As cyber threats continue to evolve and organisations become increasingly dependent on digital services, a mature and well-structured approach to information security is essential. Protecting systems, data and business processes is therefore a key priority.
We are looking for an experienced Cybersecurity Expert who can help shape the organisation’s security strategy while also taking an active role in its implementation. You will contribute to the further development of the Information Security Management System (ISMS), support preparations for ISO 27001 certification and help ensure compliance with the requirements introduced by NIS2.
In this role, you report directly to the ICT Director and work closely with the Data Protection Officer. You act as one of the main points of contact for cybersecurity and information security across the organisation, collaborating with internal ICT teams, process owners and specialised external security providers.
This is an opportunity to join at an important stage in the organisation’s security maturity journey. Significant investments are being made in cybersecurity, supported by a dedicated budget, external expertise and an ongoing NIS2 programme. One of the main objectives is to achieve ISO 27001 certification by spring 2027. You will therefore have the opportunity to help establish and strengthen the foundations of a sustainable and mature security organisation.
Responsibilities
As Cybersecurity Expert, you will play a key role in developing, implementing and monitoring the organisation’s cybersecurity and information security framework. Your focus will be on reducing risk, embedding security requirements into the organisation and continuously improving its overall level of cyber resilience.
Your responsibilities will include:
- Managing and further developing the Information Security Management System (ISMS), including policies, processes, procedures, documentation and recurring review cycles.
- Supporting and coordinating the roadmap towards ISO 27001 certification.
- Identifying, assessing and monitoring cybersecurity and information security risks.
- Maintaining the organisation’s security risk register and providing periodic risk reporting to the relevant governance and management bodies.
- Ensuring alignment with applicable standards, frameworks and legislation, including ISO 27001, NIS2 and CyberFundamentals (CyFun).
- Preparing for and supporting internal and external security audits.
- Maintaining the Statement of Applicability and other security and audit documentation, ensuring that the organisation remains prepared for audits and assessments.
- Maintaining and improving the Incident Response Plan, coordinating security incidents and ensuring that reporting obligations, follow-up activities and remediation actions are handled correctly.
- Contributing to business continuity and disaster recovery initiatives, with particular attention to cybersecurity and information security requirements.
- Assessing cybersecurity risks related to suppliers and the wider supply chain and ensuring that critical third parties comply with agreed security requirements.
- Coordinating external security providers and following up on activities such as vulnerability management, patch management, security monitoring and identity & access management.
- Improving security awareness across the organisation through training, communication initiatives and awareness campaigns.
- Providing management and senior leadership with clear reporting on cybersecurity risks, incidents, KPIs and the progress of ongoing security initiatives.
Ideal profile
We are looking for an experienced cybersecurity professional who is comfortable working in an organisation where security processes and governance are continuing to evolve. You combine strong technical and security knowledge with a practical mindset and enjoy translating security requirements into concrete and workable solutions.
Ideally, you bring the following experience and capabilities:
- A Master's degree, preferably in IT, computer science, business administration or a related discipline, or equivalent professional experience.
- At least five years of relevant experience in cybersecurity, information security or IT risk management.
- Strong knowledge of recognised information security standards and regulatory frameworks, particularly ISO 27001, NIS2 and CyberFundamentals (CyFun).
- Hands-on experience with security risk management, compliance activities, audits and the implementation or management of an ISMS.
- A good understanding of modern IT environments, including infrastructure, cloud platforms, identity services and security technologies.
- Practical knowledge of areas such as security operations, vulnerability management, third-party risk management and incident management.
- Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer or ISO 27001 Lead Auditor are considered a strong advantage.
- Strong analytical capabilities and the ability to work in a structured and organised manner.
- The ability to translate complex security challenges into realistic recommendations, priorities and actions.
- Strong stakeholder management skills, allowing you to communicate effectively with technical specialists, operational teams, management and senior leadership.
- Previous experience in healthcare or in environments where sensitive or personal information requires a high level of protection is an advantage.
- Fluency in Dutch and a good professional command of English.