Do you want to provide strategic advice and actually see your recommendations put into practice? At mnemonic, you’ll help some of Europe’s most business-critical organisations, across the Benelux, the Nordics and the UK, to strengthen their resilience against threats and manage their risks. We translate governance, risk and security into choices that really matter for our clients. You’ll rarely spend two weeks doing the same thing: one day you might be advising a client’s C-suite on where to focus their cybersecurity efforts. The next, you could be leading a strategic security project or stepping in as CISO-for-hire.
mnemonic’s success and growth has created the need for us to strengthen our GRC team in the Netherlands and we are looking for a Senior GRC Consultant who will work closely with clients and wants to contribute to the further development of our services.
If you ask one of our GRC colleagues why they work for mnemonic, you’ll often hear the same answers: the unique in-house expertise, a flat organisational structure and a close-knit atmosphere with scope for social activities. You can see from the figures that this approach works well: our staff turnover is below 5 per cent, exceptionally low for our industry, and our client retention rate is around 95 per cent.
mnemonic was founded in 2000 and, with 450 employees, has become one of Europe’s largest independent pure-play cybersecurity firms. You’ll be working alongside an international team of security specialists on complex and meaningful challenges. We work for some of the most critical organisations and infrastructures and are best known for our Security Operations Centers (SOC) and Managed Detection and Response (MDR) services, through which we protect clients on a daily basis against today’s most advanced cyber threats.
As a Senior GRC Consultant, you’ll play a key role in our advisory services in the field of Governance, Risk & Compliance. You’ll work closely with clients and support organisations in setting up, developing and managing their information security programmes within complex and business-critical environments.
You will work on highly complex projects, often in direct collaboration with executive boards and management teams. In doing so, you will translate risks, regulations and strategic objectives into structures, processes and concrete improvements. You will collaborate with both business and technical teams, often in environments where security is essential to the organisation’s continuity.
The role is based at our office in Utrecht, with the option to work flexibly from the office and from home. As our head office is in Oslo, you may occasionally be required to travel there.
- Independently leading and carrying out consultancy projects in the field of information security and GRC, from analysis through to implementation.
- Acting as a security manager or CISO-for-hire for clients, steering their security programme and embedding it within the organisation.
- Translating legal and regulatory requirements and risks into governance structures, operating models and practical working methods. Examples include NIS2, CbW, BIO, DORA, the GDPR, the EU AI Act and the CRA.
- Advising boards and management teams on governance, risks and maturity development.
- Communicating / presenting technical findings to a management audience that want to relate the findings to their strategic and financial priorities.
- Planning and carrying out risk analyses, security assessments and crisis and resilience exercises.
- Establishing and further developing Information Security Management Systems (ISMS) and supporting compliance initiatives.
- Collaborating with both business stakeholders and technical teams.
- Managing multiple parallel projects, from planning and scope definition through to stakeholder engagement and delivery.
- Contributing to the further development of mnemonic’s GRC offering.
- Participating in client meetings and supporting pre-sales activities.
You have a completed higher professional education (HBO) or university (WO) degree, for example in IT, information security or a similar field. In addition, you have at least 5 years’ experience in information security and GRC, preferably in a consultancy environment.
You have practical experience with governance, risk management and compliance, and know how to translate frameworks into concrete solutions within organisations. For example, you have worked on risk analyses, policy development or the implementation of management systems (ISMS). You also have a good knowledge of frameworks such as ISO 27001, NIST or similar standards.
You are analytical, organised and a strong communicator. You take ownership of your assignments and are able to explain complex topics in a way that is understandable to both technical and non-technical audiences. You have a good command of Dutch and English, both spoken and written.
You follow the current trends in IT and are passionate about staying on top of what the industry is talking about. New and “first time” assignments are an opportunity for learning and you lean in to learning while doing.
The certifications listed below help us identify suitable candidates and give you an idea of what might be valuable to obtain for this role. They are an advantage, not a requirement:
- CISSP, CISM or CISA
- ISO 27001 Lead Implementer / Lead Auditor
- CIPP/E or CIPM (privacy)
- CCSP or CCSK (cloud security)
- PRINCE2 or a comparable project management certification
The role offers a great deal of responsibility and excellent opportunities for professional development. In addition, mnemonic offers you:
- A competitive salary, a bonus scheme and a share scheme designed to encourage long-term collaboration.
- A good pension scheme and insurance cover.
- Ample opportunities for training, courses and attending professional conferences.
- A flexible working model and a centrally located office in Utrecht.
- An informal, pleasant working environment that prioritises work-life balance for everyone, including colleagues with families.
- A close-knit team atmosphere with social activities, events and outings with colleagues.
mnemonic has been recognised by Great Place to Work as one of Europe’s best employers for many years