Information Security Officer (ISO)

Could you do the vital job of maintaining a high level of information security for us?

Martijn Sanders
  • Working week: 40 hours a week
  • Experience: At least 5 years' relevant work experience in a similar role
  • Education: Higher vocational working and reasoning ability
  • Mindset: A tactically astute and pragmatic security professional who is consistently ahead of the risks, translates policy into action and sees collaboration as the key to security.
  • Salary: € 4.040 - € 5.600 for a 40-hour week, depending on experience
How you'd explain your job at a party

I deal with information security, risk management, compliance (e.g. with ISO 27001 and soon SOC 2), working with technical teams to keep our security up to scratch.

Your role

As Information Security Officer (ISO) you’ll play a vital role within our organisation, a leading service provider in the internet sector and operator of the .nl domain. Because of our status as an essential service provider and critical infrastructure operator, information security is very important to us. You’ll work in the Security Services Department and report directly to our CISO.

In that setting, you’ll share responsibility for the further professionalisation of our information security and for raising our maturity level within the CMM (Capability Maturity Model). As well as maintaining our existing ISO 27001 certification, you’ll help us achieve SOC 2 certification.

Here's what you'll be doing:

Your focus will include tactical and operational aspects, supporting the CISO and taking over some of the CISO’s workload. You'll be working closely with all the teams within the organisation. Your main duties and responsibilities will include:

  • Policy development and management: In consultation with the CISO, you’ll adapt existing information security policies and define new policies, taking account of the latest developments and legal requirements. The policies you adapt and define will be subject to approval by the CISO.

  • Compliance and audits: You’ll monitor the effectiveness of security controls and ensure that they demonstrably meet the applicable internal and external requirements. In that context, you’ll work in close consultation with the control owners and the Compliance Officer. You’ll play an active role preparing for and guiding external audits (e.g. for ISO 27001, SOC 2).

  • Risk management: You’ll contribute to risk analyses and evaluations, and you’ll advise on appropriate action to mitigate the identified risks.

  • Technical advice and support: Working with the Technical Security Officers, you’ll advise the control owners about the implementation of security measures.

  • Penetration test coordination: You’ll coordinate and oversee periodic penetration tests, and you’ll ensure that the findings are followed up.

  • Awareness programme: You’ll contribute to the design and implementation of an effective awareness programme for all personnel, in order to reinforce the organisation’s security culture.

  • Legal compliance: You’ll ensure that our information security always complies with all relevant legislation and regulations, including the GDPR, NIS2 and CBW.

  • Project support: You’ll make an active contribution to the security-related aspects of projects, such as the outsourcing of primary and secondary triage in the SOC.

Your skills

Our core values of customer focus, trustworthiness, innovation, independence and professionalism strike a chord with you. And you want to keep learning and developing. If that sounds like you, you'll fit right in! Because we allow people to be themselves.

You'll also have:

  • At least a higher vocational qualification in a relevant field (e.g. informatics, technical business management, cybersecurity)

  • At least 5 years' relevant work experience in a similar role, preferably within an organisation responsible for critical infrastructure or in the internet industry

  • Preferably a CISM or CISSP qualification; otherwise we will support you in acquiring such a qualification

  • Good knowledge of cloud security, identity & access management (IAM) issues and understanding of network protocols and the OSI model

  • Demonstrable experience of realising and maintaining ISO 27001 compliance, and preferably knowledge of SOC 2 and other relevant frameworks

  • Up-to-date knowledge of the GDPR, NIS2 and CBW (essential)

  • Knowledge and experience of project management

  • At least B1 and preferably B2 level of Dutch.

We’re looking for a proactive, stress-resistant professional with excellent communicative and advisory skills. You’ll be able to communicate with and persuade people at various levels, from executives to technical team members. You’ll have strong analytical ability and you’ll be organisationally strong, enabling you to tackle complex issues effectively and see projects through to a successful conclusion. It's important that you live in the Netherlands.

We are SIDN

The internet. The biggest and most successful global collaboration of all time. Once something new and spellbinding, it's now an integral part of everyday life for almost everyone in the Netherlands. As a result, many people take the internet for granted. But, for us, the wonder remains.

We are SIDN. We began as internet pioneers, and forged an identity as digital thinkers and doers, shaping the reality of today and tomorrow. We have a strong sense of shared responsibility for the internet in the Netherlands. A responsibility that we willingly accept. A responsibility that we work to fulfil, every hour of every day. We bring people together by operating a .nl domain that's secure and technically reliable. And, because the internet is a highly dynamic environment, we are constantly anticipating what's required and adapting our services to match.

In a world of opportunities and challenges, we're dedicated to enabling confidence online. We're a small organisation with big ambitions. Our highly motivated professionals are passionate about their work, and proud of the difference they make and the people they work with. Together, we're always reaching for the heights. How about you?

Read more about SIDN

What you can expect

For us, it's all about balance. Balance between hard work and relaxation, between performance and reward, between your ambitions and ours, between an inspiring office environment and the convenience of working from home, and of course between professional and private life. We utilise the latest technologies for easy collaboration, remotely, physically and in hybrid forms. We also make sure that our people have well-equipped home workstations, plus access to an office space with everything they need to get together, collaborate and inspire each another. If you want to go running or visit granny during office hours, we're okay with that. As long as you live up to your professional responsibilities, we'll work out between us exactly how and when you do your work. And we're not fans of formal appraisal. What really matters is year-round personal development. Where you take the lead. Helping us to consolidate our status as a major, unique player in the internet technology sector.

Pay and other benefits

What’s in it for you? First, ample opportunity for growth and skills development. After all, you'll be helping us take our IT set-up in a whole new direction. On-the-job growth will go hand-in-hand with training-based personal development -- for which we have a generous budget! There's an attractive benefits package as well:

  • Gross monthly salary of up to €5,600, depending on professional experience

  • Holiday pay of 8 per cent, plus a thirteenth salary payment

  • A variable collective bonus of up to 4 per cent

  • An attractive extra bonus if you introduce us to a new colleague

  • A basic holiday allowance of 25 days, plus scope for building up to 13 days' occasional leave entitlement, if you work full time

  • A pension with ABP, with an 80 per cent contribution from SIDN

  • A business rail card if you come to work by public transport

  • A travel allowance if you come to work using your own transport

  • A PluralSight licence and the opportunity to acquire other certificates

  • A daily home working allowance for every day that you work from home

  • A complete, healthy home workstation

  • €55 a month (net) for your home broadband

  • €25 a month (gross) contribution to your health insurance

  • Additional paternity leave on full pay

  • An optional cycle lease scheme, where SIDN covers 50 per cent of the lease cost, up to a maximum of €60 (gross) per month

  • €500 a year to donate to a good cause of your choice

  • Your own .nl domain name and hosting package

  • Professional coaching and budget coaching

  • A relocation allowance if taking the job means moving house

Everything above is for a full-time role (40-hour week).

The selection procedure includes screening, which involves obtaining a Certificate of Good Behaviour (similar to a criminal record check), and performing reference and integrity checks.

Like the sound of this job? Let's connect!

If you've read this far, we reckon you should definitely get in touch. We'd love to hear what you can bring to the table, and see whether you're right for our team. Drop us a line or give us a call!

About the application process:

Inge Loeff

Corporate recruiter

Contact

Ferry Stelte

Chief Information Security Officer (CISO)

Apply directly

This form needs javascript to work. Please enable javascript to continue.

Fields with * are required.

The form is being sent. Please wait.
Oops! Unfortunately something went wrong while submitting your application. Please try again or contact our corporate recruiter, on recruitment@sidn.nl.
Thank you for your interest in SIDN. We have received your application safely and will be in touch within 3 business days to update you on the appointment process. If you have any questions regarding your application, please contact our corporate recruiter, on recruitment@sidn.nl.
There is no application form for this position

What happens once I've applied?

  • Application

  • First interview

  • Second interview

  • Contract offer

  • Start your dream job