Your Role
As IT & Security Risk Advisor, you strengthen the 2nd Line of Defense (2LOD) and help the organization further increase its security maturity. You are an independent advisor and sparring partner for DevOps teams, solution architects, IT management, Enterprise Architecture, and suppliers. You combine in-depth knowledge of cybersecurity and software development with a strong risk awareness and an independent 2LOD perspective. You know how to translate complex technical issues into clear risk assessments and pragmatic advice for both management and development teams. In this role, you get the opportunity to make a visible impact on the further professionalization of IT & Security within one of the largest fitness chains in Europe, in an international organization with an ambitious digital change agenda.
You are capable of independently taking on complex dossiers, giving direction to improvement programs, and structurally raising the quality of decision-making around IT and security risks.
In this role, you report to the IT Quality Officer of Basic-Fit International.
You work within a broad network of stakeholders, including DevOps teams in Hoofddorp and Tilburg, responsible for business-critical digital platforms and applications used daily by millions of members and thousands of employees in six countries. In addition, you have regular contact with shared services teams, colleagues within the 2nd line, 1LOD officers, and external auditors.
Your tasks:
- Developing, implementing, and further professionalizing the 2LOD security assurance process for software development, in which you challenge DevOps teams and solution architects on Security by Design, Secure SDLC, and the effectiveness of security measures.
- Contributing to the further development of the IT Control Framework, security policy, and governance processes.
- Identifying and realizing opportunities to further professionalize the 2LOD IT Security function through the smart use of AI, AI agents, and process automation, so that risk assessments, assurance activities, and management reporting can be carried out more efficiently and at scale.
- Preparing management reports, risk analyses, and advisory documents for IT management, the Executive Board, and the Audit & Risk Committee.
Who are you?
We are looking for an experienced security professional who feels comfortable at both a technical and strategic level. You understand how modern software is developed and can substantively challenge development teams, without being responsible yourself for the execution or management of security measures.
If you are a strong technical security specialist but still developing in strategically advising and persuading executive management and senior stakeholders, we also invite you to apply.
You are independent, analytical, and persuasive. You know how to bring people along, dare to ask critical questions, and are able to pragmatically solve complex issues. You take ownership, independently determine the approach within agreed frameworks, and come up with well-founded solutions and advice for complex issues.
- At least 5 years of relevant experience in cybersecurity, IT Risk, Security Architecture, or Security Assurance, or demonstrably equivalent working and thinking level. What's decisive is that you operate at a senior level and are able to independently take on complex dossiers within a few weeks.
- Knowledge of Secure Software Development, Security by Design, and DevSecOps principles, with the ability to substantively challenge DevOps teams and critically assess security measures.
- Experience with IT Risk Management, security governance, and assurance.
- Knowledge of relevant frameworks such as ISO 27001, CIS Controls, and current legislation and regulations (including GDPR, NIS2).
- Experience with modern software architectures, cloud platforms, and the associated security challenges.
- Proven ability to bring stakeholders at various levels on board, critically challenge them, and create support for improvements in the field of IT Risk & Security.
- Excellent communication skills and the ability to operate at all levels within the organization.
- Excellent command of English, spoken and written, given Basic-Fit's international stakeholders. Dutch is nice to have.
- You are certified, or demonstrably actively pursuing certification, in at least one of the following: CISSP, CISM, or CISA (or equivalent).
Nice to have
Experience with or demonstrable affinity for the use of AI, AI agents, and process automation to make governance, risk, and assurance processes smarter and more efficient.
What do we offer you?
At Basic-Fit, it's not just about work, but about your growth. As IT Security Risk Advisor, you get the space to make an impact and further develop yourself in a dynamic, international environment.
What you can expect from us:
- Training & development: Unlimited access to GoodHabitz and LinkedIn Learning.
- Career opportunities: Plenty of room for growth, both professionally and personally.
- Enjoyment at work: An informal, international, and down-to-earth working atmosphere. Because we value collaboration, we work four days a week in the office and one day from home.
- Innovation: Your ideas contribute to strategic projects that are directly visible to millions of members.
- Salary: A gross monthly salary between €4,800 and €6,800 based on 40 hours, depending on your experience and background.
- Secondary benefits: Travel expense reimbursement, bicycle plan, health insurance discount, home-working allowance, and pension scheme (52% premium paid by Basic-Fit).
- Sport: Access to our gym at head office.
About Basic-Fit
Basic-Fit is the European leader in the value-for-money fitness market, with more than 4.7 million members in 1,650+ clubs across 6 countries. We continue to grow and constantly improve. Are you looking for a place where you can make an impact and enjoy your work? Then you've come to the right place with us!
What makes us unique?
- Working with impact: What you do makes a difference. We work not only for, but with our members, partners, and teams.
- Collaboration: Everyone works together to achieve goals and celebrate successes.
- Diversity and inclusion: Everyone is welcome in our work environment.
Apply now!
Are you ready for your next adventure? Apply and we will contact you as soon as possible.
Questions? Feel free to contact Yara at [email protected].