More jobs:
Technical Information Security Officer
Job in
3090, Rotterdam, South Holland, Netherlands
Listed on 2026-05-30
Listing for:
MS Amlin
Full Time
position Listed on 2026-05-30
Job specializations:
-
IT/Tech
Cybersecurity, Information Security
Job Description & How to Apply Below
Opportunity
We are seeking a Security Officer to lead security governance, risk, compliance, and assurance across MSIG Specialty Marine.
This high‑impact, organisation‑wide role will shape the security posture of the business while ensuring alignment with the security strategy of our global parent organisation.
Reporting directly to the Chief Financial Officer (CFO), you will own the security control framework and provide challenge, guidance, and assurance across security activities delivered by Security Analysts, internal IT teams (Architecture, Engineering, Platform & Service Management), and external security partners.
Responsibilities Security Governance & Strategy- Lead the development and maintenance of the organisation’s security governance framework.
- Translate and implement global CISO policies within the MSIG Specialty Marine environment.
- Define local security policies, standards, and control expectations.
- Establish effective governance forums and decision‑making processes.
- Ensure accurate reporting of security posture to Head Office.
- Lead the information security risk management framework across the organisation.
- Ensure compliance with group standards, internal policies, and regulatory requirements.
- Support internal and external security audits and manage evidence submissions.
- Maintain a robust assurance programme to monitor control effectiveness.
- Provide governance oversight of security operations delivered by internal teams and external SOC providers.
- Ensure effective threat detection, monitoring, and incident response capabilities.
- Oversee security incident management, escalation, and root‑cause analysis.
- Govern vulnerability management and ensure risk‑based remediation.
- Ensure security‑by‑design principles are embedded across technology solutions.
- Participate in architecture and design governance forums.
- Review proposed technology solutions and ensure alignment with security standards.
- Contribute to security reference architecture development.
- Define governance standards for cloud platforms, Microsoft 365, identity services, and endpoint security.
- Ensure strong configuration baselines, identity controls, and data protection measures.
- Oversee cloud security governance including privileged access, monitoring, and network protections.
- Work closely with the Data Protection Officer to support privacy governance.
- Define security requirements for business continuity, disaster recovery, and backup strategies.
- Ensure resilience plans and testing programmes are effective.
- Lead third‑party security risk assessments and vendor onboarding reviews.
- Ensure security requirements are embedded within procurement processes.
- Define and oversee the Secure Software Development Lifecycle (SSDLC).
- Ensure security controls are integrated across development pipelines.
- Govern application security practices including code scanning and vulnerability management.
- Support Dev Sec Ops practices across development teams.
- Extensive experience in information security governance, risk, and compliance.
- Experience operating within a three‑lines‑of‑defence model.
- Strong track record engaging senior leadership, auditors, and risk committees.
- Experience overseeing security operations and incident governance.
- Knowledge of secure software development lifecycle practices.
- Ability to translate technical risk into clear business language.
- Senior security governance experience in regulated industries (insurance, financial services, or similar).
- Strong understanding of frameworks such as ISO 27001, NIST CSF, DORA, and CIS Controls.
- Experience with cloud security (Azure), identity governance, and Zero‑Trust architecture.
- Proven experience supporting regulatory compliance and audit programmes.
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or related discipline.
- CISSP
- CISM
- CRISC
- ISO 27001 Lead Auditor / Implementer
- 30 days annual leave (based on a 40‑hour work week).
- 13th‑month salary bonus.
- Bike lease scheme for sustainable commuting.
- 50% contribution to additional health insurance.
- Contribution to sports and wellness memberships.
- A modern office environment in central Rotterdam.
- A collaborative and supportive team culture.
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×