Business Information Security Officer (BISO)

PwC Nederland

Amsterdam

Hybrid

EUR 110,000 - 140,000

Full time

8 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive salary
Permanent contract
Training programs
Mobility options
Vacation days
Well-being budget
OpenUp access
Hybrid working

Job summary

PwC Netherlands is seeking a security governance leader to own internal control, audit readiness, and the implementation of ISO 27001, SOC 2, NIS2, and DORA across the firm. You will shape PwC NL's approach to AI governance and drive our annual security risk assessment with direct impact on how we manage risk.

Join a collaborative CISO office of ambitious professionals, translate global policy into practical standards, work with auditors, business stakeholders, and technology teams, and report

Qualifications

  • 5+ years of experience in information security, governance, compliance, risk management, and internal control.
  • Hands-on experience implementing ISO 27001, SOC 2, and NIS 2.
  • Knowledge of AI governance and emerging technology controls.
  • Fluent Dutch at a professional level.
  • Strong audit and control testing experience.

Responsibilities

  • Lead the CISO office's work on internal PwC control framework and SME for internal audit, including preparation, evidence testing, remediation tracking, and control maturity improvement.
  • Drive implementation and improvement of ISO 27001, SOC 2, NIS2, and DORA, and manage the CISO office pillar of PwC NL's internal IT Unified Control Framework.
  • Lead the annual security risk assessment and manage PwC NL's security awareness campaigns.
  • Implement and maintain the firm's approach to AI governance and risk management, including policy development, risk assessment, control definition, and oversight of responsible use.
  • Partner with internal committees and lines of service to ensure security, risk, and control requirements are understood and embedded across the business.

Skills

Information security
IT governance
Compliance
Risk management
Internal control
Dutch language

Job description

Job Description & Summary

Do you want to shape how PwC Netherlands protects its people, clients, and data in a rapidly changing regulatory landscape? Are you ready to take ownership of security governance, risk, and compliance across one of the country's leading professional services firms?

Do you want to shape how PwC Netherlands protects its people, clients, and data in a rapidly changing regulatory landscape? Are you ready to take ownership of security governance, risk, and compliance across one of the country's leading professional services firms?

In this role you'll lead the CISO office's work on internal control, audit readiness, and the implementation of frameworks like ISO 27001, SOC 2, NIS2, and DORA. You'll also help shape PwC NL's approach to AI governance and drive our annual security risk assessment. It's a visible role with direct impact on how we manage security risk across the member firm.

This Is What You'll Do

You'll join the CISO office, a team of informal and ambitious professionals who work closely together on meaningful, firm-wide security topics. You'll act as a subject matter lead on internal security, risk, and control initiatives, translating global policy into practical standards and ways of working for PwC NL. You'll work hands‑on with auditors, business stakeholders, and technology teams to embed security into our day-to-day operations, while also driving forward strategic programs around resilience, regulatory readiness, and AI governance. You'll report regularly to senior stakeholders on control status, audit findings, regulatory readiness, and risk themes.

  • Lead the CISO office's work on the internal PwC control framework and act as SME for internal audit, including preparation, evidence testing, remediation tracking, and control maturity improvement.
  • Drive the implementation, upkeep, and continuous improvement of ISO 27001, SOC 2, NIS2, and DORA, and manage the CISO office pillar of PwC NL's internal IT Unified Control Framework.
  • Lead the global and local annual security risk assessment and manage PwC NL's security awareness campaigns.
  • Implement and maintain the firm's approach to AI governance and risk management, including policy development, risk assessment, control definition, and oversight of responsible use.
  • Partner with internal committees and lines of service to ensure security, risk, and control requirements are understood, workable, and embedded across the business.
You recognize yourself in this

You're a proactive professional who combines a structured, consultative approach with a hands‑on delivery mindset. You communicate practively and clearly with both technical teams and business stakeholders, and you know when to set firm guardrails and when flexibility is the smarter choice.

  • 5+ years of professional experience in information security, IT governance, compliance, risk management, and internal control.
  • Hands‑on experience implementing and maintaining ISO 27001, SOC 2, and NIS 2 (not only advising on them); security project management experience is a strong plus.
  • Solid understanding of internal audit processes, control testing, issue remediation, and how to build evidence that meets regulator and auditor standards.
  • Knowledge of AI governance, AI risk, and emerging technology controls, plus previous hands‑on IT or cybersecurity experience as a strong advantage.
  • Previous hands‑on IT, or cybersecurity experience during your early career stages is a strong advantage.
  • Fluent in Dutch at a professional level.
What We Offer
  • With us you get the chance to be yourself, bring out the best in yourself in a high-performance organization, and grow within our global network. We offer you, among other things:
  • A competitive salary in line with your experience, an annual bonus (depending on results and personal development), and the opportunity to grow further in your career;
  • A permanent contract from day one and a motivating work environment where collaboration with ambitious colleagues and recognition of your contributions are central;
  • A wide range of tailor‑made training programs focused on professional growth and leadership development;
  • The option to use various mobility providers (OV) via one convenient app;
  • 32 vacation days and the option to purchase additional leave;
  • At PwC, your well‑being is our priority. That's why we offer a personal well‑being budget to support your physical and mental health, as well as access to the well‑being platform OpenUp;
  • The opportunity to work on challenging and meaningful client engagements, use leading technology including AI tools, learn from the best, and be supported through coaching. Together we work as an inclusive team to make real impact;
  • The flexibility of hybrid working, including a fully equipped home office and a monthly net expense allowance for internet and other costs;
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Business Information Security Officer (BISO)
Business Information Security Officer (BISO)

PwC South Africa • Amsterdam

On-site
Confidential
Competitive salary
Annual bonus
Permanent contract
+6
Security Operations Analyst
Security Operations Analyst

PwC South Africa • Utrecht

Hybrid
Confidential
Annual bonus
Training & leadership programs
Mobility app (OV) for travel
+2
Senior Consultant IT Risk & Control (FS)
Senior Consultant IT Risk & Control (FS)

PwC Nederland • Amsterdam

Hybrid
EUR 60,000 - 80,000
Competitive salary
Attractive pension plan
Customized training
+3
Senior Consultant Internal Audit & Control
Senior Consultant Internal Audit & Control

PwC Nederland • Amsterdam

Hybrid
EUR 70,000 - 90,000
Hybrid working
Well-being budget
30 vacation days per year
+1
Security Governance & Risk Lead - ISO 27001, AI
Security Governance & Risk Lead - ISO 27001, AI

PwC South Africa • Amsterdam

Hybrid
Confidential
Competitive salary
Annual bonus
Permanent contract
+6
(Senior) Manager Cyber Security
(Senior) Manager Cyber Security

IBgids • Amsterdam

On-site
EUR 120,000 - 160,000
Jaarlijkse bonus
Snelle doorgroei
Onbepaalde tijd
+4
Senior Consultant SOX
Senior Consultant SOX

PwC Nederland • Amsterdam

Hybrid
EUR 70,000 - 95,000
Hybrid work model
Well-being budget
30 vacation days
+1
Security Governance & Risk Leader (Hybrid)
Security Governance & Risk Leader (Hybrid)

PwC Nederland • Amsterdam

Hybrid
EUR 110,000 - 140,000
Competitive salary
Permanent contract
Training programs
+5
Senior Cybersecurity Solutions Consultant
Senior Cybersecurity Solutions Consultant

EPAM Systems • Amsterdam

Hybrid
EUR 110,000 - 150,000
26 paid holiday days
Pension plan scheme
Disability insurance (WGA Shortfall)
+8
Senior Cybersecurity Solutions Consultant
Senior Cybersecurity Solutions Consultant

EPAM Systems • Rijswijk

Hybrid
EUR 90,000 - 130,000
Paid holidays
Pension plan
Disability insurance
+8