Back to all jobs
Visible on IKONS todayNewPopular
Security & Privacy Officer
LimburgHybrid36.1 hours/week<3months
A digitally resilient organization, with secure and privacy-conscious ICT services for education, research, and operations.
- As a Local Information Security Officer and Local Privacy Officer (LISO/LPO), you are the point of contact within the ICT department for information security, privacy, and cyber resilience.
- You translate policy, legislation, and risks into workable technical and organizational measures.
- Together with fellow LISO/LPOs and the central CISO team, you contribute to the development and safeguarding of the information security management system.
- Close collaboration with professionals from the Security Operations Centre.
- Content-driven sparring partner, coaching colleagues in their professional development, and stimulating collaboration and knowledge sharing.
- Contributing to the further professionalization of monitoring, detection, incident response, and threat management.
- The strength of the role lies in connecting policy, risks, and daily security practice.
- Translating findings from the SOC into structural improvements.
- Ensuring that policies, risk analyses, and compliance requirements are implemented in daily ICT practice.
What you do
- Develop information security and privacy policies for the ICT department, aligned with central policies.
- Advise management, Product Owners, and technical colleagues on their application and on secure, privacy-conscious ICT services.
- Guide risk analyses and system classifications, ensuring risks are identified and registered in central GRC tooling.
- Contribute to the safeguarding of security, privacy, and compliance within the information security management system.
- Support audits, DPIAs/DTIAs, and security- and privacy-by-design.
- Work closely with the Security Operations Centre on the further professionalization of monitoring, detection, incident response, and threat management, bringing substantive sharpness and overview.
- Coach SOC professionals in their professional development and encourage collaboration and knowledge sharing.
- Translate threats, incidents, and findings from security operations into priorities and structural improvements in policies and measures.
- Report to the management of the ICT department and the CISO on agreed KPIs and the progress of improvement measures.
- Report on operational security practice in collaboration with the SOC.
- Work closely with, among others, the CTO, CISO, CPO, CERT, and fellow LISO/LPOs, contributing to crisis management and the digital resilience of the organization.
What they ask
- Experienced security officer who easily switches between policy, technology, and organization.
- Understands both governance, risk & compliance and security operations.
- A firm and accessible discussion partner for management and technical colleagues.
- Knows when to be flexible and when critical questioning is needed, while keeping an eye on the interests of education, research, and operations.
- Can substantively challenge and support SOC professionals, allowing for their expertise.
- Translates technical findings into risks and administrative issues, and policies and risks into daily security practice.
- HBO or WO (higher professional education or university) working and thinking level, a relevant education, and at least three years of relevant work experience in information security.
- Knowledge of information security and risk management processes and experience with ISO 27001/27002 or similar frameworks.
- Knowledge of relevant laws and regulations, including AVG (GDPR) and Cyberbeveiligingswet/NIS2, and translating them into ICT practice.
- Knowledge of information security and privacy issues related to cloud applications.
- Communication in Dutch at a minimum B1 level and in English at a minimum C1 level.
- Sensitivity to administrative and organizational relationships.
- Brings disciplines and interests together and creates support for measures and improvements.
- Plus: additional certification, such as CISM, CISSP, CIPP/E or ECPC-B DPO.
- Plus: experience in providing training and information.
Practical
- International, open, and engaged work environment.
- Flexible working hours, home office allowance, and hybrid working.
- Freedom and space to organize your work independently and develop your own ideas.
- A close-knit community of colleagues.
- Good pension scheme, company fitness, and access to an extensive sports program.
- An inspiring work environment.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.