The person who runs ICT infrastructure and the person who independently tests whether ICT controls are working need to be different people. In this role, you own the ISMS, carry ISO 27001 and DORA compliance forward, and serve as the independent challenge function for all ICT risk at Blockrise
You will have direct access to the Board and to regulatory conversations. You are building the function with the right structural independence behind it.
What you'll do
Own the ISMS. Maintain and develop Blockrise’s Information Security Management System,keeping it current as the business scales and the regulatory environment evolves.
Drive ISO 27001 certification. Manage ongoing compliance and audit readiness. Own the relationship with our external auditor and certification body.
Implement DORA.Translate Articles 5-15 (ICT riskmanagement), 23-25 (incident reporting),and 28-30 (third-party risk) into operational controls, documented evidence, and testing cycles.
Define and enforce security policy. Own the policy framework across the organisation. Policies need to hold up under audit and in an actual incident.
Oversee vulnerability management and penetration testing. Work with our IT team and external parties to ensure findings are tracked, prioritized, and remediated.
Lead security incident response. Own the process from preparation through detection, containment, and regulatory reporting where .
Manage third-party and cloud security risk. Assess and oversee the security posture of our GCP environment and critical outsourced service providers.
Act as second-line challenge. Independently review, test, and verify that first-line ICT controls are operating as intended. Report findings without a filter.
Report to the Board and regulators.Translate technical risk into plain business language. Represent security at senior and regulatory level.
Keep the tooling stack current. Keep ICT Risk Management systems, and end point protection current. Identify gaps and propose solutions.
What you bring
WHAT YOU BRING
5 or more years in information security, with at least 2 years holding ISMS ownership or equivalent scope.
Hands-on experience implementing or maintaining ISO 27001 certification. You wereactivelyinvolvedin running the programme, not supported it from the side.
Solid working knowledge of DORA, specifically Articles 5-15, 23-25, and 28-30, with experience translating regulatory requirements into controls.
Experience across vulnerability management, penetration testing oversight, and security incident response.
A track record of defining and enforcing security policies. You pushed back when business units wanted exceptions, and you had the authority to do it.
Cloud security experience: GCP preferred; AWS or Azure acceptable.
Familiarity with SIEM, vulnerability scanners, and endpoint protection; direct experience with Vanta and/or anotherICT Risk Management Systemis a plus.
A clear understanding of the three lines of defence model. You know what genuine second-line independence requires and can explain why it matters to a CTO who currently holds both functions.
Ability to communicate security risk in business terms to a Board and regulators. Comfort with both the numbers and the regulatory language.
Strong written and spoken English. Dutch is a plus.
CISSP, CISM, or ISO 27001 Lead Implementer/Auditor (preferred). CRISC is a bonus.
Nice to have
Experience in financial services or in Bitcoin and digital asset businesses.
Working knowledge of MiCAR and its operational resilience implications.
Experience with regulatory audits run by DNB, AFM, or equivalent authorities.
Third-party risk management in outsourced or cloud-first environments, particularly for critical service providers.
What we offer
Competitive monthly salary EUR 6.500 - 8.500 based on full-time employment depending on your experience.
Up to EUR 300 to invest in tools that improve your workflow (headphones, keyboards, etc.)
Monthly Bitcoin pension of EUR 50
25 vacation days
Option to participation in our share certificate program
Travel reimbursement or NS Business Card for your commute
Opportunities for hybrid work, though in-person collaboration is highly valued
Paid training and learning resources to keep your skills sharp and up to date
A fully stocked pantry and fridge at the office, with meals, snacks, and drinks included
Discounted access to Urban Sports Club and LeaseBike plans
Contact Us
To apply, please fill in the form below. For questions about the job opening, your application, or Blockrise, please contact[email protected].
We expect to get back to you within one week. We consider every application regardless of your background and beliefs. After an introduction, an assignment may be part of the application process. Please note that by submitting your application, Blockrise (in accordance with our Privacy Policy) obtains permission to request, store, and process your application data for the purpose of considering employment. We will delete your application data within 30 days when your application is no longer under consideration.
Unsolicited recruitment We do not accept unsolicited CVs from recruiters or employment agencies. We will not consider or agree to payment of any referral compensation or recruiter fee relating to unsolicited CVs.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Netherlands.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Netherlands, connecting you to thousands of jobs fast!
Find the best jobs in Netherlands, apply in 1 click and get a job today!