Finst
Information Security Officer
NEWAmsterdamFull-timeGlobal
š Midš Hybrid
ActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will take ownership of the second-line information security, IT risk and compliance function. You will build, run and improve the ISMS, drive compliance with DORA, GDPR and other regulations, review first-line IT controls, support audits, perform vendor due diligence, and follow up on incidents and remediation plans.
Requirements
- ā3ā5 years of experience in information security, IT risk or compliance
- āSolid knowledge of DORA, GDPR and general information security principles
- āHands-on experience with setting up or managing an ISMS (ISO 27001)
- āTechnical background or experience with cloud infrastructure, CI/CD, SDLC, IAM or microservices
- āStrong understanding of risk management frameworks, controls and compliance processes
- āRelevant certification is a plus (e.g., ISO 27001 LA/LI, CISA, CISSP)
- āExperience coordinating audits and managing compliance documentation
- āExcellent communication skills and a proactive independent approach
Responsibilities
- āOwn and operate the second-line information security risk and compliance program
- āLead the setup and operation of the ISMS aligned with ISO 27001
- āDrive compliance efforts with DORA, GDPR, AI Act and other relevant regulations
- āReview and challenge first-line teams on IT security practices, policies and controls
- āDefine and maintain the IT risk management framework using best practices (e.g., ISO 27005, NIST)
- āMaintain IT compliance documentation, policies and processes
- āSchedule, manage and support internal and external audits
- āReview new tools and vendors and assist in software approval and due diligence
- āTrack incidents, non-conformities and risks and follow up with remediation plans
- āAct as an internal advisor on security and compliance best practices
Benefits & Perks
- āBonus scheme
- āShares incentive plan
- ā25 paid holidays per year
- āEquipment provided (MacBook, Windows, standing desks)
- āFlexible working hours
- āPossible partial remote work
- āMonthly team drinks
- āYearly company off-sites
Tech Stack
CDNISTDORArisk managementISMSISO 27001IAMCIcompliance documentationISO 27005