Information Security Officer

Startup Atlas

Amsterdam

Hybrid

EUR 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Bonus scheme
Shares incentive plan
Office in Amsterdam (cool office)

Job summary

Finst is seeking an Information Security Officer to own the second-line IT risk and information security function. You will report to the Chief Compliance Officer and collaborate with engineering, product and platform teams to enhance security and compliance in line with DORA, ISO 27001, GDPR and other regulations.

You will lead the ISMS, drive audits, review security practices, and act as an internal advisor on best practices.

Qualifications

  • 3–5 years in information security, IT risk or compliance.
  • Experience with ISMS implementation (ISO 27001).
  • Knowledge of DORA, GDPR.
  • Certification a plus (ISO 27001 LA/LI, CISA, CISSP).
  • Strong communication and audits coordination.

Responsibilities

  • Own and operate second-line information security risk and compliance.
  • Lead ISMS setup aligned with ISO 27001.
  • Drive compliance with DORA, GDPR, AI Act.
  • Review IT security practices in first line.
  • Maintain IT risk management framework.
  • Coordinate audits and due diligence.
  • Advise on security best practices.
  • Track incidents and remediation.

Skills

Information security
IT risk management
DORA & GDPR
ISMS management
Cloud infra & CI/CD
Audits & compliance
Communication skills
Ownership & proactive
ISO 27001 LA/LI
CISA
CISSP

Tools

ISO 27001 LA/LI

Job description

Finst is a regulated Dutch cryptocurrency exchange offering trading of over 340 cryptocurrencies with ultra-low fees of 0.15% per transaction, staking rewards, crypto bundles, and maximum security through Proof of Reserves.

Amsterdam, North Holland, Netherlands • Remote

Finst is hiring a hands‑on Information Security Officer to own the second-line IT risk and information security function, reporting to the Chief Compliance Officer and collaborating with engineering and product teams to enhance security and compliance in line with DORA, ISO 27001, GDPR, and other regulations.

Job Description
Information Security Officer
Finst is hiring!
About

Finst is one of the largest regulated cryptocurrency platforms in The Netherlands and offers a unique combination of transparency, maximum safety and ultra-low fees.

We are a mission‑driven start‑up led by the former core team of DEGIRO and backed by some of the most successful entrepreneurs and investors on the continent (DEGIRO co‑founders, Deribit, Endeit). We aim to become the largest and most‑trusted regulated crypto‑assets platform in Europe within 5 years.

Job Description
Your career and the team

We’re looking for a hands‑on Information Security Officer to join our team and take full ownership of our second‑line IT risk and information security function. You’ll be reporting directly to the Chief Compliance Officer and work closely with engineering, product, and platform teams to build, challenge, and improve our security and compliance posture in line with DORA, ISO 27001, GDPR, AI Act, EEA Act and other relevant regulations.

Your daily adventures will include
  • Own and operate our second-line information security risk and compliance program
  • Lead the setup and operation of our ISMS, aligned with ISO 27001 standards
  • Drive compliance efforts with DORA, GDPR, AI act, and other relevant regulations
  • Review and challenge first-line teams on IT security practices, policies, and controls to identify and mitigate risks early
  • Define and maintain the IT risk management framework using best practices (e.g., ISO 27005, NIST)
  • Maintain IT compliance documentation, policies, and processes across the organization
  • Schedule, manage, and support audits, both internal and external
  • Review new tools and vendors, assist in software approval and due diligence processes
  • Track incidents, non-conformities, and risks—and follow up with remediation plans
  • Act as an internal advisor on best practices in security and compliance.
Why you will love it here
  • Great skills come with great benefits – we offer competitive fixed remuneration (evolving with you) + bonus scheme
  • Our top employees get rewarded with shares incentive plan – we want you to own it
  • Work with a tightly-knit and multi‑cultural team of senior professionals – we strive to keep the talent density very high
  • Fast decision‑making and open environment, freedom, trust, and the opportunity to make a unique impact
  • Work from a very cool office in the heart of Amsterdam
  • 25 paid holidays per year to reload
  • Get the tech you need: MacBook, Windows, standing desks – you name it
  • Flexibility: although we like and encourage being together in the office, it ultimately doesn’t matter where and when you work, as long as you get it done
  • No office politics – we’re too busy changing the crypto industry
  • Monthly team drinks and yearly company off‑sites – work hard, play harder
What you’ll need to be successful
  • At least 3–5 years of experience in information security, IT risk, or compliance
  • Solid knowledge of DORA, GDPR, and general information security principles
  • Hands‑on experience with setting up or managing an ISMS (ISO 27001)
  • Technical background or experience working closely with cloud infrastructure, CI/CD, SDLC, IAM, or microservices
  • Strong understanding of risk management frameworks, controls, and compliance processes
  • A relevant certification (e.g., ISO 27001 LA/LI, CISA, CISSP, or similar) is a plus
  • Comfortable coordinating audits and managing compliance documentation
  • Excellent communication skills and a proactive, independent approach
  • Proactive, pragmatic, and able to work independently - you seek ownership, impact, and room to build

Finst welcomes everyone and is an Equal Opportunity Employer. We embrace diversity and are committed to creating an inclusive environment for employees of all backgrounds and cultures.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Risk Officer
IT Risk Officer

Coinmerce • Schiphol-Rijk

On-site
EUR 65,000 - 85,000
Free lunch
25 vacation days
Monthly chair massages
+2
Compliance Program Manager - Dora
Compliance Program Manager - Dora

Castle Island • Amsterdam

Hybrid
EUR 110,000 - 150,000
Competitive salary
Equity
Startup atmosphere
+2
Senior Security Officer
Senior Security Officer

FRISS • Utrecht

On-site
EUR 60,000 - 100,000
Flexible working hours
Health insurance
Professional development opportunities
+2
Information Security Officer
Information Security Officer

Prime Vision • Delft

On-site
EUR 90,000 - 120,000
Technical Information Security Officer (ISO)
Technical Information Security Officer (ISO)

Eye Security • Den Haag

Hybrid
EUR 90,000 - 130,000
Remote-friendly culture
Quarterly meetups
Annual company retreats
+2
Security Administrator
Security Administrator

Lynx Beleggen • Amsterdam

Hybrid
EUR 70,000 - 110,000
Training budget €2,000 per year
Hybrid work policy (Amsterdam/Berlin/G
German and English courses
+3
Junior Information Security Officer (CISO track)
Junior Information Security Officer (CISO track)

Fiducial • Delft

On-site
EUR 42,000 - 54,000
Vacation days 25 per year
Company laptop
Travel reimbursement
+2
Remote ISMS Lead — Security & Compliance (Equity)
Remote ISMS Lead — Security & Compliance (Equity)

Startup Atlas • Amsterdam

Hybrid
EUR 90,000 - 130,000
Bonus scheme
Shares incentive plan
Office in Amsterdam (cool office)
Technical Information Security Officer
Technical Information Security Officer

Qabird • Delft

On-site
EUR 70,000 - 100,000
Profit sharing
Flexible hours
Vacation add-on
+2
Senior IT Risk Officer - Amsterdam Region
Senior IT Risk Officer - Amsterdam Region

Improven • Amsterdam

On-site
EUR 70,000 - 90,000
16.33% individual choice budget
Over 5 weeks of holidays
€3,000 personal development budget per 3 years