Skip to content

Information Security Officer

  • Hybrid
    • Amsterdam, Noord-Holland, Netherlands

Job description

Nmbrs is looking for a Senior Information Security Officer to join our team in our Amsterdam office. As we scale across the Nmbrs suite of entities, keeping our systems and customer data secure is critical to maintaining trust, and you'll be at the center of making that happen, shaping our security posture end to end.

Who is Nmbrs?

We're a fast-growing scale-up building innovative HR & payroll technology. With 170+ colleagues in Amsterdam, Lisbon, and Stockholm, we do things differently. No traditional managers, a 4-day workweek, and the freedom to make an impact.

Your role

As Information Security Officer, you protect Nmbrs' digital data and systems from cyber threats, breaches and data loss. You build and maintain the security rules that keep us safe, run risk assessments, close system weaknesses, and make sure the company stays on the right side of data and security law. You own operational and technical security end to end: policies and standards, incident response, vulnerability management, security awareness, and compliance with security regulation. You'll work closely with the DPO and with security liaisons across the Nmbrs suite entities.

Job requirements

Your impact

  • Own the ISMS, keep the ISO 27001 certification and ISAE3402 audit current, ensure compliance with the Visma Security Program and track regulatory drivers such as NIS2and GDPR that affect Nmbrs' security posture.

  • Develop and maintain security policies and standards, run risk assessments, and verify that control measures are actually effective in practice.

  • Help shape our security architecture and access management approach, and make sure security is considered early in how squads build and ship software.

  • Plan audits, coordinate evidence collection, act as the main contact for auditors, and follow up on findings until closure.

  • Stay hands-on with firewalls, cloud security and system logs, and drive vulnerability management with the squads.

  • Investigate and mitigate security incidents and data breaches, and turn lessons learned into concrete improvements.

  • Set clear guidelines for safe computer, network and AI use, build a security-aware culture across the organization, from phishing to onboarding/offboarding processes, and be the go-to person for security questions.

  • Assess the security of vendors and new tools before onboarding, and answer customer security questionnaires.

  • Translate technical risks and threat trends into language non-technical colleagues and the leadership team can act on.

You bring

  • A bachelor's degree in Computer Science, Cybersecurity, or a related field.

  • A recognized security credential such as ISO 27001 Lead Implementer/Auditor, CISSP, or CISM - or a clear willingness to obtain one.

  • Broad experience across the security spectrum: technical (cloud, network, systems) as well as governance, risk, audits and compliance.

  • Comfortable working hands-on with firewalls, cloud environments and system/audit logs when needed.

  • The ability to explain technical risk clearly to non-technical colleagues and leadership.

  • Experience working in a SaaS environment.

Nice to have:

  • Fluency in Dutch.

We offer

  • We offer a gross monthly salary of 5700€ to 7000€  (depending on experience).

  • Nmbrs is a flat organization where you have the freedom and responsibility to do what you're good at and make an impact in an agile work environment.

  • A fully covered pension plan with a 15% contribution by Nmbrs.

  • A personal coach to support your personal and professional growth, plus an annual budget for training and development.

  • A healthy work-life balance: for us, full-time means working a 4-day week, giving you one day to focus on what matters most to you

  • Hybrid working flexibility.

  • As part of Visma, you’ll have access to a wide range of development opportunities, including trainings, events, and professional networks.

  • The opportunity to go on an exchange to one of our international offices for up to 4 months.

Please note: We are not able to consider candidates who are not living and working in the Amsterdam Area at this time, and we do not provide relocation sponsorships.

As part of our hiring process, we conduct a criminal background check for all candidates reaching the final stages to ensure a safe and secure environment for everyone.

At Nmbrs, we celebrate diversity and promote an inclusive environment where people from all backgrounds, ages, genders, and orientations feel equally valued.

or