Standplaats: UTRECHT
Duur: 24-08-2026 - 31-12-2026
Optie tot verlenging: Ja
Reageren voor: 07-08-2026
Zoekopdracht
PosID: P_00208468
Language: English and Dutch mandatory
ZZP Allowed: No
Description Vacancy: We are seeking a highly motivated and detail-oriented Security Officer to strengthen our security governance and assurance capabilities. The successful candidate will be responsible for assessing assurance reports, reviewing security-related information, identifying risks, and providing practical recommendations to stakeholders. This role requires excellent communication skills, strong analytical abilities, and a pragmatic, no-nonsense approach to security.
Key Responsibilities
Security Assurance & Risk Assessment
•
• Review and assess third-party assurance reports, including SOC 1, SOC 2, ISO 27001, ISAE 3000, and other relevant audit reports.
• Evaluate the effectiveness of security controls and identify potential risks, gaps, and areas for improvement.
• Interpret complex technical and compliance-related findings and translate them into clear business implications.
• Provide risk-based recommendations and support decision-making processes.
Security Review & Analysis
•
• Analyze security documentation, policies, standards, procedures, and control frameworks.
• Assess security information from internal and external sources to determine organizational risk exposure.
• Monitor and evaluate security developments, vulnerabilities, and emerging threats that may impact the organization.
• Support security governance activities by ensuring security requirements are understood and applied consistently.
Stakeholder Engagement
•
• Communicate security risks, findings, and recommendations clearly and effectively to both technical and non-technical audiences.
• Build strong working relationships with business units, vendors, auditors, and senior management.
• Challenge assumptions constructively and maintain an independent and objective perspective.
• Facilitate discussions on security risks and control effectiveness with confidence and professionalism.
Security Governance & Compliance
•
• Support compliance initiatives and security reviews against established frameworks and standards.
• Assist in maintaining security policies, standards, and guidance documentation.
• Contribute to audits, assessments, and risk management activities.
• Ensure that identified risks are appropriately documented, tracked, and remediated.
Required Qualifications
•
• Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent experience.
• Proven experience in information security, risk management, audit, assurance, or security governance.
• Strong understanding of security frameworks and assurance standards such as ISO 27001, NIST, SOC reports, and ISAE standards.
• Experience assessing assurance reports and translating findings into actionable recommendations.
• Excellent analytical and critical-thinking skills.
• Strong written and verbal communication skills.
• Ability to work independently and make sound risk-based judgments.
Personal Characteristics
•
• No-nonsense mindset: pragmatic, direct, and focused on achieving meaningful security outcomes.
• Strong attention to detail without losing sight of the bigger business picture.
• Confident in challenging stakeholders when security risks are not adequately addressed.
• Professional, resilient, and capable of handling complex discussions.
• Highly organized and able to manage competing priorities effectively.
• Collaborative team player with a strong sense of accountability.
Preferred Certifications
•
• CISSP
• CISM
• CRISC
• ISO 27001 Lead Implementer or Lead Auditor
• CISA
What are the requested activities?
•
• Review assurance reports thoroughly and efficiently from a security perspective.
• Identify, communicate and manage security risks within the E&ET domain.
• Supply stakeholders with practical, actionable advice rather than theoretical recommendations.
• Manage security decisions driven by balanced, risk-based assessments.
• Act as a trusted advisor who combines technical security understanding with strong business communication skills.
Functie-eisen:
CISA
CISM
Cissp
CRISC
Cybersecurity
ISO 27001 Lead Implementer or Lead Auditor
Risk management