> Markdown version of [/jobs/ext/2276622-it-security-risk-advisor](https://www.wearedevelopers.com/jobs/ext/2276622-it-security-risk-advisor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Risk Advisor - **Company:** Basic-Fit - **Location:** Hoofddorp, Netherlands (Remote available) - **Experience:** Expert - **Salary:** €4,800.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, DevOps, IT Management, Software Architecture, Systems Development Life Cycle, Software Engineering, Web Platforms, CIS Benchmarks, Devsecops - **Published:** August 28, 2026 - **Apply:** https://basicfit.wd103.myworkdayjobs.com/BasicFit_Career_Site_NL/job/Hoofddorp/Senior-IT-Security-Risk-Advisor_R54298 ## About the Role You are independent, analytical, and persuasive. You know how to bring people along, dare to ask critical questions, and are able to pragmatically solve complex issues. You take ownership, independently determine the approach within agreed frameworks, and come up with well-founded solutions and advice for complex issues. * At least 5 years of relevant experience in cybersecurity, IT Risk, Security Architecture, or Security Assurance, or demonstrably equivalent working and thinking level. What's decisive is that you operate at a senior level and are able to independently take on complex dossiers within a few weeks. * Knowledge of Secure Software Development, Security by Design, and DevSecOps principles, with the ability to substantively challenge DevOps teams and critically assess security measures. * Experience with IT Risk Management, security governance, and assurance. * Knowledge of relevant frameworks such as ISO 27001, CIS Controls, and current legislation and regulations (including GDPR, NIS2). * Experience with modern software architectures, cloud platforms, and the associated security challenges. * Proven ability to bring stakeholders at various levels on board, critically challenge them, and create support for improvements in the field of IT Risk & Security. * Excellent communication skills and the ability to operate at all levels within the organization. * Excellent command of English, spoken and written, given Basic-Fit's international stakeholders. Dutch is nice to have. * You are certified, or demonstrably actively pursuing certification, in at least one of the following: CISSP, CISM, or CISA (or equivalent). Nice to have Experience with or demonstrable affinity for the use of AI, AI agents, and process automation to make governance, risk, and assurance processes smarter and more efficient. ## Description As IT & Security Risk Advisor, you strengthen the 2nd Line of Defense (2LOD) and help the organization further increase its security maturity. You are an independent advisor and sparring partner for DevOps teams, solution architects, IT management, Enterprise Architecture, and suppliers. You combine in-depth knowledge of cybersecurity and software development with a strong risk awareness and an independent 2LOD perspective. You know how to translate complex technical issues into clear risk assessments and pragmatic advice for both management and development teams. In this role, you get the opportunity to make a visible impact on the further professionalization of IT & Security within one of the largest fitness chains in Europe, in an international organization with an ambitious digital change agenda. You are capable of independently taking on complex dossiers, giving direction to improvement programs, and structurally raising the quality of decision-making around IT and security risks. In this role, you report to the IT Quality Officer of Basic-Fit International. You work within a broad network of stakeholders, including DevOps teams in Hoofddorp and Tilburg, responsible for business-critical digital platforms and applications used daily by millions of members and thousands of employees in six countries. In addition, you have regular contact with shared services teams, colleagues within the 2nd line, 1LOD officers, and external auditors. Your tasks: * Developing, implementing, and further professionalizing the 2LOD security assurance process for software development, in which you challenge DevOps teams and solution architects on Security by Design, Secure SDLC, and the effectiveness of security measures. * Contributing to the further development of the IT Control Framework, security policy, and governance processes. * Identifying and realizing opportunities to further professionalize the 2LOD IT Security function through the smart use of AI, AI agents, and process automation, so that risk assessments, assurance activities, and management reporting can be carried out more efficiently and at scale. * Preparing management reports, risk analyses, and advisory documents for IT management, the Executive Board, and the Audit & Risk Committee. Who are you? We are looking for an experienced security professional who feels comfortable at both a technical and strategic level. You understand how modern software is developed and can substantively challenge development teams, without being responsible yourself for the execution or management of security measures. If you are a strong technical security specialist but still developing in strategically advising and persuading executive management and senior stakeholders, we also invite you to apply. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [The Netherlands – Europe’s powerhouse for software development?](https://www.wearedevelopers.com/magazine/31-the-netherlands-europe-s-powerhouse-for-software-development) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)