Skip to content
MVPeopleGroup
GRC & Compliance

Business Information Security Officer (BISO)

Haarlemmermeer, NHSecondment (MVProfessionals)HybridSenioroverige

About the assignment

As BISO, you own security governance for your business unit or department. You translate enterprise security policies into practical controls, assess risks specific to your domain, and drive compliance with internal standards and external regulations.

You work closely with business leaders, IT operations, and the central security team. Your role is to embed security into business processes without slowing them down. You'll identify emerging risks, manage vendor security, and ensure incident response readiness.

Your responsibilities

  • Design and implement security controls aligned with business objectives and regulatory requirements
  • Conduct risk assessments for new projects, systems, and third-party integrations
  • Monitor compliance with security policies and coordinate remediation of findings
  • Lead security awareness and training initiatives within your business unit
  • Manage vendor and third-party security assessments and ongoing monitoring
  • Develop and maintain incident response procedures for your domain
  • Report security posture and emerging risks to business and security leadership
  • Collaborate with IT teams to implement security solutions and access controls

Tech Stack & Tools

Platforms & Tooling

ServiceNow GRCArcherCyberArkOktaEntra IDSplunkMicrosoft Sentinel

Frameworks & Standards

ISO 27001NIST Cybersecurity FrameworkCOBITCIS BenchmarksNIS2DORA

Cloud & Infrastructure

AWS Security HubAzure Security CenterGoogle Cloud Security Command Center

Methodologies

Risk management (FAIR, NIST RMF)Threat modelingControl framework designIncident response planning

Certifications (preferred)

CISSPCISMCRISCCISA

Must-haves

  • 5+ years in information security, compliance, or IT risk roles
  • Deep knowledge of ISO 27001, NIST frameworks, or equivalent standards
  • Experience with GRC platforms and security control assessment
  • Strong communication skills: translate security to non-technical stakeholders
  • Understanding of cloud security, IAM, and third-party risk management

Nice-to-haves

  • Experience in your industry vertical (banking, healthcare, government, etc.)
  • Familiarity with DORA, NIS2, or emerging regulatory frameworks
  • Background in IT audit or internal audit

What we offer

  • Strategic influence over security direction within your business unit
  • Cross-functional collaboration with business, IT, and leadership teams
  • Continuous learning budget for certifications and professional development
  • Flexible work arrangements and work-life balance
  • Competitive salary and pension scheme
  • Personal guidance from a dedicated MVPeople consultant who knows your niche

The process

1

Introduction

Phone call with your MVPeople consultant (within 24 hours)

2

Match & Brief

We discuss the assignment in detail and prepare you

3

Client meeting

Introduction to the client

4

Start

Contracting and onboarding

Details

Type

Secondment (MVProfessionals)

Location

Haarlemmermeer, NH

Work model

Hybrid

Level

Senior

Industry

overige

Market indication

€75,000 - €100,000 per year

Posted

3 September 2026

Job ID

57649



Contact

Apply nowMore information
Apply now