Back to all jobs
Visible on IKONS todayNewPopular
CISO
GelderlandHybrid36 hours/week3-6months
The assignment includes, in addition to regular CISO tasks, an important quartermaster role for approximately 50% of the hours.
- Objectives of the quartermaster role are to standardize the task definition and positioning of the CISO in two government organizations, and to further professionalize and harmonize the information security organization.
- Based on the findings in the first 2 months of the quartermaster phase, an advice is requested on the CISO to be recruited for the long term.
What you will do.
- Advise on the structural implementation (task package and positioning) of the CISO role, including personality type, required skills, and competencies.
- Simultaneously advise on the standardization and professionalization of the information security organization in two organizations, ensuring organizational and administrative support.
- After decision-making, ensure the implementation of advice to achieve a uniform and professionalized information security organization(s).
- Develop a single strategic roadmap for information security in both organizations, in line with the Cybersecurity Act and the BIO2 standard framework.
- Realize and further develop a PDCA cycle.
- Prepare administrators for their role under the Cybersecurity Act.
- Set up administrative reporting and involve administrators in risk assessment and mitigation (Art. 24 Cbw).
- Where necessary, guide the realization and implementation of a business continuity policy (BCM), or advise on and supervise its execution.
- Regularly organize (joint) consultations with colleagues in the information security discipline (ISOs, Privacy Officers, Data Protection Officer).
What they ask
- Demonstrably completed education at a minimum of HBO bachelor level.
- Demonstrably completed additional courses CISSP, CISM or directly comparable.
- Minimum of 5 years demonstrable work experience in the past 7 years at a strategic level within information security.
- Demonstrably willing to be physically present on location at the client for at least 1 day.
Preferences.
- Demonstrable knowledge of the Cybersecurity Act (Cbw/NIS2), BIO2, its predecessors, and related legislation and regulations (e.g., AVG, Archiefwet).
- Demonstrable work experience with setting up processes around risk management, supplier management, and incident management.
- Demonstrable work experience with setting up and/or further developing governance and risk management structures.
- Demonstrable work experience with creating support for uniform decision-making within multiple organizations.
- Demonstrable work experience with connecting and collaborating with colleagues within information security.
Profile
- Administrative sensitivity: ability to translate technical risks into administrative language and create support among the board and management without formal enforcement power.
- Persuasiveness: ability to translate technical risks into administrative language and create support among the board and management without formal enforcement power.
- Connecting ability between organizations: able to bridge (cultural) differences between two organizations and set shared priorities to implement uniform policy in both organizations.
- Analytical ability: able to weigh complex, incomplete information and come to a substantiated judgment and advise on it.
- Judgment: able to weigh complex, incomplete information and come to a substantiated judgment and advise on it.
- Change capacity: able to bring about behavioral and organizational change with the aim of embedding it in the organization's culture.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.