Information Security Expert (Supply Chain Security Audit)
Work Arrangement
Office Days per Week: 2 days
Key Skills
Job Description
Introduction 36 hours per week Start date: ASAP End date: 30 September 2027 Hybrid working, 1-2 days from the office. Travelling abroad is required for this role. Candidates have to live in the Netherlands. Job description You will join the Supply Chain Security (SCS) team, part of the Corporate Information Security Office (CISO) department, within the Cyber Defence grid. CISO is responsible for the bank's information security globally, across all subsidiaries and countries. The grid Cyber Defence is responsible for the security operations activities of ABN AMRO, and within our team we continuously provide visibility into the security posture of the vendors of ABN AMRO. The 20 Supply Chain Security team members are experienced in information security and vendor relations. The team is diverse in both nationalities and professional background, which makes it a great place to work and develop yourself. You can imagine that security is a major asset within the bank. As an Information Security Expert you will be responsible to manage, monitor and report on the performance and the status of the security posture of our vendors. This role is specifically aimed at conducting end to end audits. The team works according to the DevOps & Agile methodology. The working language within the team is English. For your work you often engage with various stakeholders such as; Risk, Procurement, Contract Owners and our suppliers. With the following results (SMART) - The Information security expert is responsible for conducting comprehensive, end‑to‑end audits of systems, processes, SaaS platforms, and internal controls to ensure compliance, security, operational efficiency, and risk mitigation. - This role involves detailed analysis, evidence gathering, root‑cause identification, and actionable reporting to stakeholders across Security, IT, Compliance, and Business units. - The expert provides insight into gaps, emerging risks, and improvement opportunities. Requirements Technical Skills - Strong understanding of IT platforms, applications, security architectures, cloud/SaaS models, and shared responsibilities. - Hands-on experience assessing configurations, access controls, authentication, security settings, system behaviour, logs, audit trails, and monitoring data. - Solid IAM knowledge, including RBAC, PAM, access governance, and user lifecycle controls. - Able to evaluate control design and operating effectiveness using direct system evidence. - Knowledge of IT and cloud security, compliance requirements, internal policies, and frameworks such as ISO 27001, SOC 2, NIST, CIS, and GDPR. Analytical Skills: Excellent attention to detail, critical thinking, and problem-solving; able to identify patterns, anomalies, root causes, and risks. Interpersonal Skills: Communicates complex findings clearly to non-technical audiences; collaborates effectively across Security, IT, DevOps, Compliance, and Business teams; produces strong documentation, reports, and presentations. Experience Typically 6–8 years of experience in internal audit, security auditing, IT risk, compliance, or a related field. SaaS experience is highly desirable; exposure to security posture reviews Preferred Certifications (Not mandatory, but beneficial) - CISA (Certified Information Systems Auditor) - ISO 27001 Lead Audit
Core Responsibilities
Responsible for conducting comprehensive end-to-end audits of systems, processes, and SaaS platforms to ensure security compliance and risk mitigation. The role involves monitoring vendor security postures and reporting findings to stakeholders across Security, IT, and Business units.
Requirements
Requires 6-8 years of experience in security auditing or IT risk, with strong knowledge of cloud security frameworks and IAM. Candidates must be based in the Netherlands and possess excellent analytical and interpersonal communication skills.
About A2Z-CM N.V.
Industry: Business Consulting and Services
Company size: 51-200 employees
A2Z-CM is an independent private company founded in 2012 with offices in Amsterdam and United Kingdom. A2Z-CM is a vendor-neutral, fully-compliant company offering consultancy services, contract management and international brokering to suppliers and agencies in the Netherlands and other countries according to the principle of think global, act local. The A2Z-CM team assist clients by analysing their organisational issues and implementing realistic and cost-effective development plans. Think global, act local. At A2Z-CM, our specialists offer a combination of IT and technical experience, plus a thorough knowledge of compliance and risk mitigation. Our thorough grasp of both fields means that you get solutions tailored to meet your specific needs - solutions that are fully compliant. A2Z-CM provides Clients and contractors with clear, friendly and professional advice on all aspects of the local fiscal and legal regulations. It's our job to deliver a comprehensive range of services, leaving you free to focus on your core business or project.