CrawlJobs Logo

Information Security Expert

Netherlands, Amsterdam · Job Posted June 16, 2026
Apply Position
Job Link Share

Job Description

We are looking for an independent and highly skilled Information Security Expert to join our client’s team on an expertise-driven assignment. We are looking for a specialist who can hit the ground running to deliver comprehensive, end-to-end security audits within the critical domain of Supply Chain Security. If you are a self-starter who thrives on delivering deep-dive analyses and structured risk assessments in a collaborative environment, this project is for you.

Job Responsibility

  • Conduct detailed technical analyses, evidence gathering, root-cause identification, and actionable reporting
  • Evaluate control designs versus actual operational effectiveness using direct system evidence rather than design intent alone
  • Provide key insights into technical gaps, emerging security risks, and strategic improvement opportunities
  • Lead and conduct thorough end-to-end audits of systems, processes, SaaS platforms, and third-party vendors
  • Analyze technical configurations, including access controls, authentication mechanisms, security settings, and system behaviors
  • Review and interpret log files, audit trails, and system monitoring data to validate control effectiveness and locate weaknesses
  • Evaluate cloud, SaaS, and platform architectures against shared responsibility models to call out security and ownership gaps
  • Actively engage and collaborate with internal and external stakeholders, including Risk, Procurement, Contract Owners, and suppliers
  • Work aligned with DevOps & Agile methodologies within an international team

Requirements

  • Typically 6-8 years of experience in internal audit, security auditing, IT risk, compliance, or similar specialist roles
  • Proven experience auditing SaaS environments and cloud architectures is a strong plus
  • Demonstrated experience testing actual operational control effectiveness using direct system evidence and technical configurations
  • Solid understanding of IT platforms, applications, security architectures, and Identity and Access Management (IAM), including RBAC, PAM, access governance, and user lifecycle controls
  • Strong familiarity with industry standards and compliance frameworks such as ISO 27001, SOC 2, NIST, CIS, and GDPR
  • Comfort working in a hybrid, DevOps, and Agile environment
  • Full professional fluency in English (the working language of the team)
  • Ability to work in a hybrid setup (1-2 days per week from the office)
  • Willingness to travel abroad as required for audit-related activities

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

Information Security Expert

8 matching positions

Information Assurance Specialist – III (Information Security Analyst)

Barbaricum is seeking an experienced Information Assurance Specialist III (Infor...
Location
Location
United States , Indianapolis
Salary
Salary:
Not provided
barbaricum.com Logo
Barbaricum
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Active DoD Secret Clearance
  • Bachelor's degree in related field
  • Must meet DoDM 8140.03 IAT III/IAM II requirements
  • Minimum 10yr experience in network operations and information security
  • Demonstrated experience assessing security controls based on cybersecurity principles and tenets.(e.g., NIST SP 800-53, Cybersecurity Framework, etc.)
  • In-depth understanding of relevance of NIST Security Controls and Control Implementation methodologies to the SA&SA process
  • Relevant DOD, DHS or .gov Cyber Security Information Assurance focused experience with specific current hands-on researching, writing, and submitting complete A&A documentation packages for new system authorizations
Job Responsibility
Job Responsibility
  • Assess, implement, and validate cybersecurity controls in accordance with NIST SP 800-53, the NIST Cybersecurity Framework, and applicable DoD cybersecurity requirements
  • Support the Security Assessment and Authorization (SA&A) process by evaluating security controls, identifying risks, and recommending mitigation strategies
  • Develop, review, and maintain Assessment and Authorization (A&A) documentation packages to support system accreditation and authorization efforts
  • Conduct security assessments, vulnerability analyses, and compliance reviews to ensure systems meet federal and DoD cybersecurity standards
  • Collaborate with system owners, engineers, and cybersecurity teams to implement security controls and maintain a strong security posture across enterprise environments
  • Support continuous monitoring activities, including risk assessments, control validation, remediation tracking, and reporting
  • Provide cybersecurity guidance and recommendations related to information assurance, risk management, and regulatory compliance
  • Prepare technical reports, security documentation, and executive briefings to support authorization decisions and stakeholder requirements
  • Ensure compliance with Risk Management Framework (RMF), DoD policies, and applicable government cybersecurity regulations
  • Serve as a subject matter expert on information assurance, cybersecurity controls, accreditation processes, and security compliance initiatives
  • Fulltime
Read More
Arrow Right
New

Chief Information Security Officer

At Boeing, we innovate and collaborate to make the world a better place. We're c...
Location
Location
Australia , Brisbane
Salary
Salary:
Not provided
boeing.com Logo
Boeing
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Senior leadership experience in cyber and information security assurance ideally within Defence, national security, or critical infrastructure
  • Proven track record of building and leading successful teams
  • Deep knowledge of ISM, DSPF, DISP, and Defence accreditation processes, as well as familiarity with ISO 27001, NIST CSF, and NIST SP 800-171 frameworks
  • Demonstrated experience securing both IT and OT environments
  • Demonstrated experience leading regulatory compliance assessments/efforts pertaining to the ASD ISM and Essential Eight cybersecurity frameworks
  • Experience presenting complex security risks, strategies, and concepts in business terms to executive leadership and Board of Directors
Job Responsibility
Job Responsibility
  • Develop and implement a comprehensive information security and cyber defence strategy across Boeing Defence Australia and other regional subsidiaries, that integrates closely with the other non-cyber security domains
  • Advise the BDA CSO, executive leadership, and program directors on cyber risk management, threats, mitigation strategies and security investment
  • In close collaboration with Enterprise cybersecurity teams, ensure alignment between Australian requirements and Boeing global security standards
  • Ensure compliance with the ISM, DSPF, DISP, ASDEFCON security clauses, and Defence accreditation processes
  • Oversee IRAP assessments, system security plans, risk assessments, and continuous monitoring programs ensuring consistent implementation of ASD Essential Eight maturity targets
  • Lead cybersecurity for all IT and OT environments across Boeing Australia, including manufacturing systems, mission systems labs, sustainment facilities, and unmanned systems operations
  • Drive secure-by-design engineering for ICT, OT, cloud, and cross-domain solutions
  • Develop and oversee the Australian cyber defence capability, including SOC operations, threat intelligence, and incident response
  • Coordinate cyber incident management across BDA and other supported subsidiaries, in conjunction with local Boeing global IT and cyber teams, ensuring timely regulatory reporting is undertaken
  • Provide cybersecurity assurance for bids, platform upgrades, and sovereign capability programs
What we offer
What we offer
  • Competitive base pay and incentive programs
  • Industry-leading tuition assistance program pays your institution directly
  • Resources and opportunities to grow your career
  • Up to $10,000 match when you support your favorite nonprofit organizations
  • Fulltime
Read More
Arrow Right
New

Manager Information Security Office (ISO), Enterprise Data

Manager Information Security Office (ISO), Enterprise Data
Location
Location
United States , McLean, Virginia
Salary
Salary:
197300.00 - 225100.00 USD / Year
capitalone.com Logo
Capital One
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • High School Diploma, GED or equivalent certification
  • At least 4 years of experience working in cybersecurity or information technology
  • At least 1 year of experience providing guidance and oversight of Security concepts
  • At least 1 year of experience performing security risk assessments and security architecture reviews
  • At least 1 year of experience with architecture, software design, networking, and cloud infrastructure
Job Responsibility
Job Responsibility
  • Act as a central Information Security point of contact for Capital One’s Enterprise Data organization
  • Coordinate and execute proactive Information Security consulting to the business and technology teams covering API Security, File Transfer, Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, Datalake Architecture, BI, and consumption tools, and User Access Management
  • Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
  • Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
  • Escalate and manage cyber security risk
  • Provide ad hoc support on special Information Security hot topics for the business
  • Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
  • Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
What we offer
What we offer
  • Performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI)
  • comprehensive, competitive, and inclusive set of health, financial and other benefits
  • Fulltime
Read More
Arrow Right

Business Information Security Officer

Brown & Brown is seeking a Business Information Security Officer (BISO) to join ...
Location
Location
United States , Daytona Beach
Salary
Salary:
180000.00 - 200000.00 USD / Year
bbrown.com Logo
Brown & Brown UK
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • CISSP, CISM, or equivalent certifications (preferred)
  • BA/BS in business, security, or technology
  • 8–10+ years of experience in information security, cybersecurity, risk management, governance, physical security, or regulatory compliance, with a focus on business-aligned service delivery
  • Experience working with cross-functional teams
  • Working knowledge of ISO27001, NIST, Cyber Essentials and other security standards
  • Deep experience of security architecture and the tooling required to instantiate
  • Knowledge of Property & Casualty insurance is a plus
  • Experience running a SOC and working cyber incidents
  • Experience leading teams responsible for security across mid-to-large organizations (55+ people)
  • Strong understanding of organizational environments and their connection to external business drivers
Job Responsibility
Job Responsibility
  • Support the implementation, maintenance, and continuous improvement of information and physical security programs in alignment with corporate policies, standards, and frameworks
  • Contribute as a key member in shaping both the Brown & Brown security roadmap and divisional technology roadmap
  • Serve as a subject matter expert for information and physical security, supporting strategy development and execution
  • Provide guidance on prioritizing divisional investments that impact security
  • Allocate security resources (architecture, engineering, operations, risk management) to meet divisional needs
  • Support merger and acquisition activities, including pre-deal due diligence and post-deal 90-day security integration
  • Advise divisional leaders on security-related risk and assist in meeting broader risk management and compliance objectives
  • Monitor emerging security trends and assess potential impacts to divisions or profit centers
  • Ensure risk remediation processes are followed, issues are mitigated, and exceptions are tracked according to organizational standards
  • Manage IT certification and accreditation processes in collaboration with auditors and certification bodies
What we offer
What we offer
  • Health Benefits: Medical/Rx, Dental, Vision, Life Insurance, Disability Insurance
  • Financial Benefits: ESPP
  • 401k
  • Student Loan Assistance
  • Tuition Reimbursement
  • Mental Health & Wellness: Free Mental Health & Enhanced Advocacy Services
  • Beyond Benefits: Paid Time Off, Holidays, Preferred Partner Discounts and more
  • Fulltime
Read More
Arrow Right

Information Security Lead

We’re hiring a Lead of Information Security, reporting to the VP of Technical Op...
Location
Location
United States , Philadelphia
Salary
Salary:
Not provided
Proscia
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of experience in information security, including direct experience improving, and contributing to GRC programs
  • Proven expertise in regulatory frameworks such as ISO 27001, SOC 2, GDPR, HIPAA, FedRAMP, TX-RAMP, StateRAMP or similar
  • Hands-on experience with vulnerability management tools, incident response, and security audits
  • Experience embedding security into software development lifecycles—DevSecOps principles applied in practice
  • Experience selecting, implementing, and managing security tooling (e.g., XDR, SIEM, endpoint, code scanning, etc.)
  • Exceptional communication and influencing skills across technical and non-technical teams
  • A high degree of autonomy and ownership—comfortable leading cross-functional efforts and prioritizing in a dynamic environment
  • You already use AI tools in your security work—for policy drafting, threat analysis, log review, control validation, or however it fits your practice
  • Experience with cloud-native environments (AWS preferred)
  • Experience building with or on top of LLMs, AI agents, or agentic pipelines
Job Responsibility
Job Responsibility
  • Manage and evolve vulnerability management— tooling, reporting, and remediation governance
  • Serve as a consultative security leader for Engineering, Product, and Customer teams—governing system designs, architecture, and implementation through a security-first lens
  • Implement AI native tooling to improve detection and response capabilities without incurring an increased demand on resources
  • Partner with Engineering to implement developer-friendly security tools that improve security posture and reduce compliance burdens without slowing velocity
  • Oversee incident response preparation, processes, and execution—ensuring coordinated action, effective communication, and the kind of thorough post-incident analysis that prevents the same problem twice
  • Under the direction VP, TechOps, improve the Proscia Information Security Program, with a focus on governance, risk, and compliance (GRC) across the Concentriq suite of applications and Proscia’s business applications
  • Contribute to security policy development across regulated and non-regulated markets—implementing agentic workflows where it accelerates your research and stress-testing, iterating with stakeholders, and maintaining the rigor and compliance standards our customers expect
  • Influence and execute on the company’s regulatory roadmap—seeking new certifications and frameworks (e.g., ISO 27001, SOC 2, HITRUST) in response to customer and market demands
  • Enable other teams to answer security-related questions from customers, prospects, and partners providing expert information security guidance
  • Anticipate and adapt to industry and regulatory trends, including how AI is reshaping both the threat landscape and the defender’s toolkit—and surface emerging requirements before they become urgent
What we offer
What we offer
  • Competitive pay
  • Savings options
  • Schedule options
  • Insurance options that promote long-term health and personal growth
  • Office environment designed for creativity and agility with walls as notepads and couches for collaboration
  • Located in the heart of Philadelphia with views of the city
  • Fulltime
Read More
Arrow Right

Senior Information Security Specialist

SmartRecruiters is looking for a Senior Information Security Specialist to join ...
Location
Location
Poland
Salary
Salary:
Not provided
smartrecruiters.com Logo
SmartRecruiters
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of experience in information security, governance, risk, and/or compliance roles with a technical orientation
  • Demonstrated compliance or auditing experience with at least one major framework
  • Hands-on experience with incident response - including participation in security incident investigations, containment, and post-mortem processes
  • Solid understanding of controls auditing principles and evidence management
  • Technical understanding of cloud infrastructure (AWS preferred), networking fundamentals, identity management, and SaaS security architectures
  • Knowledge of risk management methodologies and experience conducting or supporting risk assessments
  • Ability to manage and deliver on multiple complex projects simultaneously, with minimal supervision
  • The ability to investigate, question, and interpret internal and external IT security and compliance issues at both a governance and technical level
  • A strong understanding of technology, cloud-based products, and SaaS environments
  • Experience working across business units and geographical boundaries to engage engineering, business, and operational teams
Job Responsibility
Job Responsibility
  • Identify manual, repetitive GRC processes and design automation blueprints to streamline them, including evidence collection, control monitoring, access reviews, policy enforcement checks, and compliance reporting
  • Build and maintain automated workflows using compliance platforms, scripting, or integration tools to reduce manual effort and improve audit-readiness
  • Develop reusable templates, playbooks, and standardised blueprints for recurring GRC activities (e.g., vendor assessments, internal audits, risk reviews) to ensure consistency and scalability
  • Collaborate with engineering and IT teams to integrate security and compliance checks into existing toolchains and CI/CD pipelines where applicable
  • Continuously evaluate and improve GRC tooling, data flows, and reporting to drive operational efficiency across the team
  • Manage stakeholder expectations and partner with internal teams to ensure effective management of IT risks and compliance obligations
  • Maintain regional and local stakeholder relationships, meeting schedules, minutes, and reports
  • Support the maintenance of the SOC 2 Type II framework, including evidence collection, control testing coordination, and audit support
  • Effectively manage ISO 27001 and ISO 22301 audit lifecycles and coordinate with stakeholders on ISMS and BCMS improvements
  • Support the maintenance and continuous improvement of the ISO 42001 (AI Management System) framework in alignment with the EU AI Act
  • Fulltime
Read More
Arrow Right

Senior Lead Information Security Office Consultant

As a Senior Lead Consultant in Capital One’s Cyber Information Security Office (...
Location
Location
United States , McLean
Salary
Salary:
229900.00 - 262400.00 USD / Year
capitalone.com Logo
Capital One
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • High School Diploma, GED or equivalent certification
  • At least 6 years of experience working in cyber security or information technology
  • At least 5 years of experience providing guidance and oversight of cyber security concepts
  • At least 4 years of experience performing cyber security risk assessments and cyber security architecture reviews
  • At least 4 years of experience with architecture, software design, networking or cloud infrastructure
Job Responsibility
Job Responsibility
  • Act as a central Information Security point of contact for a portfolio of customer servicing technology assets
  • Coordinate and execute proactive Information Security consulting to the business and technology teams covering Infrastructure Security, Resiliency, Data Security, Network Architecture and Design, and User Access Management
  • Serve as an expert in Capital One’s Information Security capabilities, solutions, policies, procedures and standards
  • Influence customers to leverage security capabilities and solutions to shift and integrate security to the left in the development processes
  • Escalate and manage cyber security risk
  • Provide ad hoc support on special Information Security hot topics for the business
  • Provide regular updates to executive leadership with your line of business on the overall Information Security health and risk environment
  • Work with line of business leadership to anticipate their objectives and needs to better serve the line of business
What we offer
What we offer
  • Performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI)
  • comprehensive, competitive, and inclusive set of health, financial and other benefits
  • Fulltime
Read More
Arrow Right

Lead Information Security Engineer - Python Full Stack Developer

Wells Fargo is seeking a Lead Information Security Engineer.
Location
Location
India , Hyderabad
Salary
Salary:
Not provided
https://www.wellsfargo.com/ Logo
Wells Fargo
Expiration Date
June 29, 2026
Flip Icon
Requirements
Requirements
  • 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 5+years of experience in Software Engineering, Data Engineering, or a backend development python development and backend architecture
  • Expert level knowledge of Python internals, concurrency (Asyncic/Multiprocessing) and building high performance, memory efficient applications
  • Proven expertise in designing and governing enterprise grade CI/CD pipelines and must manage complex code promotions across multi-region environments using GIT hub actions, Git Lab, or Azure DevOps
  • Extensive hands-on experience with Apache Kafka (or Confluent), including cluster tuning, schema registry management and designing event driven architectures
  • Deep experience with Grafana and Prometheus for full stack observability – defining SLIs/SLOs, custom exporters and complex alerting logic
  • Strong understating of the end-to-end ML life cycle, specifically in the deployment and scaling of models using frameworks like BentoML, Ray, or KServe
  • Experience in SQL, data modelling, ETL/ELT pipelines, and large-scale data processing
  • Good to have knowledge in Terraform, Palumi and container orchestration – Kubernetes, EKS
Job Responsibility
Job Responsibility
  • Lead computer security incident response activities for highly complex events
  • Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies
  • Provide security consulting on large projects for internal clients to ensure conformity with corporate information, security policy, and standards
  • Design, document, test, maintain, and provide issue resolution recommendations for highly complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security
  • Review and correlate security logs
  • Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
  • Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
  • Collaborate and influence all levels of professionals including managers
  • Lead a team to achieve objectives
  • Lead the development of mission critical python services, ensuring high availability and low latency performance
  • Fulltime
Read More
Arrow Right