> Markdown version of [/jobs/ext/1444126-information-security-officer](https://www.wearedevelopers.com/jobs/ext/1444126-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information & Security Officer - **Company:** Hunt & Hackett - **Location:** Den Haag, Netherlands - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, DevOps, Intelligence Analysis, Information Security Management System - **Published:** July 26, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=c7db7004628d98f5 ## About the Role * [GRC foundation]: you have experience with information security governance, risk, compliance or audit and understand how an ISMS works. Familiarity with ISO 27001 and SOC 2 is valuable. Knowing where to find the right clause and what it means in practice matters more than reciting it from memory. * [Practical security mileage]: you have worked in or closely with one or more practical security fields, such as SOC operations, red teaming, penetration testing, incident response, security engineering or technical infrastructure. Experience with DevOps, SRE or high-paced development teams is equally relevant. * [Technical curiosity]: you don't need to be the person popping shells or carrying the pager today, but you should understand what happens on the other side of a policy. You are comfortable asking technical colleagues how something really works and curious enough to keep asking when the first answer is 'it depends'. * [Structure and follow-through]: you can maintain accurate documentation, collect evidence, track actions and follow up with owners until matters are properly closed. You like details, but you don't lose sight of why they matter. * [Communication]: you can explain security requirements in plain language, ask constructive questions and write concise policies, reports and recommendations. You are comfortable working in English; Dutch is an advantage. * [Pragmatism]: you can distinguish between controls that materially reduce risk, controls that help a little and controls that are theoretically elegant but practically useless. You prefer a workable 80% solution that people actually use over a perfect control that only exists on paper. You can explain the trade-off, make a conscious decision and revisit it when the circumstances change. ## Description An information & Security officer at Hunt & Hackett is not a human checkbox or the person who only appears when an audit starts. You help keep our ISMS in shape and both our feet in reality. This means clear policies, sensible controls, risks with owners and actions that actually get closed. You work alongside colleagues from security operations, incident response, developers and the wider business. We are not trying to build a utopian security world where budgets are unlimited, systems never change and users never make mistakes. That world does not exist. A control is only useful if it works on a calm Tuesday and at 02:00 during an incident. We don't expect you to know every clause by heart. We do expect you to ask good questions, follow through and learn quickly. Your responsibilities include: * [Keep the ISMS real]: maintain and improve policies, procedures, control descriptions and supporting records. If a document describes a parallel universe instead of Hunt & Hackett, you help bring it back to reality. * [Risk without theatre]: help identify and assess information security risks, maintain the risk register and follow up on treatment actions. You distinguish between what seriously reduces risk, what helps a little and what mainly makes the framework look complete. A risk without an owner is just a well-documented future surprise. * [Audit-ready, not audit-panicked]: coordinate internal reviews and support external audits, including the collection and validation of evidence. Evidence should be part of the process, not an archaeological expedition the week before the auditor arrives. * [Close the loop]: work with operational and technical teams to evaluate controls, exceptions, incidents and audit findings. You turn lessons from the SOC, incident response, red teaming and development into practical improvements instead of another meeting about improvements. * [Make security understandable]: give colleagues pragmatic advice, contribute to security awareness and translate requirements into language people can use. 'Because ISO says so' is not considered a complete explanation., + A monthly salary of course; + The opportunity to safeguard Europe's leading organizations; + A unique culture of 'responsible rebellion' where you can learn from the best to get the most out of yourself; + The most innovative approach to get the job done; + Being part of a winning team, with room for fun, learning and developing yourself; + A proper laptop to get the job done; + A modern pension, which is transparent and can be controlled by yourself; + Employee share participation scheme; + Compensation for your travel costs + Daily lunch is in us; we prepare and enjoy it as a team A culture of 'responsible rebellion' Only (very) talented, multidisciplinary teams of threat hunters, intelligence analysts, reverse engineers, data scientists, developers and hackers are able to outsmart the increasingly professional community of cyber attackers. We pride ourselves as a force for the good and as such we think and act as responsible rebels. We are not 'just another security company', and our people are not 'just employees'. Everyone at Hunt & Hackett wants to be the best in their field and focuses at delivering next-gen levels of service. This means that we live by: * + Security first: a foundational core value that underscores our company's unwavering commitment to prioritizing security in all aspects of our operations. + Pushing the envelope: Everyone at our teams takes the responsibility to make our work better every day, by being creative to color outside of the lines if needed. + Everything is important: Tiny details have a huge impact, especially in security. We are system thinkers that oversee the big picture and who are simultaneously obsessive about details. That's why we champion tradecraft. + Perseverance: To become successful, you will have to endure challenges, errors, failures and obstacles along the way. These may take weeks, months, or years to overcome. + Ego is the enemy: Ego ultimately prevents us from learning, holds us back and makes us overreach. It is therefore important to battle that inner force that destroys great empire's, companies, careers and tears apart relationships. We'd love to hear from you! For more information or to apply, please fill out the form below. If you're viewing this on a Job Posting site, please still do fill out the form on our website (https://www.huntandhackett.com/jobs) ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your First Pitch Is to AI: How to Make Your Brand/Product Visible in the Age of Generative Search](https://www.wearedevelopers.com/videos/100121-your-first-pitch-is-to-ai-how-to-make-your-brand-product-visible-in-the-age-of-generative-search) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer)