Jobs / engineering
Information Security Officer (ISO)
SendCloud · Eindhoven
About the role
📍Eindhoven HQ (3 days in office) | 🗓️ 40hrs per week
What you will do
- Own our ISO 27001 ISMS and keep it always-on — internal audits, evidence, management reviews, corrective actions, and external audit readiness.
- Run security risk management that leads to decisions — maintaining a living risk register, driving mitigations with owners and timelines, and enabling explicit risk acceptance when needed.
- Drive security governance that teams can actually use — practical policies and standards for access, data handling, vendor risk, and incident response.
- Lead security incident governance — classification, escalation, post-incident learning loops, and preventing repeats, in partnership with Platform, Engineering, and Support.
- Manage third-party and vendor security risk — risk tiering, due diligence, and working with Legal on security requirements and ongoing assurance.
- Enable safe use of AI and agentic workflows with clear guardrails, including visibility on shadow IT/AI in collaboration with IT and Platform.
- Report to leadership on security posture, top risks, incidents, audit outcomes, and progress.