Amsterdam
The primary purpose of your role as Information Security Officer is to guide Prothya in protecting the confidentiality, integrity, and availability of information at Prothya, with the underlying goal to keep our information secure. This applies to analogue and digital information in all locations where Prothya operates. As an Information Security Officer, you act as our information guardian, which is achieved by implementing security policies and measures, creating protocols and instructions, educating employees, responding to threats and monitoring security events. You are the Subject Matter Expert in information security, and are the one that people can approach with any questions they might have.
Key accountabilities:
1. Developing security policies
Develop a coherent and integrated set of information security policies, measures, guidelines, and procedures, and embed them within Prothya’s quality management system. Ensure these policies and procedures are continuously maintained and regularly updated to remain aligned with both internal changes and external developments.
2. Implementing security measures
Based on policies and risk assessments, coordinate the implementation of the measures and guidelines into tangible security controls. Oversee implementations such as firewalls, authentication methods, access controls, encryption and data classification.
3. Conducting risk assessments
Plan and conduct risk assessments to identify potential threats and vulnerabilities that could compromise information security, and evaluate the likelihood and potential impact of such risks. Clearly report on the findings and use these insights to recommend new or refined policies and measures aimed at effectively mitigating identified risks.
4. Educating and training employees
Raise awareness about cybersecurity threats and best practices through training programs and initiatives, in alignment with policies. For example, share security tips with end users by using available communication methods such as the intranet and information screens.
5. Responding to security incidents
Investigate security incidents—such as data breaches, lost or stolen devices, cyberattacks, and alerts of suspicious behaviour—by following established protocols for analysis, response, and resolution. Ensure thorough and accurate reporting throughout the process, while taking immediate action to contain any damage. Implement appropriate corrective measures and follow-up actions to prevent recurrence and strengthen overall security resilience.
6. Staying current with evolving threats
Stay up-to-date on the latest threats and adapt strategies accordingly, which you accomplish by following public available sources in the information security sector, joining security focused communities and attending security conferences, seminars and events.
7. Monitor & Report
Use various tools and techniques to monitor the network, computer systems and applications for suspicious activity, potential breaches and vulnerabilities. Request penetration tests to review the infrastructure vulnerabilities and oversee mitigating actions by responsible SME’s to counteract for potential security incidents. Report to management on various security metrics based on aggregated security data.
8. Resource for information about cybersecurity
Act as the Subject Matter Expert on information security at Prothya, providing clear and reliable guidance across the organization. Serve as the primary point of contact for all cybersecurity-related questions, offering expert advice and support to colleagues at all levels, and positioning yourself as the go-to resource for anything related to information security.
Your profile:
What we offer:
Acquisitie wordt niet op prijs gesteld. Prothya aanvaardt geen ongevraagde hulp van bureaus voor deze vacature. Toegestuurde cv's (in welke vorm dan ook) door bemiddelingsbureaus aan enige medewerker van Prothya zonder geldige schriftelijke zoekopdracht, worden gezien als eigendom van Prothya waarvoor op geen enkele wijze een vergoeding verschuldigd is.