Information Security / IT Risk & Compliance Consultant (medior)
For a leading international organisation in the medical technology sector, we are looking for a medior Information Security / IT Risk & Compliance Consultant. In this assignment you will support the organisation with information security governance, IT risk and compliance, translating regulations and control frameworks (including ISO 27001, NIST, PCI DSS, DORA and NIS2) into workable IT controls.
Key responsibilities include:
Performing and supporting IT risk and compliance assessments, and identifying and mitigating risks;
Establishing, validating and improving control frameworks and risk management processes;
Preparing and supporting internal and external audits, including evidence and remediation management;
Supporting security governance and the integration of controls into SDLC/DevOps processes;
Aligning with and advising stakeholders across IT, security, DevOps and business.
Requirements:
3–5 years of relevant experience in information security, IT risk and/or compliance (medior level);
CISM certification (strong preference);
Demonstrable knowledge of relevant control frameworks such as ISO 27001, NIST and PCI DSS;
Living and working in the Netherlands;
Dutch-speaking is preferred; English-speaking (UK) is negotiable.