Vacature Junior IT Security officer in 's-Gravenhage bij Experis

  • Referentie nr.: 237712
  • Geplaats op: 2026-07-22
Plaats je CV - Bij meerdere uitzendbureaus tegelijk!

Vacature omschrijving

Bedrijfsomschrijving

Organizational Context.

The company operates in a regulated financial-services environment where data security, availability, resilience, and compliance are critical management objectives. Security activities are aligned to group-wide standards and control frameworks, including IT control frameworks, enterprise control frameworks, DORA-related resilience requirements, security reporting, and risk management processes.

The Junior IT Security Officer supports business-line execution and evidence gathering, while strategic security direction, prioritization, and governance remain with the Business Security Officer/ Business CISO and IT leadership.

Role Summary

We are seeking a Junior IT Security Officer with a practical technical background, affinity with cloud and application security, and an interest in risk, control, and regulatory compliance. The candidate will work closely with security stakeholders, IT operations, Product Owners, DevOps/application teams, ORM, and group-level security colleagues to support day-to-day security execution, monitoring, evidence collection, and reporting.

Functieomschrijving
  • Support the implementation and operation of the organization's IT Security approach across business applications, cloud environments, and supporting IT processes.
  • Support control performance and monitoring (e.g., ITCF), including evidence collection, control documentation, test-of-design/test-of-effectiveness preparation, and follow-up of improvement actions.
  • Monitor and report on vulnerabilities, security changes, open high-risk items, and related remediation progress for management reporting cycles.
  • Support DORA-related operational activities, including inputs for IT Risk Management, Incident Management, Operational Resilience Testing, and third-party provider risk management reporting.
  • Support access management and user access management (UAM) campaigns, including movers/leavers follow-up, role clean-up, control evidence, and exceptions tracking.
  • Maintain and improve operational security documentation, such as security guidelines, control evidence, action logs, dashboard inputs, and reporting packs.
  • Assist with risk assessments, security reviews, follow-up on technical security requirements, and application/control assessments.
  • Support security awareness activities and coordinate practical follow-up with Product Owners, engineers, DevOps teams, and business stakeholders.
  • Register, analyze, and report IT security incidents and operational security findings in line with applicable processes.
  • Cooperate with internal and external service providers, application developers, infrastructure teams, security operations, and group IT stakeholders.
  • Contribute to continuous improvement and simplification of security controls, reporting processes, and operational security checks.

Functie-eisen
  • Bachelor's degree.
  • General IT knowledge, including ITIL, Agile delivery, DevOps ways of working, and cloud/application infrastructure concepts.
  • Understanding of security requirements at a tactical and operational level, and how they align with security architecture and enterprise architecture.
  • Basic understanding of control frameworks such as ITCF/ECF, DORA, COBIT, or comparable risk/control frameworks.
  • Affinity with cloud security, identity and access management, vulnerability management, incident management, and security monitoring/reporting.
  • Ability to work with dashboards, action trackers, evidence repositories, and management-reporting inputs.
  • Hands-on ability with scripting or query languages such as Python, Kusto, or similar is a plus.
  • Strong communication skills in English and Dutch is preferred

Additional Useful Skills

  • Experience with threat assessments, technical security requirements, secure code review, or security-by-design reviews.
  • Understanding of SecDevOps, CI/CD controls, vulnerability scanning, SIEM/security event processes, and operational security procedures.
  • Experience supporting audits, control testing, evidence gathering, risk acceptances, or remediation tracking.
  • Security education or recognized certification such as CISSP, CSSP, CISM, CRISC, Azure/AWS security certification, or similar.
  • Affinity with the financial industry and regulated IT environments.

Personality Requirements

  • Analytical and structured, with attention to evidence, follow-up, and control quality.
  • Pragmatic and delivery-minded, able to work with both business and technical teams.
  • Curious, willing to learn, and comfortable asking clarifying questions.
  • Reliable and persistent in tracking actions to closure.
  • Collaborative, service-oriented, and able to work independently within clear governance boundaries.

Arbeidsvoorwaarden
  • The opportunity to work within one of the most innovative and respected financial institutions in the Netherlands;
  • A hybrid working model, combining two days a week in the office;
  • Salary between 3300 and 3800 based on 40 hours;
  • Holiday allowance;
  • 13th month;
  • 26 vacation days

Sollicitatieprocedure
Wil je meer informatie of heb je vragen over deze vacature neem dan contact op met Anique Prinse via anique.prinse@experis.nl of bel 0182-692020.

Relevante vacatures