 12-12 12h-88c-6.627 0-12-5.373-12-12v-24c0-6.627 5.373-12 12-12h12v-64h-12c-6.627 0-12-5.373-12-12v-24c0-6.627 5.373-12 12-12h64c6.627 0 12 5.373 12 12v100h12c6.627 0 12 5.373 12 12v24z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">F\u00f6r att kunna offerera p\u00e5 v\u00e5ra uppdrag m\u00e5ste du vara registrerad anv\u00e4ndare i KeySourcingTool och ditt bolag m\u00e5ste \u00e4ven vara aff\u00e4rspartner med KeyMan (kostnadsfritt).<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-8208697 e-flex e-con-boxed e-con e-parent\" data-id=\"8208697\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2f3264f elementor-align-left elementor-widget elementor-widget-button\" data-id=\"2f3264f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/app.keysourcingtool.com\/tender_invite_parts\/13046935\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">OFFERERA P\u00c5 DETTA UPPDRAG VIA KEYSOURCINGTOOL<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5d0885e e-flex e-con-boxed e-con e-parent\" data-id=\"5d0885e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-bb68ae0 elementor-widget elementor-widget-text-editor\" data-id=\"bb68ae0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>(Om du \u00e4r helt ny anv\u00e4ndare och vill registrera dig och ditt bolag i KeySourcingTool &#8211; <a href=\"https:\/\/app.keysourcingtool.com\/users\/sign_up\"><strong>Klicka h\u00e4r<\/strong><\/a>)<\/p><p>(Om ditt bolag redan \u00e4r registrerat i KeySourcingTool men beh\u00f6ver bli aff\u00e4rspartner med KeyMan &#8211; <a href=\"https:\/\/www.keyman.se\/sv\/prenumerera-pa-uppdrag\/\"><strong>Klicka h\u00e4r<\/strong><\/a>)<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<div>Assignment: ISO\/IEC 27001 Implementation Lead (interim \/ consultant) \u2014 PostNord TPL<\/div>\n<div><strong>Reports to:<\/strong> CIO, PostNord TPL<\/div>\n<div><strong>Background<\/strong><\/div>\n<div>PostNord TPL (third-party logistics) is pursuing its own ISO\/IEC 27001:2022 certification \u2014 including an in-house-developed warehouse management system (WMS) and warehouse operational technology (OT) (scope not decided). A full gap analysis of all 118 requirements is <strong>complete<\/strong>: the operational and technical security foundation is genuinely strong, but it is largely undocumented and unevidenced (the majority of controls are &#8221;partially in place&#8221;). The parent, PostNord Group, is already ISO 27001 certified, so much of the framework can be adopted or localised rather than built from scratch.<\/div>\n<div><strong>The assignment<\/strong><\/div>\n<div>Drive and implement the remediation programme that turns the completed gap analysis into an implemented, evidenced, audit-ready ISMS. This is a <strong>hands-on delivery role<\/strong>, not an advisory one: the consultant builds artefacts, runs the programme, and coordinates the owning teams to close the gaps \u2014 working within PostNord TPL&#8217;s phased strategy and alongside the Group&#8217;s certified ISMS.<\/div>\n<div><strong>Key responsibilities<\/strong><\/div>\n<ul>\n<li><strong>Own and drive<\/strong> the ISO 27001:2022 implementation programme for TPL toward certification-readiness, reporting progress to the CIO and steering.<\/li>\n<li><strong>Build the risk-management engine<\/strong> \u2014 establish the risk method (localising the Group&#8217;s), populate and score the risk register with owners, and produce the <strong>Statement of Applicability<\/strong> (the critical-path deliverable).<\/li>\n<li><strong>Develop and localise the ISMS documentation set<\/strong> \u2014 policies, procedures and operating procedures \u2014 adopting from the Group where possible and creating what&#8217;s missing (~36 documents identified).<\/li>\n<li><strong>Close the prioritised gaps<\/strong> across the management-system clauses and all four Annex A domains, coordinating IT, Regional IT, HR, Legal, DPO, Procurement and Facilities.<\/li>\n<li><strong>Stand up the key processes<\/strong> \u2014 access governance \/ joiner-mover-leaver, incident management, tested disaster recovery and continuity, supplier security, and secure-development documentation for the in-house WMS.<\/li>\n<li><strong>Establish the assurance cycle<\/strong> \u2014 security metrics\/KPIs, the internal audit (with Group Internal Audit), and the management review.<\/li>\n<li><strong>Build the evidence base<\/strong> (~55 audit artefacts) so the ISMS is demonstrably operating.<\/li>\n<li><strong>Support tool selection and rollout<\/strong> \u2014 access-governance (IAM) and asset inventory\/CMDB.<\/li>\n<li><strong>Prepare for and support the certification audit<\/strong> (Stage 1 and Stage 2) with an accredited certification body.<\/li>\n<\/ul>\n<div><strong>What success looks like<\/strong><\/div>\n<div>A documented, operating ISMS with a signed-off SoA, a populated risk register, a completed internal audit and management review, and an evidence base that passes a Stage 2 certification audit for the agreed scope.<\/div>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[19],"tags":[276],"class_list":["post-31542","post","type-post","status-publish","format-standard","hentry","category-data-it","tag-informationssakerhetsspecialist"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ISO\/IEC 27001 Implementation Lead (interim \/ consultant) - POSTNORD GROUP - KeyMan<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/\" \/>\n<meta property=\"og:locale\" content=\"sv_SE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ISO\/IEC 27001 Implementation Lead (interim \/ consultant) - POSTNORD GROUP - KeyMan\" \/>\n<meta property=\"og:description\" content=\"Assignment: ISO\/IEC 27001 Implementation Lead (interim \/ consultant) \u2014 PostNord TPLReports to: CIO, PostNord TPLBackgroundPostNord TPL (third-party logistics) is pursuing its own ISO\/IEC 27001:2022 certification \u2014 including an in-house-developed warehouse management system (WMS) and warehouse operational technology (OT) (scope not decided). A full gap analysis of all 118 requirements is complete: the operational and technical security foundation is genuinely strong, but it is largely undocumented and unevidenced (the majority of controls are &quot;partially in place&quot;). The parent, PostNord Group, is already ISO 27001 certified, so much of the framework can be adopted or localised rather than built from scratch.The assignmentDrive and implement the remediation programme that turns the completed gap analysis into an implemented, evidenced, audit-ready ISMS. This is a hands-on delivery role, not an advisory one: the consultant builds artefacts, runs the programme, and coordinates the owning teams to close the gaps \u2014 working within PostNord TPL&#039;s phased strategy and alongside the Group&#039;s certified ISMS.Key responsibilitiesOwn and drive the ISO 27001:2022 implementation programme for TPL toward certification-readiness, reporting progress to the CIO and steering.Build the risk-management engine \u2014 establish the risk method (localising the Group&#039;s), populate and score the risk register with owners, and produce the Statement of Applicability (the critical-path deliverable).Develop and localise the ISMS documentation set \u2014 policies, procedures and operating procedures \u2014 adopting from the Group where possible and creating what&#039;s missing (~36 documents identified).Close the prioritised gaps across the management-system clauses and all four Annex A domains, coordinating IT, Regional IT, HR, Legal, DPO, Procurement and Facilities.Stand up the key processes \u2014 access governance \/ joiner-mover-leaver, incident management, tested disaster recovery and continuity, supplier security, and secure-development documentation for the in-house WMS.Establish the assurance cycle \u2014 security metrics\/KPIs, the internal audit (with Group Internal Audit), and the management review.Build the evidence base (~55 audit artefacts) so the ISMS is demonstrably operating.Support tool selection and rollout \u2014 access-governance (IAM) and asset inventory\/CMDB.Prepare for and support the certification audit (Stage 1 and Stage 2) with an accredited certification body.What success looks likeA documented, operating ISMS with a signed-off SoA, a populated risk register, a completed internal audit and management review, and an evidence base that passes a Stage 2 certification audit for the agreed scope.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/\" \/>\n<meta property=\"og:site_name\" content=\"KeyMan\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-14T22:00:00+00:00\" \/>\n<meta name=\"author\" content=\"Alexander\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@info@jlkonsult.com\" \/>\n<meta name=\"twitter:label1\" content=\"Skriven av\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alexander\" \/>\n\t<meta name=\"twitter:label2\" content=\"Ber\u00e4knad l\u00e4stid\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minuter\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/\"},\"author\":{\"name\":\"Alexander\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#\\\/schema\\\/person\\\/f7cf64356a2e8e8114c06c50c2fe9032\"},\"headline\":\"ISO\\\/IEC 27001 Implementation Lead (interim \\\/ consultant) &#8211; POSTNORD GROUP\",\"datePublished\":\"2026-09-14T22:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/\"},\"wordCount\":972,\"publisher\":{\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#organization\"},\"keywords\":[\"Informationss\u00e4kerhetsspecialist\"],\"articleSection\":[\"Data\\\/IT\"],\"inLanguage\":\"sv-SE\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/\",\"url\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/\",\"name\":\"ISO\\\/IEC 27001 Implementation Lead (interim \\\/ consultant) - POSTNORD GROUP - KeyMan\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#website\"},\"datePublished\":\"2026-09-14T22:00:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/#breadcrumb\"},\"inLanguage\":\"sv-SE\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/uncategorized\\\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ISO\\\/IEC 27001 Implementation Lead (interim \\\/ consultant) &#8211; POSTNORD GROUP\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#website\",\"url\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/\",\"name\":\"KeyMan\",\"description\":\"Sannolikt Sveriges b\u00e4sta konsultm\u00e4klare\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"sv-SE\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#organization\",\"name\":\"KeyMan\",\"url\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sv-SE\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/KeyMan-by-Werkey-dark-logo.svg\",\"contentUrl\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/KeyMan-by-Werkey-dark-logo.svg\",\"width\":201,\"height\":52,\"caption\":\"KeyMan\"},\"image\":{\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/#\\\/schema\\\/person\\\/f7cf64356a2e8e8114c06c50c2fe9032\",\"name\":\"Alexander\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sv-SE\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a550395a7d6b92f61698b6efb3fbeca470c0cef70d52e223a812a167c70c200?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a550395a7d6b92f61698b6efb3fbeca470c0cef70d52e223a812a167c70c200?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4a550395a7d6b92f61698b6efb3fbeca470c0cef70d52e223a812a167c70c200?s=96&d=mm&r=g\",\"caption\":\"Alexander\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/info@jlkonsult.com\"],\"url\":\"https:\\\/\\\/www.keyman.se\\\/sv\\\/author\\\/alexander\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ISO\/IEC 27001 Implementation Lead (interim \/ consultant) - POSTNORD GROUP - KeyMan","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/","og_locale":"sv_SE","og_type":"article","og_title":"ISO\/IEC 27001 Implementation Lead (interim \/ consultant) - POSTNORD GROUP - KeyMan","og_description":"Assignment: ISO\/IEC 27001 Implementation Lead (interim \/ consultant) \u2014 PostNord TPLReports to: CIO, PostNord TPLBackgroundPostNord TPL (third-party logistics) is pursuing its own ISO\/IEC 27001:2022 certification \u2014 including an in-house-developed warehouse management system (WMS) and warehouse operational technology (OT) (scope not decided). A full gap analysis of all 118 requirements is complete: the operational and technical security foundation is genuinely strong, but it is largely undocumented and unevidenced (the majority of controls are \"partially in place\"). The parent, PostNord Group, is already ISO 27001 certified, so much of the framework can be adopted or localised rather than built from scratch.The assignmentDrive and implement the remediation programme that turns the completed gap analysis into an implemented, evidenced, audit-ready ISMS. This is a hands-on delivery role, not an advisory one: the consultant builds artefacts, runs the programme, and coordinates the owning teams to close the gaps \u2014 working within PostNord TPL's phased strategy and alongside the Group's certified ISMS.Key responsibilitiesOwn and drive the ISO 27001:2022 implementation programme for TPL toward certification-readiness, reporting progress to the CIO and steering.Build the risk-management engine \u2014 establish the risk method (localising the Group's), populate and score the risk register with owners, and produce the Statement of Applicability (the critical-path deliverable).Develop and localise the ISMS documentation set \u2014 policies, procedures and operating procedures \u2014 adopting from the Group where possible and creating what's missing (~36 documents identified).Close the prioritised gaps across the management-system clauses and all four Annex A domains, coordinating IT, Regional IT, HR, Legal, DPO, Procurement and Facilities.Stand up the key processes \u2014 access governance \/ joiner-mover-leaver, incident management, tested disaster recovery and continuity, supplier security, and secure-development documentation for the in-house WMS.Establish the assurance cycle \u2014 security metrics\/KPIs, the internal audit (with Group Internal Audit), and the management review.Build the evidence base (~55 audit artefacts) so the ISMS is demonstrably operating.Support tool selection and rollout \u2014 access-governance (IAM) and asset inventory\/CMDB.Prepare for and support the certification audit (Stage 1 and Stage 2) with an accredited certification body.What success looks likeA documented, operating ISMS with a signed-off SoA, a populated risk register, a completed internal audit and management review, and an evidence base that passes a Stage 2 certification audit for the agreed scope.","og_url":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/","og_site_name":"KeyMan","article_published_time":"2026-09-14T22:00:00+00:00","author":"Alexander","twitter_card":"summary_large_image","twitter_creator":"@info@jlkonsult.com","twitter_misc":{"Skriven av":"Alexander","Ber\u00e4knad l\u00e4stid":"5 minuter"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/#article","isPartOf":{"@id":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/"},"author":{"name":"Alexander","@id":"https:\/\/www.keyman.se\/sv\/#\/schema\/person\/f7cf64356a2e8e8114c06c50c2fe9032"},"headline":"ISO\/IEC 27001 Implementation Lead (interim \/ consultant) &#8211; POSTNORD GROUP","datePublished":"2026-09-14T22:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/"},"wordCount":972,"publisher":{"@id":"https:\/\/www.keyman.se\/sv\/#organization"},"keywords":["Informationss\u00e4kerhetsspecialist"],"articleSection":["Data\/IT"],"inLanguage":"sv-SE"},{"@type":"WebPage","@id":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/","url":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/","name":"ISO\/IEC 27001 Implementation Lead (interim \/ consultant) - POSTNORD GROUP - KeyMan","isPartOf":{"@id":"https:\/\/www.keyman.se\/sv\/#website"},"datePublished":"2026-09-14T22:00:00+00:00","breadcrumb":{"@id":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/#breadcrumb"},"inLanguage":"sv-SE","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.keyman.se\/sv\/uncategorized\/iso-iec-27001-implementation-lead-interim-consultant-postnord-group-16323\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.keyman.se\/sv\/"},{"@type":"ListItem","position":2,"name":"ISO\/IEC 27001 Implementation Lead (interim \/ consultant) &#8211; POSTNORD GROUP"}]},{"@type":"WebSite","@id":"https:\/\/www.keyman.se\/sv\/#website","url":"https:\/\/www.keyman.se\/sv\/","name":"KeyMan","description":"Sannolikt Sveriges b\u00e4sta konsultm\u00e4klare","publisher":{"@id":"https:\/\/www.keyman.se\/sv\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.keyman.se\/sv\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"sv-SE"},{"@type":"Organization","@id":"https:\/\/www.keyman.se\/sv\/#organization","name":"KeyMan","url":"https:\/\/www.keyman.se\/sv\/","logo":{"@type":"ImageObject","inLanguage":"sv-SE","@id":"https:\/\/www.keyman.se\/sv\/#\/schema\/logo\/image\/","url":"https:\/\/www.keyman.se\/sv\/wp-content\/uploads\/2022\/12\/KeyMan-by-Werkey-dark-logo.svg","contentUrl":"https:\/\/www.keyman.se\/sv\/wp-content\/uploads\/2022\/12\/KeyMan-by-Werkey-dark-logo.svg","width":201,"height":52,"caption":"KeyMan"},"image":{"@id":"https:\/\/www.keyman.se\/sv\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.keyman.se\/sv\/#\/schema\/person\/f7cf64356a2e8e8114c06c50c2fe9032","name":"Alexander","image":{"@type":"ImageObject","inLanguage":"sv-SE","@id":"https:\/\/secure.gravatar.com\/avatar\/4a550395a7d6b92f61698b6efb3fbeca470c0cef70d52e223a812a167c70c200?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4a550395a7d6b92f61698b6efb3fbeca470c0cef70d52e223a812a167c70c200?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4a550395a7d6b92f61698b6efb3fbeca470c0cef70d52e223a812a167c70c200?s=96&d=mm&r=g","caption":"Alexander"},"sameAs":["https:\/\/x.com\/info@jlkonsult.com"],"url":"https:\/\/www.keyman.se\/sv\/author\/alexander\/"}]}},"_links":{"self":[{"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/posts\/31542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/comments?post=31542"}],"version-history":[{"count":0,"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/posts\/31542\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/media?parent=31542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/categories?post=31542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.keyman.se\/sv\/wp-json\/wp\/v2\/tags?post=31542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}