As Information Security Officer (ISO) you’ll play a vital role within our organisation, a leading service provider in the internet sector and operator of the .nl domain. Because of our status as an essential service provider and critical infrastructure operator, information security is very important to us. You’ll work in the Security Services Department and report directly to our CISO.
In that setting, you’ll share responsibility for the further professionalisation of our information security and for raising our maturity level within the CMM (Capability Maturity Model). As well as maintaining our existing ISO 27001 certification, you’ll help us achieve SOC 2 certification.
Here's what you'll be doing:
Your focus will include tactical and operational aspects, supporting the CISO and taking over some of the CISO’s workload. You'll be working closely with all the teams within the organisation. Your main duties and responsibilities will include:
Policy development and management: In consultation with the CISO, you’ll adapt existing information security policies and define new policies, taking account of the latest developments and legal requirements. The policies you adapt and define will be subject to approval by the CISO.
Compliance and audits: You’ll monitor the effectiveness of security controls and ensure that they demonstrably meet the applicable internal and external requirements. In that context, you’ll work in close consultation with the control owners and the Compliance Officer. You’ll play an active role preparing for and guiding external audits (e.g. for ISO 27001, SOC 2).
Risk management: You’ll contribute to risk analyses and evaluations, and you’ll advise on appropriate action to mitigate the identified risks.
Technical advice and support: Working with the Technical Security Officers, you’ll advise the control owners about the implementation of security measures.
Penetration test coordination: You’ll coordinate and oversee periodic penetration tests, and you’ll ensure that the findings are followed up.
Awareness programme: You’ll contribute to the design and implementation of an effective awareness programme for all personnel, in order to reinforce the organisation’s security culture.
Legal compliance: You’ll ensure that our information security always complies with all relevant legislation and regulations, including the GDPR, NIS2 and CBW.
Project support: You’ll make an active contribution to the security-related aspects of projects, such as the outsourcing of primary and secondary triage in the SOC.