> Markdown version of [/jobs/ext/2214211-information-security-officer](https://www.wearedevelopers.com/jobs/ext/2214211-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** Nmbrs - **Location:** Amsterdam, Netherlands - **Experience:** Expert - **Salary:** €5,700.0 - €7,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Audit Trail, Software as a Service, Cloud Computing Security, Cyber Security, Identity and Access Management, Phishing, Software Vulnerability Management, Nmbrs, Information Security Management System, Cloud Platform System, Information Technology, Visma Applications - **Published:** August 25, 2026 - **Apply:** https://nmbrs.recruitee.com/o/information-security-officer ## About the Role * A bachelor's degree in Computer Science, Cybersecurity, or a related field. * A recognized security credential such as ISO 27001 Lead Implementer/Auditor, CISSP, or CISM - or a clear willingness to obtain one. * Broad experience across the security spectrum: technical (cloud, network, systems) as well as governance, risk, audits and compliance. * Comfortable working hands-on with firewalls, cloud environments and system/audit logs when needed. * The ability to explain technical risk clearly to non-technical colleagues and leadership. * Experience working in a SaaS environment. Nice to have: * Fluency in Dutch. ## Description As Information Security Officer, you protect Nmbrs' digital data and systems from cyber threats, breaches and data loss. You build and maintain the security rules that keep us safe, run risk assessments, close system weaknesses, and make sure the company stays on the right side of data and security law. You own operational and technical security end to end: policies and standards, incident response, vulnerability management, security awareness, and compliance with security regulation. You'll work closely with the DPO and with security liaisons across the Nmbrs suite entities., * Own the ISMS, keep the ISO 27001 certification and ISAE3402 audit current, ensure compliance with the Visma Security Program and track regulatory drivers such as NIS2and GDPR that affect Nmbrs' security posture. * Develop and maintain security policies and standards, run risk assessments, and verify that control measures are actually effective in practice. * Help shape our security architecture and access management approach, and make sure security is considered early in how squads build and ship software. * Plan audits, coordinate evidence collection, act as the main contact for auditors, and follow up on findings until closure. * Stay hands-on with firewalls, cloud security and system logs, and drive vulnerability management with the squads. * Investigate and mitigate security incidents and data breaches, and turn lessons learned into concrete improvements. * Set clear guidelines for safe computer, network and AI use, build a security-aware culture across the organization, from phishing to onboarding/offboarding processes, and be the go-to person for security questions. * Assess the security of vendors and new tools before onboarding, and answer customer security questionnaires. * Translate technical risks and threat trends into language non-technical colleagues and the leadership team can act on. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [The Netherlands – Europe’s powerhouse for software development?](https://www.wearedevelopers.com/magazine/31-the-netherlands-europe-s-powerhouse-for-software-development) - [The Best Tech Hubs in Europe: 5 Best Cities For Software Engineers](https://www.wearedevelopers.com/magazine/246-the-best-tech-hubs-in-europe-5-best-cities-for-software-engineers)