Amsterdam
1 week ago

Information Security Officer
Nmbrs
Amsterdam
1 week ago
Information Security Officer
Nmbrs is looking for a Senior Information Security Officer to join their Amsterdam office. The role involves owning the security posture end to end, including ISMS, ISO 27001, risk assessments, incident response, and compliance. The ideal candidate has broad security experience, a relevant degree, and a recognized security credential.
HybridFull-timeSeniorISO 27001ISAE3402
Information Security Officer
Nmbrs is looking for a Senior Information Security Officer to join their Amsterdam office. The role involves owning the security posture end to end, including ISMS, ISO 27001, risk assessments, incident response, and compliance. The ideal candidate has broad security experience, a relevant degree, and a recognized security credential.
HybridFull-timeSeniorISO 27001
Salary
Not specified
Core Qualifications
Technical (Must-have)
ISO 27001ISAE3402NIS2GDPRCISSPCISMCloud SecurityFirewallsVulnerability ManagementRisk AssessmentIncident ResponseSecurity ArchitectureAccess ManagementAuditCompliance
Soft Skills
CommunicationSecurity AwarenessCollaboration
Preferred Qualifications
Technical (Nice-to-have)
Dutch
Key Responsibilities
- Own the ISMS, keep the ISO 27001 certification and ISAE3402 audit current, ensure compliance with the Visma Security Program and track regulatory drivers such as NIS2 and GDPR.
- Develop and maintain security policies and standards, run risk assessments, and verify that control measures are effective.
- Help shape security architecture and access management approach, and ensure security is considered early in software development.
- Plan audits, coordinate evidence collection, act as main contact for auditors, and follow up on findings.
- Stay hands-on with firewalls, cloud security and system logs, and drive vulnerability management.
- Investigate and mitigate security incidents and data breaches, and turn lessons learned into improvements.
- Set guidelines for safe computer, network and AI use, build a security-aware culture, and be the go-to person for security questions.
- Assess the security of vendors and new tools before onboarding, and answer customer security questionnaires.
- Translate technical risks and threat trends into language non-technical colleagues and leadership can act on.
Information SecurityISO 27001ComplianceCloud SecuritySaaSHybridFull-timeSeniorAmsterdam