
Information Security Officer (ISO)
Key Skills
Job Description
- Developing, updating and monitoring information security policies, frameworks and procedures
- Directing the risk management process
- Identifying, analyzing and monitoring risks
- Assigning risks to process owners and management
- Monitoring mitigating measures via GRC tooling and ISMS
- Setting up and managing asset registers including IoT applications
- Integrating assets into the risk management process
- Performing supplier assessments and supply chain risk analyses
- Testing contractual security requirements
- Implementing BIO2 and NIS2 measures
- Support with DPIAs, risk analyses and security assessments
- Preparation of advisory reports
- Further development and management of the Information Security Management System (ISMS)
- Performing Business Impact Analyses (BIAs)
- Translating BIA results into control measures
- Supporting ENSIA audits and other compliance audits
- Ensuring correct file formation and evidence
- Representing information security within projects and consultations
- Advising management and colleagues on information security and risk management
- Organizing awareness campaigns, training and communication activities
Requirements
- Completed HBO or WO education in, for example, information management, cybersecurity, law or (technical) business administration
- At least 3 years of experience as an Information Security Officer within a municipality, province or other government organization
- Up-to-date knowledge of information security, governance and risk management
- Knowledge of BIO2
- Knowledge of the Cybersecurity Act (NIS2)
- Experience in setting up and implementing risk management processes
- Experience with risk identification, analysis and monitoring
- Experience with supplier management and supply chain risks
- Knowledge of contractual security requirements
- Affinity with asset management and IoT security
- Excellent command of the Dutch language verbally and in writing
- Reference from a recent relevant client
- Certification CISM
- CISSP Certification
- CRISC Certification
- Experience with GRC tooling
- Experience with ISMS implementations
- Experience with ENSIA audits
- Experience within municipal organizations
- Experience with Business Impact Analyses (BIAs)
- Experience with information security awareness programs
- Proactive
- Result-oriented
- Analytically strong
- Risk-aware
- Persuasiveness
- Administrative sensitivity
- Organizationally aware
- Connecting capacity
- Flexible
- Pragmatic
- Strong verbal communication skills
- Strong written communication skills
- Able to switch strategically, tactically and operationally
- Strong in stakeholder management
- Vision combined with execution power
- Ability to create ownership within the organization
- Networker and ambassador of information security
Core Responsibilities
The ISO is responsible for strengthening risk management processes and developing the Information Security Management System (ISMS). They will implement security measures, ensure compliance with BIO2 and NIS2, and advise management on information security and risk.
Requirements
Requires a bachelor's or master's degree in cybersecurity, law, or business administration with at least 3 years of experience in a government organization. Proficiency in Dutch and knowledge of BIO2, NIS2, and risk management processes are essential.
About Madello Consulting
Industry: Software Development
Company size: 11-50 employees
Welcome to MADELLO CONSULTING! At MADELLO CONSULTING, we are driven by a mission to empower talents globally. Our roots trace back to Lavendel Consulting, and we have rebranded to better reflect our commitment to operational excellence, innovation, and impactful solutions in the IT industry. Our Expertise: - Global IT Consulting & Services: Delivering tailored IT solutions to meet the unique needs of our clients. - IT Staffing Solutions: Connecting top-tier IT talent with businesses worldwide. - Offshoring & Nearshoring: Providing cost-effective, efficient solutions to enhance your IT operations. - Digital Transformation: Leveraging cutting-edge technologies to drive business innovation and efficiency. - Pricefx Implementation: Optimizing pricing strategies to drive business growth. - SnapLogic Implementation: Streamlining data integration processes for improved operational efficiency. Our Values: - Empowerment: We believe in empowering our workforce and clients to achieve their full potential. - Innovation: Continuously exploring new ideas and technologies to deliver cutting-edge solutions. - Excellence: Striving for the highest standards in everything we do. - Integrity: Upholding transparency, honesty, and ethical behavior in all our actions. - Collaboration: Valuing teamwork and partnerships to achieve common goals. - Impact: Committed to making a meaningful impact on society and the IT industry. - Customer Focus: We put our customers at the heart of everything we do, exceeding their expectations through personalized service. - People as Our Greatest Asset: In the knowledge industry, our people are our most valuable asset. We invest in their growth and well-being. - Family and Community: We aspire to be more than just a company; we aim to be a family and a community, fostering a supportive and inclusive environment. Join us on our journey to create a positive and lasting impact. Together, we can achieve great things!