
Information Security Officer
Mendix
Information Security Officer
Mendix, part of Siemens Digital Industries Software, is seeking a proactive Information Security Officer in Rotterdam to protect information assets and strengthen compliance. The role involves control assessment, compliance monitoring, audit support, policy development, and fostering a security-first culture. Requires 3-5 years of experience in information security, IT audit, or compliance, plus an active security certification.
Information Security Officer
Mendix, part of Siemens Digital Industries Software, is seeking a proactive Information Security Officer in Rotterdam to protect information assets and strengthen compliance. The role involves control assessment, compliance monitoring, audit support, policy development, and fostering a security-first culture. Requires 3-5 years of experience in information security, IT audit, or compliance, plus an active security certification.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Assess the effectiveness of existing security controls against defined risks, and flag gaps or improvement areas.
- Monitor compliance against security frameworks and regulatory requirements (e.g., SOC 1 & 2, ISO 27001, NIST, C5, ISO 42001), conduct gap assessments against applicable laws, regulations, and internal frameworks, and report status and findings to relevant partners.
- Support internal and external audits by gathering, assessing, and providing vital evidence to demonstrate compliance.
- Handle collection, secure storage and archival of security evidence to ensure its integrity and availability for audits.
- Research, establish, and maintain information security policies, standards, and procedures tailored to specific organizational needs and emerging threats.
- Communicate security requirements, policy updates, and risk information clearly to relevant teams to support a security-conscious culture.
- Collaborate with applicable departments to ensure security controls are successfully implemented, maintained, and continuously optimized.