Information Security & Compiance Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Are you our pragmatic link between compliance and the day-to-day? As a fintech SaaS company, Billit operates in a heavily regulated environment - think DORA and ISO 27001. That’s why we’re expanding our team with someone who:
-
operationally translates our security and compliance obligations into day-to-day practice
-
and makes good governance real and workable in a scale-up that takes quality seriously - without turning it into bureaucratic overhead.
What does an Information Security & Compliance Officer do at Billit? You’re the operational engine behind our security and compliance work. You coordinate, document, and monitor processes. You make sure that what’s written on paper is actually followed and acted upon. You report to our Chief Quality Officer and serve as the bridge between strategy and execution. In practice:
-
You coordinate and follow up on incoming security reports, making sure they reach the right teams on time.
-
You monitor SLA’s, follow-up deadlines, and the progress of security cases.
-
You manage our ISO 27001 documentation and ensure the quality, completeness, and consistency of all security and audit information.
-
You coordinate internal and external penetration tests, including planning, communication, and administrative follow-up.
-
You serve as the first point of contact for general security and compliance questions - both internally and externally.
-
You follow up on scan results and ensure findings are properly registered and handled.
-
You report on open findings, KPIs, and remediation progress.
-
You support audits and compliance activities and actively contribute to the continuous improvement of our security processes.
-
You optimize and document operational security processes and work instructions - pragmatically and scalably.
-
For those familiar with the Three Lines of Defense model: you work within our 1st line of control quality team. On the front line, hands-on and boots on the ground.
Requirements
-
You have at least a few years of relevant experience in an operational compliance or security role, preferably in a regulated environment (fintech, SaaS, healthcare, government…).
-
Ideally, you’re already familiar with DORA, ISO 27001, and/or GDPR.
-
Relevant certifications (ISO 27001 Lead Implementer, CISM, CRISC…) are a real asset, though not required.
-
You preferably have demonstrable experience managing security documentation and supporting audits. If you don’t have that specific experience yet but bring strong analytical thinking, drive, and a hunger to learn fast - don’t let that stop you from applying.
-
You communicate fluently in English and preferably also in Dutch.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.careerjet.beGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How to land a developer job in Amsterdam
Software Developer Salary in The Netherlands [2023]
How to Find Tech Jobs in Amsterdam
9 Ways to Make Money Hacking