Oral Hammaslääkärit Oy

Cybersecurity Lead, Colosseum Dental Group

Oral Hammaslääkärit Oy Espoo, Uusimaa, Finland

Hospitals and Health Care · 1,001-5,000 employees

2 d ago
security Senior (5-10 yrs) Full-time Finland
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cybersecurity Lead is responsible for developing and maturing the group's cybersecurity strategy, governance, and risk management across 11 countries. They will also lead incident response efforts, manage security operations, and act as a trusted advisor to senior management.

What they look for

Cybersecurity strategy Risk management ISO 27001 NIST CSF Vulnerability management SentinelOne Microsoft security stack Entra ID Zero Trust Incident response NIS2 GDPR CIS Benchmarks Azure M365 Cybersecurity governance

Requirements

Candidates must have at least 5 years of hands-on cybersecurity experience, including 3 years in a senior or lead role. Proficiency in the Microsoft security stack, XDR solutions, and relevant cybersecurity frameworks like ISO 27001 or NIST CSF is required.

Benefits

Competitive compensation Professional development opportunities

Full description

We are hiring

Cybersecurity Lead

About Colosseum Dental Group

Colosseum Group is one of Europe’s leading multi-site healthcare services groups, operating across 11 countries with over 650 clinics and over 12’500+ colleagues.

Headquartered in Zurich and backed by a long-term family office investor, the group is in an exciting phase of growth, expansion via M&A and transformation.

The group has a strong presence in markets including the Nordics, Germany, and Switzerland, with a growing reputation for clinical excellence and patient-centric care, serving over 6 million patients a year.

The Role

As Cybersecurity lead, you are the owner of cybersecurity across the entire Colosseum Dental group. You set direction, manage risk, and are equally comfortable getting hands-on with the system to actively support our Country IT managers in execution, while representing Cybersecurity to our Board and Country senior management. You will report directly to the Group Director Technology & IT Operations and work alongside the Group CIO, country IT Managers and external partners.

What You Will Own

Cybersecurity Strategy & Governance

● Develop, own, and continuously mature the CDG cybersecurity strategy, aligned to the Colosseum strategy and the ISO 27001 / NIST CSF frameworks

● Define and enforce cybersecurity policies, standards, and baselines across all 11 operating countries

● Own the cybersecurity risk register; present risk posture and remediation roadmaps to the Group CFO, Group CIO and executive leadership

● Lead annual assessments, continuous penetration tests and manage any statutory or regulatory obligations (NIS2, GDPR cybersecurity provisions)

● Own the third-party / supplier cybersecurity assessment process for our technology vendors and SaaS solutions

Hands-On Cybersecurity Operations

● Run a structured vulnerability management programme

● Personally configure, tune, and audit cybersecurity controls across our Cybersecurity stack (SentinelOne, Microsoft security stack, Entra ID and more)

● Maintain and continuously improve secure baselines (CIS Benchmarks / Microsoft security Baselines) for Windows, Azure Landing Zones, and M365 tenants

● Drive Zero Trust adoption across identity, device, network, and data layers

Incident Response & Crisis Management

● Own and together with Country IT Management lead the IT incident response process end-to-end, from detection through containment, eradication, and post-incident review

● Maintain and test an up-to-date Incident Response Plan and Business Continuity provisions for cyber events

● Coordinate and supervise the external CDC partner; define SLAs, runbooks, review alert quality, and escalation thresholds

Culture & Enablement

● Build and sustain a cybersecurity-aware culture: design and run targeted awareness campaigns, phishing simulations, and role-based training

● Act as a trusted advisor to country CFOs and country IT Managers, making cybersecurity understandable and actionable

● Help grow the cybersecurity capability within the broader Group IT team to make cybersecurity a habit

What You Bring

Non-negotiable

● 5+ years of hands-on information- and cybersecurity experience, with 3+ years in a senior or lead role

● Technical expert in the Microsoft security stack (Defender, Azure, Entra ID, M365, etc.)

● Experience managing XDR solutions, preferably SentinelOne, in a large environment of 5,000+ users

● Knowledge of Zero Trust principles and practical implementation

● Led or co-led real cyber incident responses

● Proficient in cybersecurity frameworks and regulations like NIS2 directive, ISO 27001, NIST CSF or CIS Controls

Strongly preferred

● Experience in multi-country/multi-entity organisations, ideally with a distributed IT model

● Experience managing or overseeing a CDC relationship

● Background in healthcare, dental, or a regulated industry (advantageous but not required)

● Relevant and preferred certifications: SC-100 (Microsoft Cybersecurity Architect), SC-200, SC-300, SC-400, CISSP, CISM, or ISO 27001 Lead Implementer/Auditor

You as a person

● Hands-on, self-sufficient and a pragmatic risk thinker

● Practical approach in establishing robust controls rather than merely creating compliance frameworks

● Comfortable operating with ambiguity in a fast-scaling organisation

● Collaborative and direct to influence without authority across country IT teams

● Capable of clearly communicating risk to non-technical senior stakeholders

What We Offer

● A part in one of Europe’s leading and fastest-growing dental care groups

● An opportunity to grow and build a mature cybersecurity function across 11 countries and have an effect on the tooling we are going to use

● A modern technology environment with an appetite for cybersecurity investment

● Competitive compensation commensurate with seniority and market and opportunities for professional development

● A purpose-driven organisation: Our mission is to provide modern, quality dentistry services for the benefit of patients, dentists, colleagues and shareholders, striving for continuous growth and excellence

How to Apply?

Please submit your CV and a short cover letter describing your relevant experience and certifications. We review applications on a rolling basis and encourage early submissions.

For further information

Petteri Pasanen

Group Director, Technology & IT Operations

petteri.pasanen@colosseumdental.com

Any questions on your mind regarding the position or the process? Reach out to me anytime via email. Please note: we don't process any applications via email, all applications must be submitted through our recruitment portal.

Colosseum Dental Group is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Similar roles