GRC/IS Consultant

Software Search

Netherlands

Hybrid

EUR 9,000 - 11,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Laptop and phone
Training budget
Events & meetups
Flexible hours (32/36/40h)

Job summary

Software Search is seeking a GRC/IS Consultant to help clients gain control over risks, compliance, and information security. The role focuses on translating laws into practical policies, guiding audits, and increasing security awareness on challenging projects.

You will assess and implement GRC frameworks such as GDPR, NIS2, DORA, and ISO 27001, collaborating with management and stakeholders to deliver tangible improvements across organizations.

Qualifications

  • Higher professional or university degree in Information Security, IT, Law, or related field.
  • 5+ years of experience in GRC, information security, or a similar role.
  • Knowledge of GDPR, NIS2, DORA, ISO 27001, NEN 7510, and BIO.
  • Certifications such as CISM, CIPP/E, CRISC, CISSP or similar.
  • Excellent communication and stakeholder management; fluent in Dutch and English.

Responsibilities

  • Analyze processes and risks, develop and implement policies and procedures.
  • Guide internal and external audits and ensure regulatory compliance.
  • Advise management and translate IT/security topics into business language.
  • Develop risk assessments and deliver security awareness training.
  • Shape governance, risk, and compliance programs across client organizations.

Skills

Dutch (C1)
English fluent
Stakeholder mgmt
Communication
Security awareness
GRC frameworks

Education

Higher degree in Information Security/IT/Law
CISM
CIPP/E
CRISC
CISSP

Job description

GRC/IS Consultant

Salary: €10,000
Location: The Randstad
Type: Hybrid

Are you the GRC specialist who helps organizations gain control over risks, compliance, and information security? Do you get energy from translating laws and regulations into practical policies and processes, guiding audits, and increasing security awareness? Do you want to work on challenging projects without having to worry about sales? Then you may be the GRC/IS Consultant we are looking for.

With us, you will work on complex governance, risk, compliance, and information security challenges for leading clients. You advise on, implement, and optimize GRC frameworks, and you have the freedom to choose which projects suit you best. Whether your focus is on ISO 27001 implementations, NIS2 or DORA compliance, privacy by design, or security awareness programs, you can shape your path based on your expertise and interests.

What are you going to do?

Imagine this: you are starting a new project at a large organization. You begin by analyzing current processes and risks, developing and implementing policies and procedures, guiding internal and external audits, and helping ensure compliance with relevant laws, regulations, and security standards. You advise management, train employees in security awareness, and act as a sparring partner at different levels of the organization.

Your responsibilities may include:

  • Developing and implementing policies, procedures, and work instructions
  • Advising on compliance with regulations and frameworks such as GDPR, NIS2, DORA, ISO 27001, NEN 7510, and BIO
  • Guiding internal and external audits
  • Setting up and conducting risk assessments
  • Providing support during security incidents, such as data breaches
  • Developing and delivering security awareness training and campaigns
  • Advising management and stakeholders on governance, risk, and compliance
What are you bringing?
  • A completed higher professional or university degree, for example in Information Security, IT, Law, or a related field
  • Fluent Dutch, both spoken and written, at C1 level
  • At least 5 years of experience in GRC, information security, or a similar role
  • Experience with relevant laws, regulations, and frameworks such as GDPR, NIS2, DORA, ISO 27001, NEN 7510, and BIO
  • One or more relevant certifications, such as CISM, CIPP/E, CRISC, CISSP, or similar
  • Excellent communication skills and the ability to explain complex topics in a clear and understandable way
  • Strong stakeholder management skills and the ability to translate IT and security topics into business language
  • Fluency in both Dutch and English
You like this
  • Making risks manageable — helping organizations gain insight into risks and improve control
  • Turning frameworks into practice — translating rules and standards into workable, effective solutions
  • Supporting audits and certifications — guiding organizations through assessment and improvement processes
  • Building awareness — increasing security awareness through training and campaigns
  • Working across the organization — collaborating with both management and operational teams
You don’t like this
  • Vague policies — documentation that exists on paper but is not applied in practice
  • Box-ticking without impact — compliance efforts that lack real substance
  • Unclear documentation and responsibilities — poorly defined ownership and incomplete processes
What we offer
  • A permanent contract
  • The freedom to choose projects that match your specialization and ambition
  • A competitive compensation model
  • A 32, 36, or 40-hour work week
  • Optional work resources such as a laptop and phone
  • A training budget and internal knowledge sessions
  • Access to events, meet-ups, and professional communities
Application process
  • You apply — You will hear from us within 5 working days.
  • Initial meeting — We get to know each other and discuss your ambitions.
  • Technical interview — A conversation with one of our consultants to dive deeper into your experience.
  • Final match — We go through the employment terms together in clear, understandable language.
  • Signature — Once everything feels right for both sides, we move forward together.
Interested?

If you want to help organizations gain real control over risks, laws and regulations, and information security, and you enjoy working on challenging GRC projects, we would love to hear from you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC/IS Consultant
GRC/IS Consultant

FreshMinds • Leiden

On-site
EUR 89,280 - 111,600
70% van het bill rate
Trainingsbudget
Optioneel leaseauto, laptop en telefoon
+1
Information Security Consultant
Information Security Consultant

ITSync • Netherlands

On-site
EUR 73,000 - 92,000
Hybrid working
Home-office flexibility
Competitive salary
GRC Professional (Governance, Risk & Compliance)
GRC Professional (Governance, Risk & Compliance)

Securance • Utrecht

On-site
EUR 36,000 - 62,000
Hybrid working
Bonus scheme (13th month)
Laptop en telefoonvergoeding
+5
Senior GRC Specialist - NL
Senior GRC Specialist - NL

Capgemini • Utrecht

On-site
EUR 70,000 - 90,000
Vast contract
Goed salaris met groeimogelijkheden
Onbeperkt trainingen
+3
Security Consultant
Security Consultant

Software Search • Netherlands

Hybrid
EUR 102,000 - 122,000
Permanent contract
Project variety and autonomy
Competitive compensation
+4
GRC Professional (Governance, Risk & Compliance)
GRC Professional (Governance, Risk & Compliance)

Securance Advisory • Utrecht

On-site
Maandsalaris tussen €3.600 en €5.600
Aantrekkelijke bonusregeling
Flexibele werktijden
+2
GRC Professional (Governance, Risk & Compliance)
GRC Professional (Governance, Risk & Compliance)

Securance Into Control • Utrecht

On-site
Confidential
Competitief salaris
Bedrijfs-laptop en telefoonvergoeding
Mobiliteitsbudget
+4
Security Engineer
Security Engineer

Software Search • Netherlands

Hybrid
EUR 100,000 - 123,000
Permanent contract
Training budget and security community
Information Security Officer
Information Security Officer

MVProfessionals • Eindhoven

Hybrid
EUR 75,000 - 100,000
Strategische rol bij directie
Autonomie in security governance
Loopbaanpad richting CISO
+1
Senior Informatiebeveiliging Consultant – Strategisch & Hands-on
Senior Informatiebeveiliging Consultant – Strategisch & Hands-on

Dignitas Group • De Bilt

On-site