Information Security Engineer

Ardena

Netherlands

On-site

EUR 55,000 - 75,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Attractive employment conditions
Flexible working hours
Opportunities for professional growth

Job summary

Ardena in the Netherlands is looking for an experienced Information Security Engineer. This role involves owning the information security programme, managing audits, and ensuring compliance with ISO 27001 standards.

The ideal candidate will have 3 to 5 years of experience in IT security, demonstrate strong leadership skills, and possess a Bachelor's degree in IT security or a related field. This position offers a collaborative work environment with flexible hours.

Qualifications

  • 3 to 5 years of hands-on experience in an information security or IT security role.
  • Demonstrated experience with ISO 27001 programmes and audits.
  • Fluent in English; Dutch is an advantage.

Responsibilities

  • Own and maintain the Information Security Management System (ISMS).
  • Prepare for and manage external audits.
  • Conduct internal audits and track corrective actions.

Skills

ISO 27001 implementation
Risk management
Cybersecurity awareness
Vulnerability management
IT systems understanding

Education

Bachelor's degree in IT security or related field

Tools

SIEM tools
Vulnerability management tooling

Job description

About Ardena
Ardena is a global Contract Development and Manufacturing Organisation (CDMO) and Contract Research Organisation (CRO) specialising in precision medicine development. Ardena supports pharmaceutical and biotechnology companies in bringing innovative, complex molecules from discovery to market. The Ardena Group operates from five sites across Europe and the United States, employing more than 750 professionals. Ardena European sites are located in Oss and Assen (the Netherlands), Ghent (Belgium), and Pamplona (Spain). Ardena US facility is based in Somerset, New Jersey. Ardena provides integrated services spanning drug substance development, drug product formulation, GMP manufacturing, bioanalytical services, clinical logistics, fill and finish, and CMC regulatory support.

For the Ardena site based in Oss, we are looking for an Information Security Engineer. Information security has been part of the IT organisation and is being handled alongside everything else that keeps our infrastructure and systems running. As our organisation grows and the regulatory and cyber landscape becomes more demanding, it is time for IT security to have its own dedicated focus. This role is not a junior position. We are looking for someone who can own our information security programme, run it independently, and develop it further. You will work closely with the IT Operations Director and have direct visibility across the organisation, but we expect you to drive the agenda, not wait for it.

What you will do
  • Own and maintain the Information Security Management System (ISMS) in line with ISO 27001 and other ISO standards.
  • Drive the implementation roadmap, perform gap analyses, create risk treatment plans, policy framework, and controls.
  • Prepare for and manage external certification and surveillance audits.
  • Conduct internal audits and track corrective actions to closure.
  • Identify process improvements and increase cybersecurity awareness.
  • Maintain the information security risk register and ensure risks are assessed, accepted, or treated.
  • Monitor compliance with internal policies and applicable regulations (NIS2, GDPR from an IT security angle).
  • Provide security input to new IT projects, system implementations, and vendor assessments.
  • Manage vulnerability assessments, patch compliance tracking, and penetration testing cycles.
  • Own the incident response process for security events – detection, containment, reporting, post-incident review.
  • Oversee access management principles and periodically review user rights.
  • Coordinate security awareness training and phishing exercises across the organisation.
  • Report on security posture and KPIs to IT management and, where relevant, to senior leadership.
  • Act as the point of contact for information security questions from internal stakeholders, clients, and auditors.
What we are looking for
Background & education
  • Bachelor's degree in IT security, cybersecurity, computer science, or a related field from a university of applied sciences (HBO).
  • ISO 27001 Lead Implementer or Lead Auditor certification is a strong plus; solid working knowledge of the standard is a must.
Experience
  • 3 to 5 years of hands‑on experience in an information security or IT security role; this means not just advisory work, but actual implementation and operations.
  • Demonstrated experience running or contributing to an ISO 27001 programme (gap analysis, audits, controls, risk assessments).
  • Comfortable working in complex, multi‑site IT environments with a mix of on‑premise and cloud infrastructure.
Technical understanding
  • Solid understanding of IT systems—networks, servers, endpoints, Active Directory, cloud services—at a level that lets you have a credible technical conversation.
  • Familiarity with vulnerability management tooling, SIEM concepts, and endpoint security.
  • Able to read and interpret security logs, understand firewall rules, and assess access configurations.
How you work
  • You take ownership. You see what needs to be done and you do it—without needing someone to walk alongside you every step of the way.
  • You can translate technical risk into plain language for management and non‑technical stakeholders.
  • You are structured, thorough, and comfortable in a regulated environment where documentation and auditability matter.
  • Fluent in English; Dutch is an advantage for day‑to‑day interaction with colleagues.
  • You are prepared to travel to Ardena sites on an occasional basis (approximately 5% of your time).
Nice to have
  • Additional certifications such as CISSP, CISM, CEH, or CompTIA Security+.
  • Experience in a GxP‑regulated environment (pharmaceutical, medical device, food) – you do not need to know GxP, but if you do, great.
  • Familiarity with the NIS2 Directive and its implications for critical infrastructure operators.
  • Experience with cloud security (Microsoft Azure / M365 security stack).
What we offer
  • A challenging and impactful leadership role in a learning organisation that supports professional growth.
  • A collaborative, international working environment with engaged and knowledgeable colleagues.
  • An open corporate culture with short communication lines.
  • Attractive employment conditions.
  • Flexible working hours to support work‑life balance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Applications Director
IT Applications Director

Ardena • Oss

Hybrid
EUR 120,000 - 170,000
Flexible working hours
International environment
Learning organisation
IT Applications Director
IT Applications Director

Ardena Careers • Oss

On-site
EUR 120,000 - 170,000
Leadership role
Collaborative environment
Open culture
+2
Lead Information Security Engineer – ISO 27001, Multi-Site
Lead Information Security Engineer – ISO 27001, Multi-Site

Ardena • Netherlands

On-site
EUR 55,000 - 75,000
Attractive employment conditions
Flexible working hours
Opportunities for professional growth
Associate Scientist Immunochemistry
Associate Scientist Immunochemistry

Ardena • Geffen

On-site
EUR 42,000 - 56,000
Salary range €3,800–€5,000 gross per月
Learning environment
Flexible working hours
+1
Security Risk Manager @ ASML
Security Risk Manager @ ASML

Sterksen • Veldhoven

On-site
EUR 95,000 - 135,000
Senior Information Security Engineer
Senior Information Security Engineer

Cyber Security District • Amsterdam

Hybrid
EUR 79,000 - 94,000
Competitive salary
Hybrid work model
Employer-paid pension
+4
Information Security Engineer
Information Security Engineer

Doghouse Recruitment • Amsterdam

On-site
EUR 84,000 - 90,000
Pension without contributions
Travel allowance
Internet allowance
+3
Information Security Governance & Compliance Officer
Information Security Governance & Compliance Officer

Vanderlande • Veghel

Hybrid
EUR 60,000 - 80,000
40 vacation days
Flexible working hours
Hybrid workplace
+4
Senior Network Security Engineer
Senior Network Security Engineer

ABN AMRO • Netherlands

On-site
EUR 90,000 - 120,000
Competitive salary
Pension scheme
WFH flexibility
+3
Information Security Engineer
Information Security Engineer

Haskoning • Amersfoort

Hybrid
EUR 47,000 - 87,000
Competitive base salary
Pension with 18.3% employer contrib.
Profit sharing
+5