Overview
A major public-sector organization is seeking a seasoned Information Security Consultant to strengthen its internal security governance and contribute to the broader development of regional-level information security policies. The consultant will work within a central security & risk team in a complex, multi-stakeholder IT environment.
Responsibilities
Develop, implement, and monitor information security policies and controls
Translate organizational security requirements into concrete, actionable security measures
Define and maintain risk management processes, including strategic/tactical risk assessments
Lead or support the development of security plans, incident handling procedures, awareness campaigns, and training initiatives
Support internal stakeholders in implementing risk assessments at system or asset level
Monitor information security risks and ensure timely and accurate reporting
Initiate and manage security awareness programs and policy improvement projects
Act as the internal point of reference for best practices in information security
Maintain documentation and contribute to knowledge sharing within the organization
Technical Environment
Information Security Management Systems (ISMS)
ISO 27001 frameworks
Risk and compliance management
Collaboration with enterprise and solution architects, product owners, developers, and IT operations teams
Broad stakeholder involvement across internal and external partners
Profile
Minimum 5 years of experience in Information Security, preferably in complex public or hybrid organizations
Strong experience in one or more domains such as:
Implementation of security management processes
Vulnerability management and penetration testing
Application security optimization
Privileged Access Management
Encryption technologies
Solid knowledge of security frameworks: ISO 27000, COBIT, NIST, OWASP, CIS Controls
Strong analytical, documentation, and stakeholder communication skills
Relevant certifications such as CISSP, CISM, CEH, ISO 27001 Lead Implementer, etc.
Fluency in Dutch at native level (C2) is strictly required
