Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
PwC Netherlands is seeking a security governance leader to own internal control, audit readiness, and the implementation of ISO 27001, SOC 2, NIS2, and DORA across the firm. You will shape PwC NL's approach to AI governance and drive our annual security risk assessment with direct impact on how we manage risk.
Join a collaborative CISO office of ambitious professionals, translate global policy into practical standards, work with auditors, business stakeholders, and technology teams, and report
Do you want to shape how PwC Netherlands protects its people, clients, and data in a rapidly changing regulatory landscape? Are you ready to take ownership of security governance, risk, and compliance across one of the country's leading professional services firms?
Do you want to shape how PwC Netherlands protects its people, clients, and data in a rapidly changing regulatory landscape? Are you ready to take ownership of security governance, risk, and compliance across one of the country's leading professional services firms?
In this role you'll lead the CISO office's work on internal control, audit readiness, and the implementation of frameworks like ISO 27001, SOC 2, NIS2, and DORA. You'll also help shape PwC NL's approach to AI governance and drive our annual security risk assessment. It's a visible role with direct impact on how we manage security risk across the member firm.
You'll join the CISO office, a team of informal and ambitious professionals who work closely together on meaningful, firm-wide security topics. You'll act as a subject matter lead on internal security, risk, and control initiatives, translating global policy into practical standards and ways of working for PwC NL. You'll work hands‑on with auditors, business stakeholders, and technology teams to embed security into our day-to-day operations, while also driving forward strategic programs around resilience, regulatory readiness, and AI governance. You'll report regularly to senior stakeholders on control status, audit findings, regulatory readiness, and risk themes.
You're a proactive professional who combines a structured, consultative approach with a hands‑on delivery mindset. You communicate practively and clearly with both technical teams and business stakeholders, and you know when to set firm guardrails and when flexibility is the smarter choice.