About the assignment
You build and maintain the compliance infrastructure that keeps your organisation operating within legal and regulatory boundaries. You're responsible for translating complex regulations into actionable policies and procedures.
Your impact spans multiple domains: data protection, industry-specific mandates, internal controls, and third-party risk. You work cross-functionally with IT security, legal, and business units to embed compliance into operations rather than treat it as a checkbox exercise.
Your responsibilities
- Design and maintain compliance frameworks aligned with ISO 27001, NIS2, GDPR, and sector-specific regulations
- Conduct compliance gap assessments and remediation planning with measurable timelines
- Monitor control effectiveness through testing, audits, and evidence collection
- Prepare compliance reports and board-level summaries on regulatory status and emerging risks
- Manage audit relationships with internal and external auditors, including response to findings
- Drive policy development and update cycles across information security, data protection, and operational controls
- Coordinate third-party compliance questionnaires and vendor risk assessments
- Stay current on regulatory changes and advise leadership on implementation impact and costs
Tech Stack & Tools
Platforms & Tooling
Frameworks & Standards
Methodologies
Certifications (preferred)
Must-haves
- 5+ years in compliance, audit, GRC, or internal controls roles
- Hands-on experience with ISO 27001 implementation or maintenance
- Proven ability to interpret regulatory requirements and translate into controls
- Experience with compliance management tools (ServiceNow GRC, Archer, or equivalent)
- Strong stakeholder management across IT, legal, and business functions
Nice-to-haves
- Experience with NIS2, DORA, or GDPR implementation projects
- Background in financial services, healthcare, or critical infrastructure sectors
- Familiarity with audit frameworks (COBIT, NIST) and testing methodologies
What we offer
- Lead compliance strategy for a regulated organisation where your work directly protects the business
- Access to professional development budgets for certifications (CISA, CRISC)
- Collaborative environment with security, legal, and business leadership teams
- Clear career progression to Compliance Manager or Chief Risk Officer roles
- Flexible work arrangements with focus on delivery over location
- Personal guidance from a dedicated MVPeople consultant who knows your niche
The process
Introduction
Phone call with your MVPeople consultant (within 24 hours)
Match & Brief
We discuss the assignment in detail and prepare you
Client meeting
Introduction to the client
Start
Contracting and onboarding
Details
Type
Consultancy
Location
heerlen
Work model
Hybrid
Level
Medior
Industry
overige
Posted
5 June 2026
Contact
MVPeople Group
jobs@mvpeoplegroup.com