Information Security Officer (ISO)
Embark on an exciting journey with us at Hotelschool The Hague! We're on the lookout for a dynamic Information Security Officer to be a key player in our multidisciplinary team. In this role, you'll collaborate closely with the Chief Information Security Officer, contributing to new projects, risk monitoring, and the implementation of robust controls. If you're passionate about information security, enjoy a friendly yet challenging environment, and want to be part of a renowned educational institution with a 95-year legacy, this opportunity is for you! Apply now and be at the forefront of shaping the future of security in our organization.
General function description
The Information Security Officer (ISO) advices management in implementing security controls, contributes to/leads security related projects, coordinates and performs risk monitoring activities, prepares risk reports and maintains the control framework (via GRC tooling). The Information Security Officer also gives substance to the information security -function on a tactical / operational level.
Fluency in both Dutch and English languages is essential for this role, requiring excellent communication skills in both languages.
You will:
- Support the CISO in reporting to management.
- Providing solicited and unsolicited (proactive) advice on cybersecurity issues.
- Assist management in the operationalization of security policies.
- Lead or participate in projects according to the Security roadmap.
- Assist in (the coordination of) external and internal audits.
- Perform operational risk management: advice management on classification, risks assessments and risk treatment. Participate in DPIA’s.
- Assist in the implementation of mitigating security controls in projects, applications, systems and processes.
- Monitor and report on (residual-) risks and control effectiveness.
- Contribute in the process of educating stakeholders on security related competencies (‘awareness’).
- Handle security incidents and act as an advisor in other incidents and data-leaks.
- Advice on change requests, participate in Change Advisory Boards.
- Advice the IT department on security management.
- Participate in (the organization of) crisis exercises.
- Participate in supplier risk management activities.
- Education organizations work closely together: participating in events and external collaboration is part of the job.
- Develop and share knowledge. Nobody knows everything: developing and sharing our knowledge with team members is vital to optimal support the organization.
- Work closely with the CISO in planning tasks and deciding on supporting tools and approach: the security function is new to the organization and needs to be finetuned.
· Support the current (small) multi-disciplinary team of cybersecurity professionals and developing this team further towards the next level of maturity and services provided by the Privacy and information Security Office.
· Report periodically to the CISO on the status of information security, awareness, information security incidents and their handling.
Candidate profile
You have/are:
- HBO / WO working and thinking level.
- CISM, CISSP or SSCP certification is a plus.
- Knowledge of the Government Information Security Baseline (BIO/NBA), ISO 27001/2 (International Standards for Information Security) and NIS2 (Network and Information Security Directive).
- At least two years of work experience in an information security profession.
- Basic knowledge of the General Data Protection Regulation (AVG).
- Broad theoretical knowledge in the field of privacy & information security.
- Management and advisory skills.
- Good communication skills (oral and written) to convey (the importance of) cybersecurity to all levels within the organization and maintain contact with external stakeholders and suppliers.
- Experience with managing cybersecurity projects.
- Experience with supervising compliance with policy, including supervising security audits.
- Experience with supervising technical and organizational measures for information security.
- Proven track record implementing a security control framework.
- Experience with analyzing data and preparing management information.
- Excellent spoken and written proficiency both in Dutch and English.
Remuneration
Hotelschool The Hague offers a salary based on scale 11 the labour agreement of Universities of Applied Science (CAO HBO) with a range between € 4.535,76 and € 6.359,47 gross per month, depending on your professional experience and qualifications.
In addition, Hotelschool The Hague offers:
- A 13th month;
- An excellent package of fringe benefits;
- Employees with a 40-hour working week are entitled to 428 hours (53 days) of leave annually with retention of salary;
- Excellent opportunities for further personal development;
- Compensation towards your health insurance expenses;
- Option to make use of group discounts for multiple insurances;
- Travel allowances for commuting to and from work;
- A pension plan through ABP;
- Most importantly you would work for an organisation that strives to have a positive impact on society, helping to develop future leaders in the hospitality industry.
Additional information
Hotelschool The Hague works with a 40-hour workweek. The starting date for this position is as soon as possible.
Additional information can be provided by Mr Tim van Leeuwen, Manager Facility & Real Estate.
An English language proficiency test may be part of the selection procedure. Upon receiving an offer, a certificate of conduct (VOG) is required.
How to apply
We look forward to receiving your English CV and motivation letter to attention of Menno Koeslag through the link below.
- Department
- Facility & Real Estate
- Locations
- The Hague/ Amsterdam
- Remote status
- Hybrid