Skip to content

Information Security Officer

  • Hybrid
    • Amsterdam, Noord-Holland, Netherlands

Job description

Nmbrs is looking for a Senior Information Security Officer to join our team in our Amsterdam office. As we scale across the Nmbrs suite of entities, keeping our systems and customer data secure is critical to maintaining trust, and you'll be at the center of making that happen, shaping our security posture end to end.

Time to grow. Time to thrive.

We are Nmbrs. We build smart business software that removes unnecessary complexity for SMEs and the professionals who support them. Nmbrs brings together four established product organisations—Payroll, Accounting, Invoicing and Reporting—with teams across the Netherlands, Sweden and Portugal.

We are one brand with a shared ambition, while continuing to work from the expertise and strengths of our individual organisations. We join forces where it makes sense, while keeping teams, expertise and decision-making close together.

For this role, you’ll join Nmbrs Payroll in Amsterdam, working closely with the colleagues in your local team while being part of the wider Nmbrs organisation.

Your role

As Information Security Officer, you protect Nmbrs' digital data and systems from cyber threats, breaches and data loss. You build and maintain the security rules that keep us safe, run risk assessments, close system weaknesses, and make sure the company stays on the right side of data and security law. You own operational and technical security end to end: policies and standards, incident response, vulnerability management, security awareness, and compliance with security regulation. You'll work closely with the DPO and with security liaisons across the Nmbrs suite entities.

Job requirements

Your impact

  • Own the ISMS, keep the ISO 27001 certification and ISAE3402 audit current, ensure compliance with the Visma Security Program and track regulatory drivers such as NIS2and GDPR that affect Nmbrs' security posture.

  • Develop and maintain security policies and standards, run risk assessments, and verify that control measures are actually effective in practice.

  • Help shape our security architecture and access management approach, and make sure security is considered early in how squads build and ship software.

  • Plan audits, coordinate evidence collection, act as the main contact for auditors, and follow up on findings until closure.

  • Stay hands-on with firewalls, cloud security and system logs, and drive vulnerability management with the squads.

  • Investigate and mitigate security incidents and data breaches, and turn lessons learned into concrete improvements.

  • Set clear guidelines for safe computer, network and AI use, build a security-aware culture across the organization, from phishing to onboarding/offboarding processes, and be the go-to person for security questions.

  • Assess the security of vendors and new tools before onboarding, and answer customer security questionnaires.

  • Translate technical risks and threat trends into language non-technical colleagues and the leadership team can act on.

You bring

  • A bachelor's degree in Computer Science, Cybersecurity, or a related field.

  • A recognized security credential such as ISO 27001 Lead Implementer/Auditor, CISSP, or CISM - or a clear willingness to obtain one.

  • Broad experience across the security spectrum: technical (cloud, network, systems) as well as governance, risk, audits and compliance.

  • Comfortable working hands-on with firewalls, cloud environments and system/audit logs when needed.

  • The ability to explain technical risk clearly to non-technical colleagues and leadership.

Nice to have:

  • Fluency in Dutch.

  • Experience working in a SaaS environment.

We offer

  • A salary range of €5.700 to €7.000 gross per month (excluding holiday allowance), depending on your experience;

  • Nmbrs is a flat organization where you get the freedom and responsibility to do what you’re good at and make an impact in a flexible, agile working environment;

  • A fully covered pension plan with a 15% employer contribution;

  • A personal coach who supports your personal and professional growth, plus an annual training budget;

  • A healthy work-life balance: at Nmbrs, full-time means a 4-day workweek, giving you an extra day for what matters most to you;

  • Hybrid working;

  • As part of Visma, you get access to a wide range of development opportunities, including training, events and professional networks;

  • The opportunity to spend up to 4 months on an exchange at one of our international offices;

  • A spacious and bright office close to Amsterdam Sloterdijk station, with elevator access to all floors;

  • A pet-friendly workplace — feel free to bring your four-legged friend along.

Application process

  1. Equalture assessment – You start with a series of neuroscience-based games via Equalture.

  2. Cultural interview – An online conversation with one or two of our recruiters to get to know each other and see if there's a good cultural match.

  3. Technical interview – You'll come to our office in Amsterdam and meet two colleagues who will dive deeper into your knowledge, experience, and approach.

  4. Final interview – A last conversation with our COO about the role, your ambitions, and what a potential collaboration could look like.

or