F2F.com logo

HEAD OF INFORMATION SECURITY

F2F.com

Amsterdam
Full-time
5-10 years experience
Hybrid

€6,000 - €9,500 per month

Key Skills

Information Security
Security Leadership
Python
Node.js
Application Security
API Security
Secure Code Review
CI/CD Security
SAST/DAST/SCA
Infrastructure as Code Review
AWS
Identity and Access Management
Cryptography
Incident Response
ISO 27001
Risk Management

Job Description

Head of Information Security Are you a hands-on security leader who wants to take real ownership? At F2F.com, we're looking for a Head of Information Security who sets the direction, rolls up their sleeves and helps us build a platform creators can trust. This role is open to residents of the Netherlands only. About The Role We are looking for a proactive, hands on Head of Information Security who takes real ownership of security at F2F.com. You set the direction, but you also roll up your sleeves: you review code with our engineers, step in when something goes wrong and keep things practical rather than bureaucratic. In a growing company like ours, security only works when everyone understands why it matters. You work across the whole company, not just with the development team: with our support and safety teams on escalations, with leadership on risk and with every colleague on awareness. From our engineers to our office manager, you make sure everyone knows what good security looks like in their daily work. In the near future, you will also lead our journey towards ISO 27001 certification. What you will do Strategy and governance Develop, implement and maintain practical information security policies aligned with our business goals, without unnecessary bureaucracy. Assess security risks, maintain the risk register and advise leadership on mitigation strategies. Oversee security evaluations of third party suppliers and keep track of data flows to external vendors. Prepare and guide the ISO 27001 certification process, building an ISMS that fits the size and pace of our organisation. Hands on security engineering Perform regular code reviews to identify, document and remediate vulnerabilities (such as the OWASP Top 10 and business logic flaws). Partner with software engineers to design secure services, API integrations and database interactions. Integrate SAST, DAST and dependency scanning into our CI/CD pipelines. Design and implement robust Identity and Access Management (IAM) for internal and customer facing systems. Act as our go to expert on cryptography, token authentication, secure session handling, and cooperate with legal and compliance on matters such as legally required security measures, privacy and data protection and the secure use of AI within the organisation. Incident response and escalations Lead incident response: preparation, detection, containment and thorough reviews afterwards. Take the lead in escalations, working closely with our support team and safety team, and prevent escalations where possible by managing risks early. Work with our partner on device management and endpoint security, including MDM rollout and EDR/XDR monitoring. Set up threat intelligence and dashboards to report monthly on security posture, incidents and threat vectors. Security awareness across the company Take the whole organisation along in security awareness, translating technical risks into clear and practical guidance that every colleague understands. Build a security culture where people know what to do and feel comfortable raising concerns. What you bring Strong interpersonal skills and organisational sensitivity: you can explain security to a developer, a support agent and a founder, each in their own language. Proven ability to drive organisational change and implement security measures that people actually adopt. Leadership in escalations, combined with a preventive mindset. Proactive and self directed: you see what needs to be done and act on it without waiting to be asked. 5+ years of practical experience in software development or security engineering, with a focus on Python, Node and API security. Comfortable in CI/CD: SAST/DAST/SCA integration, IaC review and cloud (AWS). Deep technical understanding of application security, secure code design and API security. Experience running or building an ISMS (ISO 27001 or NIST CSF), ideally in a small or medium sized organisation. Experience guiding an ISO 27001 certification is a strong plus. Nice to have: experience with MDM, EDR/XDR endpoint monitoring and zero trust solutions. Fluency in English and Dutch is a plus. What we Offer Competitive salary and strong secondary benefits 24 vacation days Fully paid pension plan, no employee contribution Free lunch at the office NS Business Card Flexible working hours and hybrid working €1,000 personal development budget per year Gym subscription via ClassPass or a sports venue of your choice Lease-a-bike scheme Salary between €6000 - €9500 Interested? Sound like your next move? We'd love to hear from you, portfolio or side project included if you have one. Send your CV and motivation letter to [email protected]. Apply now and come help us build a platform creators can trust. ‍ apply now

Core Responsibilities

Set and implement practical information security strategy, governance, and risk management, while leading the organization’s preparation for ISO 27001 certification. Provide hands-on application and cloud security, lead incident response and escalations, oversee endpoint security and supplier assessments, and build security awareness across the company.

Requirements

Requires at least five years of practical software development or security engineering experience, with strong Python, Node.js, API security, application security, CI/CD, and AWS knowledge. Candidates should have experience building or running an ISMS and demonstrate proactive leadership, communication, and organizational change skills; ISO 27001 certification guidance and endpoint security experience are advantageous.

Benefits

  • 24 Vacation Days
  • Fully Paid Pension Plan
  • Free Office Lunch
  • NS Business Card
  • Flexible Working Hours
  • Hybrid Working
  • €1,000 Annual Personal Development Budget
  • Gym Subscription
  • Lease-A-Bike Scheme

About F2F.com

Industry: Entertainment Providers

Company size: 11-50 employees

F2F.com (friends2follow) is a premium creator-first platform redefining the connected adult space. Based in Amsterdam and operating globally, we empower creators to build meaningful, safe and authentic connections with their fans. We provide a supportive ecosystem with transparent tools, personalised growth guidance, mental health resources, and a community-first philosophy designed to help creators thrive. We call it the connected adult space: a safe, human-centred and transparent alternative to the traditional adult industry. A space where creators maintain full control of their business, engage directly with their fans, and grow through innovation, trust and genuine connection. Our platform is built on four commitments: Safety: A secure environment where creators can work with confidence. Transparency: Clear policies, fair payouts and direct communication. Empowerment: Tools, data insights and support to help creators grow sustainably. Community: A global network of creators and fans connected through authenticity. F2F.com is shaping the future of adult fan engagement

Added Yesterday