Brightlyn logo

Cyber Security Consultant

Brightlyn

The Hague
Full-time
5-10 years experience
On-site

Key Skills

IT Security
Risk Assessment
Security and Compliance
IT and Cloud Infrastructure
Backup and Recovery Architecture
Identity and Access Management
Advanced Excel
Power BI
Data Analysis and Visualization
Artificial Intelligence Tools
ISO 27001
NIST Cybersecurity Framework
CIS Controls v8
DORA
NIS2
Stakeholder Communication

Job Description

Description Are you ready to make a real technical impact in security and risk management? At Brightlyn, a forward-thinking start-up based in The Hague, we partner with society-critical organizations to help them build resilience, meet regulatory requirements, and stay ahead of evolving cyber threats. As a Senior Security & Compliance Consultant, you’ll get hands-on with the biggest organizations in the Netherlands — spanning financial services, public, production, utility, and retail sectors. You won’t just review policy documents: you’ll sit down with engineers and system administrators, pull apart how their environment is actually built and configured, and challenge whether it holds up. This isn’t just a job; it’s an opportunity to help organizations protect what matters most while driving innovation in the security and risk domain. Key Responsibilities: Conduct in-depth, technical security and risk assessments in complex IT environments, producing actionable, pragmatic roadmaps aligned with customer business objectives. Interview and challenge engineers, system administrators, and architects on how security controls are actually implemented and configured – not just on paper. For example: how backup management is set up (who has access, what does a logically sound implementation look like, should the backup environment sit in a separate network/AD forest, is a 3-2-1 backup strategy, or higher, in place, are backups immutable) and the same level of technical depth for identity and access management (privileged access, MFA coverage, joiner-mover-leaver processes, segregation of duties). Work data-driven: analyse extracts from customers’ CMDBs, asset inventories, backup systems, and IAM/MFA registrations, and turn them into logical, insightful dashboards that expose gaps and support your findings with evidence rather than opinion. Be hands-on in resolving our customers’ most critical DORA and NIS2 challenges. Brightlyn is the DORA authority in the Netherlands, and we need resolvers rather than commentators: you translate the regulation’s requirements on ICT risk management, incident classification and reporting, digital operational resilience testing and third-party/ICT outsourcing into concrete technical measures, sit with engineers, system administrators and suppliers to get those measures actually implemented and evidenced. You will own DORA topics end to end for financial entities, from initial gap assessment through remediation to demonstrable, audit-proof resilience and become one of the specialists our customers call. Perform ransomware quick assessments, identifying vulnerabilities and guiding customers on key protective Ransomware measures. Innovate and develop new security, risk, and compliance services to stay ahead of industry trends. Communicate technical and strategic insights across all levels. From engineers to executive management, enabling customers to make informed, risk-aware decisions. Stay ahead of emerging trends, such as sovereign cloud strategies & solutions. What We’re Looking For: Demonstrated experience in IT security, risk, and compliance. A demonstrable background in IT & cloud infrastructure, so you can credibly interview and challenge engineers and sysadmins on their design and configuration choices rather than relying on checklists. Solid working knowledge of core technical domains we assess daily, such as backup & recovery architecture (3-2-1 strategy, immutability, network/AD segregation, access controls) and identity & access management (privileged access, MFA, account lifecycle management) and the ability to quickly get up to speed on adjacent technical domains. Advanced Excel skills (pivot tables, complex formulas and charts) and experience with Power BI (data modelling) to independently analyse large, messy data extracts such as CMDB exports, asset lists, backup job overviews, MFA/account reports and turn them into clear, logical dashboards that drive findings. Practical, hands-on use of AI to work faster and smarter using AI tooling to interrogate large data extracts, accelerate analysis and drafting, and build assistants or chat interfaces. Strong command of frameworks like ISO 27001, NIST Cybersecurity Framework, and CIS v8 and an ability to focus on their overarching goals rather than just the letter of the control. Great familiarity with regulatory standards such as NIS2 and DORA, understanding both the letter and the intent of these regulations. Confidence in challenging the status quo, taking ownership, and continually raising the bar. Comfort delivering boardroom presentations, leading discussions, and facilitating interactive training sessions. Experience conducting risk assessments and a risk-first mindset. Why Join Brightlyn? At Brightlyn, we don’t just innovate; we dare to do better, every day. Here’s what you can expect: Meaningful Work: Collaborate with critical organizations to solve complex security challenges and make a real societal impact. A Strong Support System: Whether you're an experienced professional sharpening your skills or a young professional looking to grow, we’ll provide coaching, mentorship, and ongoing learning opportunities. Together, we’ll help you become the best version of yourself. A Vibrant Community: We’re passionate about security and risk! Join us for meetups, conferences, and internal knowledge-sharing events to stay sharp and stay inspired. Fantastic Workspace: Located in The Hague's Binckhorst district, our modern office has all the perks: productive equipment, great food and drinks, and even a gym to keep you at your best. If you’re ready to work with some of the brightest minds in security and risk while making a meaningful difference, we’d love to hear from you!

Core Responsibilities

Conduct technical security and risk assessments, analyze customer infrastructure and data, and develop practical remediation roadmaps. Lead DORA and NIS2 remediation, ransomware assessments, and the development of security and compliance services, communicating findings to technical teams and executives.

Requirements

Candidates should have demonstrated experience in IT security, risk, and compliance, with a strong background in IT and cloud infrastructure and practical knowledge of backup and recovery and identity and access management. The role also requires advanced Excel and Power BI skills, hands-on use of AI tools, familiarity with ISO 27001, NIST CSF, CIS v8, DORA, and NIS2, and confidence presenting and challenging stakeholders.

Benefits

  • Coaching and Mentorship
  • Ongoing Learning Opportunities
  • Meetups and Conferences
  • Internal Knowledge-Sharing Events
  • Modern Office
  • Productive Equipment
  • Food and Drinks
  • Gym

About Brightlyn

Industry: IT Services and IT Consulting

Company size: 2-10 employees

Brightlyn is redefining how digital security is approached: simple, strategic, and powerful. We transform security from a box-ticking exercise into a true source of value, fostering trust, clarity, and confidence in an increasingly complex world. Cybersecurity & IT Audits We perform risk‑focused IT and cybersecurity audits & assessments that go beyond checkbox compliance. Our audits provide meaningful insights on the design and effectiveness of controls that matter most to your organization, customers, and regulators. Regulatory & Compliance Advisory (DORA, NIS2, SOC 2) Brightlyn supports organizations in navigating complex regulations such as DORA and NIS2, as well as assurance engagements like SOC 2, ISAE 3000, and ISAE 3402. We help turn regulatory obligations into a strategic advantage by aligning compliance with real operational resilience. Risk & Control Frameworks We design and assess security and control frameworks tailored to modern IT environments, including cloud, DevOps, and outsourced service models. Our approach focuses on clarity, usability, and effectiveness across people, process, and technology. Security Assessments & Improvement Roadmaps From in‑depth risk assessments to targeted reviews, we identify root causes of weaknesses and provide pragmatic improvement roadmaps that can be implemented quickly and sustainably. End‑to‑End Support Brightlyn offers an end‑to‑end approach, from identifying control weaknesses, to supporting implementation, and providing independent assurance. Fully unburdening customers while safeguarding their most critical processes.

Added Today