Nijmegen
2 weeks ago
Information Security Officer logo

Information Security Officer

ScreenPoint Medical

Information Security Officer

ScreenPoint Medical, The Breast AI Company, seeks an Organizational Information Security Officer to lead and mature its information security program. The role focuses on ISO 27001 and SOC 2, working with cross-functional teams to embed security into operations, including AI-native governance. Requires strong knowledge of ISO 27001/SOC 2, risk management, and security architecture.

HybridFull-timeMid LevelISO 27001SOC 2

Salary

Not specified

Work Location

Nijmegen, Gelderland, Netherlands, NL

Work Model

Hybrid

Employment Type

Full-time

Experience Level

Associate

Core Qualifications

Technical (Must-have)
ISO 27001SOC 2Risk ManagementPolicy DevelopmentControl DesignControl TestingRemediation TrackingIAMCloud SecurityEndpoint SecurityLogging and MonitoringVulnerability ManagementEncryptionBackup/RecoveryIncident Response
Soft Skills
Stakeholder ManagementInfluenceCommunicationStrategic ThinkingProactiveIndependentTrust Building

Preferred Qualifications

Technical (Nice-to-have)
ISO 13485ISO 9001NIST CSFCIS ControlsISO 27017ISO 27018CISSPCISMCCSPISO 27001 Lead ImplementerISO 27001 Lead Auditor

Key Responsibilities

  • Own, maintain, and continuously improve the ISMS, including governance processes, documentation, security objectives, management reviews, KPIs, and an organization-wide roadmap aligned with business goals and the QMS.
  • Lead the implementation, operation, and continuous improvement of the security control environment for ISO 27001 and SOC 2, maintaining the control set, clarifying control ownership, defining operating cadences, collecting evidence, supporting audits, and tracking remediation.
  • Build and operate a pragmatic security governance model, including policies, standards, risk assessments, risk treatment plans, exception handling, and leadership reporting.
  • Partner with Infrastructure and Engineering to strengthen secure foundations across IAM, endpoint security, cloud security, logging and monitoring, encryption, backup and recovery, and vulnerability management.
  • Own incident response planning and coordination, including playbooks, tabletop exercises, escalation paths, communication plans, and post-incident reviews.
  • Establish and run a vendor risk management process, including supplier security reviews, contract/security requirement input, risk-based monitoring, and follow-up for critical suppliers.
  • Build a security-first culture through practical training, clear guidance, and stakeholder enablement, acting as the primary point of contact for security inquiries, customer assurance requests, audits, and security-related decision-making.
  • Support ScreenPoint's transition into an AI-native organization by helping define practical security principles for the responsible use of AI tools, data, automation, and emerging technologies.
Information SecurityISO 27001SOC 2MedTechAIHybridFull-timeNijmegen