Skip to content
MVPeopleGroup
CISO

Security Transformation Lead (Kwartiermaker)

UtrechtFreelance / ZZP (MVPeople)HybridLeadoverige

About the assignment

A major organisation is establishing a dedicated security function from scratch. You act as the 'Kwartiermaker' (pioneer) – the first security leader tasked with building the entire security operating model.

You will define security strategy, establish governance frameworks, design security architecture across cloud and on-premise infrastructure, and embed security into organisational culture. This is a strategic role with hands-on execution.

Your impact: transform security maturity from foundational to industry-leading within 18-24 months. You report to executive leadership and own the complete security roadmap.

Your responsibilities

  • Design and establish security governance framework aligned with ISO 27001, NIST CSF, and sector-specific regulations
  • Build the security operating model: processes, policies, roles, reporting lines, and escalation procedures
  • Conduct security baseline assessment and develop phased implementation roadmap
  • Establish IAM/IGA strategy including identity lifecycle management and access governance
  • Design SOC/security monitoring architecture and vendor selection (SIEM, EDR, NDR platforms)
  • Create security awareness and culture programme to embed security mindset organisation-wide
  • Develop vendor risk management and third-party security assessment programme
  • Report security posture, risks, and transformation progress to board and executive leadership

Tech Stack & Tools

Platforms & Tooling

SailPoint or Okta (IAM/IGA)Splunk or Sentinel (SIEM)CrowdStrike or Microsoft Defender (EDR)ServiceNow GRC (governance and compliance)

Frameworks & Standards

ISO 27001/27002NIST Cybersecurity FrameworkNIST IR and incident responseCOBITCIS Controls

Cloud & Infrastructure

Microsoft AzureAWS or Google Cloud (infrastructure security assessment)

Methodologies

Risk assessment and managementSecurity architecture designGovernance and compliance mappingVendor management

Certifications (preferred)

CISSPCISMCCISO

Must-haves

  • 10+ years cybersecurity experience with 5+ years in security leadership or CISO-equivalent role
  • Proven track record building security programmes from ground zero or transforming immature functions
  • Deep knowledge of governance frameworks (ISO 27001, NIST, COBIT) and regulatory compliance
  • Experience designing IAM, SOC, and GRC strategies and selecting/implementing platforms
  • Ability to communicate complex security concepts to non-technical board members and executives
  • Strategic mindset combined with hands-on execution capability

Nice-to-haves

  • Experience in your sector or similar organisational size
  • Vendor negotiation and contract management experience
  • Background in cloud security architecture (Azure/AWS)

What we offer

  • Define and own complete security strategy – rare greenfield opportunity
  • Build and lead a high-performing security team from the ground up
  • Direct access to C-suite and board-level influence on business decisions
  • Competitive compensation commensurate with seniority and impact
  • Personal guidance from a dedicated MVPeople consultant who knows your niche

The process

1

Introduction

Phone call with your MVPeople consultant (within 24 hours)

2

Match & Brief

We discuss the assignment in detail and prepare you

3

Client meeting

Introduction to the client

4

Start

Contracting and onboarding

Details

Type

Freelance / ZZP (MVPeople)

Location

Utrecht

Work model

Hybrid

Level

Lead

Industry

overige

Market indication

€165 - €225 per hour

Posted

18 August 2026

Job ID

57450



Contact

Apply nowMore information
Apply now