Rotterdam
1 week ago
Information Security Officer logo

Information Security Officer

Mendix

Information Security Officer

Mendix, part of Siemens Digital Industries Software, is seeking a proactive Information Security Officer in Rotterdam to protect information assets and strengthen compliance. The role involves control assessment, compliance monitoring, audit support, policy development, and fostering a security-first culture. Requires 3-5 years of experience in information security, IT audit, or compliance, plus an active security certification.

HybridFull-timeMid LevelInformation SecurityIT Audit

Salary

Not specified

Work Location

Rotterdam, South Holland, Netherlands, NL

Work Model

Hybrid by default, built on trust and autonomy

Experience Required

5 years

Employment Type

Full-time

Experience Level

3-5 years of dynamic experience in an Information Security, IT Audit, or Compliance role

Core Qualifications

Technical (Must-have)
Information SecurityIT AuditComplianceCloud SecurityAWSAzureGCPISO/IEC 27001GDPRSOC 2NISTC5ISO 42001SDLCCISMCISSPISO 27001 Lead ImplementerCompTIA Security+
Soft Skills
Analytical ThinkingProblem-solvingCommunicationInitiativeSelf-directionTeam playerCollaboration

Preferred Qualifications

Technical (Nice-to-have)
Cloud security tools

Key Responsibilities

  • Assess the effectiveness of existing security controls against defined risks, and flag gaps or improvement areas.
  • Monitor compliance against security frameworks and regulatory requirements (e.g., SOC 1 & 2, ISO 27001, NIST, C5, ISO 42001), conduct gap assessments against applicable laws, regulations, and internal frameworks, and report status and findings to relevant partners.
  • Support internal and external audits by gathering, assessing, and providing vital evidence to demonstrate compliance.
  • Handle collection, secure storage and archival of security evidence to ensure its integrity and availability for audits.
  • Research, establish, and maintain information security policies, standards, and procedures tailored to specific organizational needs and emerging threats.
  • Communicate security requirements, policy updates, and risk information clearly to relevant teams to support a security-conscious culture.
  • Collaborate with applicable departments to ensure security controls are successfully implemented, maintained, and continuously optimized.
Information SecurityComplianceIT AuditCloud SecuritySoftware DevelopmentHybridRotterdamFull-time