Information Security Officer at NN Group
Den Haag, , Netherlands -
Full Time


Start Date

Immediate

Expiry Date

13 Sep, 25

Salary

3517.0

Posted On

15 Jun, 25

Experience

4 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Service Providers, Learning, Reviews, Allowances, Measures, Security Controls, Oversight, Teams, Training, Control Framework, Application Security, Reporting, Information Security

Industry

Information Technology/IT

Description

As an Information Security Officer, you play a key role in NN Bank’s technological journey to become the digital retail bank of the Netherlands. You will have the opportunity to define and implement security standards and further improve the security of our applications and platforms and support our DevOps teams in their secure development and maintenance of advanced applications and technologies as well as the security aspects in contracting and contract maintenance.

Responsibilities

Within NN Bank we have some in-house developed and hosted applications, and also a large state of the art Cloud footprint and uses several SaaS solutions – they all belong to their own Business Lines. Business Lines are supported by their own DevOps teams, and you will be working in close collaboration with them.
In this role you will be seen as the information security expert serving the DevOps teams within a particular line of business. You additionally keep an oversight on overall Bank Security posture and contribute to the definition and implementation of security improvements.
As an information security officer, you will advise and support teams in security assessments and mitigate their risks. You will also play a role in improving their security knowledge and help them improve their security and risk posture by reviewing and verifying if measures are implemented correctly.
In summary, your role as team member of the security team is to define, review and support implementing the security standards and guidelines for a structured and well-aligned way of working for information security and compliance.

Your responsibilities

  • You are the trusted security advisor to your aligned business line on all their IT security requirements. You will serve as the primary liaison on security matters for DevOps teams, providing support, guidance, and training on security-related issues. Moreover, you will be responsible for driving impact and security initiatives within the boundaries of the assigned client domain
  • You will be responsible for overseeing and managing the control tracking, reviews, reporting, and support of the Information Technology Control Framework (ITCF). This will involve conducting reviews of IT Security controls for quality and completeness
  • Assessing (new) service providers regarding their security compliance posture (Vendor Security Assessment)
  • Initiate and implement improvement opportunities in existing processes
  • Supporting and coaching DevOps teams in their secure software development process and promoting (cloud-native) application security
  • Identify current and emerging security technologies, trends, vulnerabilities, and threats, and playing an active part in managing risks. Create operational overview of Security Compliance status for your business line in terms of
  • Provides oversight with regard to overall security posture
  • Security incidents
  • Security vulnerabilities and Security Mis-Configurations
Loading...