This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Business Information Security Officer (BISO) function covers a broad scope. As the team is small, work is shared and redistributed based on demand and skillset, so you will have the opportunity to contribute across domains when required. We are specifically looking for strong depth in governance, risk, and awareness; this is where you will spend most of your time.You will help maintain clear oversight of information security risk and support early risk signaling across the organisation. This is a hands-on individual contributor role in a high-performance environment. You will report to the team lead of the Global Business Information Security Officer, based in Amsterdam, and partner closely with colleagues across multiple time zones.
Job Responsibility:
Establish, maintain, and improve information security policies and procedures that reflect regulatory requirements and how the business operates in practice
Translate regulatory, legal, and risk requirements into clear internal expectations and documented risk considerations
Maintain and evolve the risk register, support structured risk reviews, and surface emerging risks early with clear, structured analysis
Define learning objectives and design security training and phishing campaigns aligned to policy and risk themes
Prepare structured input for periodic reporting
Requirements:
4–7 years of relevant experience in information security risk or compliance, ideally in an in-house environment
Solid understanding of information security, including non-technical domains such as governance, policy, awareness, and behavioral risk
Experience establishing, maintaining, or improving information security policies and procedures in a practical business context
Experience translating regulatory or legal requirements into clear internal expectations and documentation
Strong writing skills, with the ability to express complex topics clearly and concisely
Experience maintaining a risk register and supporting risk reviews