
Technical Information Security Officer (T-ISO) & Incident Response Officer
Grant Thornton Netherlands
Technical Information Security Officer (T-ISO) & Incident Response Officer
Grant Thornton is seeking a Technical Information Security Officer (T-ISO) & Incident Response Officer to join its CISO Office. The role involves translating security policy into technical baselines, reviewing architecture and changes, assessing technical security risks, and coordinating incident response. Candidates need strong technical security expertise, governance insight, and communication skills in Dutch and English.
Technical Information Security Officer (T-ISO) & Incident Response Officer
Grant Thornton is seeking a Technical Information Security Officer (T-ISO) & Incident Response Officer to join its CISO Office. The role involves translating security policy into technical baselines, reviewing architecture and changes, assessing technical security risks, and coordinating incident response. Candidates need strong technical security expertise, governance insight, and communication skills in Dutch and English.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Translate cybersecurity policies, controls and risk decisions into technical standards, baselines, acceptance criteria and practical guidance across domains such as identity, cloud, endpoint, network, platform security, secure change and hardening.
- Review security architecture, solution designs, technology choices, changes and releases for security-by-design, risk exposure and alignment with Grant Thornton’s security requirements.
- Provide independent second-line challenge and advice to I&A, architects, engineers and project teams, while maintaining a clear boundary between oversight and execution.
- Maintain a sharp distinction from I&A and engineering: you do not structurally implement, configure or operate technical controls; I&A remains accountable for technical delivery.
- Govern vulnerability, threat, logging, monitoring and detection activities by assessing coverage, prioritisation, remediation, exceptions, retesting, penetration-test planning, findings, remediation evidence and follow-up, and escalation of material risks.
- Coordinate the security response during major cyber incidents, including severity assessment, stakeholder coordination, evidence governance, timelines, decision logs, chain of custody, root-cause analysis, lessons learned and follow-up actions.
- Develop and maintain incident-response playbooks, severity models, tabletop exercises and improvement actions that strengthen Grant Thornton’s incident readiness.
- Report technical security exposure, incidents, remediation progress, exceptions and key risks to the CISO and relevant stakeholders in a clear and decision-oriented way.
- Ensure your work results in clear technical requirements, visible risk exposure, timely escalation, stronger incident readiness and evidence-based follow-up on remediation.