Job Description - Information Security Officer (ISO)
As an Information Security Officer, you are part of the Information Security & Privacy (IB&P) department, consisting of the CISO, ISOs, Privacy Officers and the Data Protection Officer. You will be responsible for strengthening the risk management process, further developing the Information Security Management System (ISMS) and implementing information security measures within the organization.
You advise management and employees on information security, compliance and risk management. In addition, you will play an important role in the implementation of BIO2 and NIS2, supplier management, asset management and performing risk analyses and audits.
Tasks and responsibilities
Developing, updating and monitoring information security policies, frameworks and procedures
Directing the risk management process
Identifying, analyzing and monitoring risks
Assigning risks to process owners and management
Monitoring mitigating measures via GRC tooling and ISMS
Setting up and managing asset registers including IoT applications
Integrating assets into the risk management process
Performing supplier assessments and supply chain risk analyses
Testing contractual security requirements
Implementing BIO2 and NIS2 measures
Support with DPIAs, risk analyses and security assessments
Preparation of advisory reports
Further development and management of the Information Security Management System (ISMS)
Performing Business Impact Analyses (BIAs)
Translating BIA results into control measures
Supporting ENSIA audits and other compliance audits
Ensuring correct file formation and evidence
Representing information security within projects and consultations
Advising management and colleagues on information security and risk management
Organizing awareness campaigns, training and communication activities
Requirements
Completed HBO or WO education in, for example, information management, cybersecurity, law or (technical) business administration
At least 3 years of experience as an Information Security Officer within a municipality, province or other government organization
Up -to -date knowledge of information security, governance and risk management
Knowledge of BIO2
Knowledge of the Cybersecurity Act (NIS2)
Experience in setting up and implementing risk management processes
Experience with risk identification, analysis and monitoring
Experience with supplier management and supply chain risks
Knowledge of contractual security requirements
Affinity with asset management and IoT security
Excellent command of the Dutch language verbally and in writing
Reference from a recent relevant client
Advantages
Certification CISM
CISSP Certification
CRISC Certification
Experience with GRC tooling
Experience with ISMS implementations
Experience with ENSIA audits
Experience within municipal organizations
Experience with Business Impact Analyses (BIAs)
Experience with information security awareness programs
Competencies
Proactive
Result -oriented
Analytically strong
Risk -aware
Persuasiveness
Administrative sensitivity
Organizationally aware
Connecting capacity
Flexible
Pragmatic
Strong verbal communication skills
Strong written communication skills
Able to switch strategically, tactically and operationally
Strong in stakeholder management
Vision combined with execution power
Ability to create ownership within the organization
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Netherlands.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Netherlands, connecting you to thousands of jobs fast!
Find the best jobs in Netherlands, apply in 1 click and get a job today!