Job Description - Head of Information Security, Netherlands
Description
About Us:
Ant International powers the future of global commerce with digital innovation for everyone and every business to thrive. In close collaboration with partners, we support merchants of all sizes worldwide to realize their growth aspirations through a comprehensive range of tech-driven digital payment and financial services solutions.
With a focus on Travel, Trade, Technology, and Talent, Ant International is committed to enhancing the digital mindset and capacities of businesses worldwide. Through fostering collaborative efforts with partners, we are driving responsible innovation and increase market accessibility for global SMEs.
We do so across our 4 key businesses: Alipay+, Antom, WorldFirst and ANEXT Bank.
What you will be doing:
1. Governance & Strategy
Develop, maintain, and oversee the Information Security and ICT Risk Management Frameworks in line with DORA, ISO 27001, NIST, and other applicable standards.
Establish, maintain, and enforce security policies, standards, and procedures.
Provide independent second-line challenge to first-line controls and risk management activities.
Report on security posture to the Board and leadership team.
2. Regulatory Compliance & Engagement
Ensure full compliance with DORA (ICT risk management, incident reporting, resilience testing, third-party risk), PSD2-SCA, PCI-DSS, SWIFT CSP, GDPR (as it relates to ICT), and EBA guidelines.
Act as the primary liaison for DNB, EBA, and other regulators; manage regulatory inquiries, audits, inspections, and reporting obligations.
3. Incident & Access Management
Own and manage end-to-end response to security incidents and data breaches, including coordination, escalation, investigation, containment, and regulatory reporting in line with DORA and GDPR.
Oversee access control governance, including user provisioning, privileged access, and periodic access reviews.
Manage KMS and (CBD) security practices in accordance with internal policies and regulatory expectations.
4. Third-Party & Outsourced Security Oversight
Maintain ownership of all outsourced security activities (e.g., SOC, penetration testing providers), ensuring service quality, SLA adherence, and alignment with security and compliance requirements.
Manage the ICT third-party risk lifecycle, including due diligence, ongoing monitoring, and maintenance of the DORA register of critical ICT third-party providers.
5. Risk, Resilience & Assurance
Identify, assess, prioritise, and report ICT and cyber risks; define key risk indicators and present risk posture to the Board and Risk Committees.
Oversee digital operational resilience testing (including threat-led penetration testing) and disaster recovery from an ICT perspective.
Monitor the governance and technical effectiveness of cybersecurity controls (SIEM, EDR, DLP, IAM, vulnerability management, and data security) and track remediation of audit and assessment findings.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!