Information Security Officer

Prothya Biosolutions

Amsterdam

Description

The primary purpose of your role as Information Security Officer is to guide Prothya in protecting the confidentiality, integrity, and availability of information at Prothya, with the underlying goal to keep our information secure. This applies to analogue and digital information in all locations where Prothya operates. As an Information Security Officer, you act as our information guardian, which is achieved by implementing security policies and measures, creating protocols and instructions, educating employees, responding to threats and monitoring security events. You are the Subject Matter Expert in information security, and are the one that people can approach with any questions they might have.

Key accountabilities:

1. Developing security policies

Develop a coherent and integrated set of information security policies, measures, guidelines, and procedures, and embed them within Prothya’s quality management system. Ensure these policies and procedures are continuously maintained and regularly updated to remain aligned with both internal changes and external developments.

2. Implementing security measures

Based on policies and risk assessments, coordinate the implementation of the measures and guidelines into tangible security controls. Oversee implementations such as firewalls, authentication methods, access controls, encryption and data classification.

3. Conducting risk assessments

Plan and conduct risk assessments to identify potential threats and vulnerabilities that could compromise information security, and evaluate the likelihood and potential impact of such risks. Clearly report on the findings and use these insights to recommend new or refined policies and measures aimed at effectively mitigating identified risks.

4. Educating and training employees

Raise awareness about cybersecurity threats and best practices through training programs and initiatives, in alignment with policies. For example, share security tips with end users by using available communication methods such as the intranet and information screens.

5. Responding to security incidents

Investigate security incidents—such as data breaches, lost or stolen devices, cyberattacks, and alerts of suspicious behaviour—by following established protocols for analysis, response, and resolution. Ensure thorough and accurate reporting throughout the process, while taking immediate action to contain any damage. Implement appropriate corrective measures and follow-up actions to prevent recurrence and strengthen overall security resilience.

6. Staying current with evolving threats

Stay up-to-date on the latest threats and adapt strategies accordingly, which you accomplish by following public available sources in the information security sector, joining security focused communities and attending security conferences, seminars and events.

7. Monitor & Report

Use various tools and techniques to monitor the network, computer systems and applications for suspicious activity, potential breaches and vulnerabilities. Request penetration tests to review the infrastructure vulnerabilities and oversee mitigating actions by responsible SME’s to counteract for potential security incidents. Report to management on various security metrics based on aggregated security data.

8. Resource for information about cybersecurity

Act as the Subject Matter Expert on information security at Prothya, providing clear and reliable guidance across the organization. Serve as the primary point of contact for all cybersecurity-related questions, offering expert advice and support to colleagues at all levels, and positioning yourself as the go-to resource for anything related to information security.

Your profile:

  • Bachelor or Master degree in computer science, information technology, or cybersecurity.
  • Relevant security certificates such as “CISM”, “CISSP” or “C|CISO”.
  • > 5 years of experience in information technology jobs in general.
  • > 2 year of experience in the field of information security or cybersecurity.
  • Experience in writing and implementing security policies and processes.
  • Experience with ISO standards (for example: ISO27001).
  • Be familiar with actual and relevant security regulations, e.g. CIS-levels and NIS2.
  • Excellent communicative skills to explain the importance of information security.
  • Good motivational skills.
  • Skilled in negotiating with a variety of stakeholders.
  • Good writing skills in Dutch and English.

What we offer:

  • Full-time employment (40h) with flexible working hours in consultation. Working part-time can be discussed.
  • Salary between € 5.290,02 and € 7.604,37 euro gross per month based on full-time employment
  • 8.33% end-of-year bonus and 8.33% holiday allowance.
  • A personal training budget of €2,100 every three years to foster professional growth and development.
  • Contribution to travel expenses from the first kilometer.
  • Excellent accessibility by public transport and private parking available.
  • A pension plan with Zorg & Welzijn, providing security for your future.
  • A dynamic, safe, and challenging working environment with ample opportunities to grow, innovate, and learn, all while making a meaningful impact on the health of millions.

Acquisitie wordt niet op prijs gesteld. Prothya aanvaardt geen ongevraagde hulp van bureaus voor deze vacature. Toegestuurde cv's (in welke vorm dan ook) door bemiddelingsbureaus aan enige medewerker van Prothya zonder geldige schriftelijke zoekopdracht, worden gezien als eigendom van Prothya waarvoor op geen enkele wijze een vergoeding verschuldigd is.