> Markdown version of [/jobs/ext/1175578-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/1175578-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Ardena - **Location:** Oss, Netherlands - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Active Directory, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Identity and Access Management, IT Management, Information Technology Operations, Cloud Services, Phishing, Security Information and Event Management, Software Vulnerability Management, Information Security Management System, Information Technology, Firewall Services Module, Network Server, GXP, Vulnerability Analysis - **Published:** July 4, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=4ab5dd2f1505721e ## About the Role * Bachelor's degree in IT security, cybersecurity, computer science, or a related field from a university of applied sciences (HBO). * ISO 27001 Lead Implementer or Lead Auditor certification is a strong plus; solid working knowledge of the standard is a must., * 3 to 5 years of hands-on experience in an information security or IT security role; this means not just advisory work, but actual implementation and operations. * Demonstrated experience running or contributing to an ISO 27001 programme (gap analysis, audits, controls, risk assessments). * Comfortable working in complex, multi-site IT environments with a mix of on-premise and cloud infrastructure. Technical Understanding * Solid understanding of IT systems - networks, servers, endpoints, Active Directory, cloud services - at a level that lets you have a credible technical conversation. * Familiarity with vulnerability management tooling, SIEM concepts, and endpoint security. * Able to read and interpret security logs, understand firewall rules, and assess access configurations. How you work * You take ownership. You see what needs to be done and you do it - without needing someone to walk alongside you every step of the way. * You can translate technical risk into plain language for management and non-technical stakeholders. * You are structured, thorough, and comfortable in a regulated environment where documentation and auditability matter. * Fluent in English; Dutch is an advantage for day-to-day interaction with colleagues. * You are prepared to travel to Ardena sites on an occasional basis (approximately 5% of your time) Nice to have * Additional certifications such as CISSP, CISM, CEH, or CompTIA Security+. * Experience in a GxP-regulated environment (pharmaceutical, medical device, food) - you do not need to know GxP, but if you do, great. * Familiarity with the NIS2 Directive and its implications for critical infrastructure operators. * Experience with cloud security (Microsoft Azure / M365 security stack). ## Description This role is not a junior position. We are looking for someone who can own our information security programme, run it independently, and develop it further. You will work closely with the IT Operations Director and have direct visibility across the organisation, but we expect you to drive the agenda, not wait for it., * Own and maintain the Information Security Management System (ISMS) in line with ISO 27001 amongst other ISO standards. * Drive the implementation roadmap, perform gap analyses, create risk treatment plans, policy framework, and controls. * Prepare for and manage external certification and surveillance audits. * Conduct internal audits and track corrective actions to closure. * Identify process improvements and increase cybersecurity awareness. Risk & Compliance * Maintain the information security risk register and ensure risks are assessed, accepted, or treated. * Monitor compliance with internal policies and applicable regulations (NIS2, GDPR from an IT security angle). * Provide security input to new IT projects, system implementations, and vendor assessments. Operational Security * Manage vulnerability assessments, patch compliance tracking, and penetration testing cycles. * Own the incident response process for security events - detection, containment, reporting, post-incident review. * Oversee access management principles and periodically review user rights. * Coordinate security awareness training and phishing exercises across the organisation. Stakeholders & Reporting * Report on security posture and KPIs to IT management and where relevant to senior leadership. * Act as the point of contact for information security questions from internal stakeholders, clients, and auditors. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [The Netherlands – Europe’s powerhouse for software development?](https://www.wearedevelopers.com/magazine/31-the-netherlands-europe-s-powerhouse-for-software-development) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)