Information Security Officer (CGRC)

Heerema

Netherlands

On-site

EUR 70,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Strong compensation & benefits
Annual bonus tied to company performance
30 days off
Access to in-house gym
Modern office in Leiden

Job summary

Heerema is seeking an Information Security Officer (CGRC) to lead cybersecurity governance across IT and OT. This role involves defining policies, conducting risk assessments, and ensuring compliance with frameworks such as ISO and GDPR. The ideal candidate should have at least 5 years of experience in information security and relevant certifications. Heerema offers strong compensation, including bonuses and 30 days off, alongside a modern workplace in Leiden.

Qualifications

  • 5+ years of experience in information security with GRC leadership.
  • Hands-on experience with security frameworks and regulations.
  • Strong understanding of audit practices and evidence management.

Responsibilities

  • Lead cybersecurity governance across IT and OT.
  • Define policies, standards, and manage risk assessments.
  • Ensure compliance with regulations like ISO and GDPR.

Skills

Risk methodologies
Compliance
Information security
Strong communication skills

Education

HBO or WO degree
Relevant certifications (CISSP, CISM, ISO 27001)

Job description

Cybersecurity is essential to keeping our global offshore operations safe and reliable. As Information Security Officer (CGRC), you set the governance and risk foundation that protects our IT, OT, and information assets.

Your role in the story

As Information Security Officer (CGRC), you lead cybersecurity governance across IT and OT at Heerema. You define policies and standards, drive risk assessments, and ensure compliance with regulations such as ISO, NIS2, and GDPR, working closely with IT, OT, and the business to embed security controls into daily operations and projects.

What you will be working on
  • Defining and maintaining the cybersecurity governance framework, including top‑level security directives, policies, and supporting standards
  • Establishing clear CGRC roles and responsibilities (RACI) across IT, OT, and the business
  • Planning, executing and maintaining cybersecurity risk assessments, including project and third‑party risk
  • Mapping security requirements to external frameworks and regulations (e.g. ISO/IEC 27001/2, NIST CSF/800‑53, IEC 62443, GDPR, NIS2, IMO)
  • Coordinating internal and external audits and managing audit findings and remediation
  • Defining CGRC KPIs, maturity metrics, dashboards, and management reporting
  • Developing and delivering role‑based cybersecurity awareness and training
  • Maintaining cybersecurity incident response governance, post‑incident reviews, and regulatory reporting in collaboration with relevant teams
  • Building strong partnerships across IT, OT, Legal, Compliance, Quality, HR, and external stakeholders
Key ingredients for success
  • HBO or WO degree; relevant certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, or IEC 62443 are preferred
  • 5+ years of experience in information security, risk, or compliance roles with demonstrable GRC leadership across IT and/or OT
  • Hands‑on experience with security frameworks (ISO/IEC 27001/2, NIST CSF/800‑53), privacy (GDPR), EU directives (e.g. NIS2), and IMO cybersecurity requirements
  • Strong understanding of risk methodologies, control testing, audit practices, and evidence management
  • Ability to structure policies and standards and operate governance processes across complex organizations
  • Strong communication skills, able to translate between technical and non‑technical audiences in English and Dutch
  • Comfortable working across IT, OT, and operational environments, balancing regulatory obligations with business realities
Benefits
  • Strong compensation & benefits, including an annual bonus plan tied to company performance
  • Bonus basis = your annual gross salary + 13th month + 8% holiday allowance
  • Future‑proof pension: gross scheme covering base + 13th month + holiday allowance, with no mandatory contribution up to €72,488.52
  • 30 days off to recharge, with the option to buy 10 extra days
  • Free access to an in‑house gym, including fitness classes
  • Activities to connect with colleagues (e.g. Friday‑afternoon get‑together)
  • A modern and easily accessible office in Leiden
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Governance & Risk Lead (CGRC) for IT & OT
Cyber Governance & Risk Lead (CGRC) for IT & OT

Heerema • Netherlands

On-site
EUR 70,000 - 100,000
Strong compensation & benefits
Annual bonus tied to company performance
30 days off
+2
Corporate Information Security Officer (CISO) (Leiden, ZH, NL, 2332 AA)
Corporate Information Security Officer (CISO) (Leiden, ZH, NL, 2332 AA)

Qabird • Leiden

On-site
EUR 150,000 - 210,000
GRC Professional (Governance, Risk & Compliance)
GRC Professional (Governance, Risk & Compliance)

Securance Service Inc • Utrecht

Hybrid
Confidential
Bonus scheme
Company laptop and phone
Mobility budget
+7
Security Officer (Operational Technology) - m/f/x
Security Officer (Operational Technology) - m/f/x

RWE • Geertruidenberg

Hybrid
EUR 70,000 - 95,000
Flexible and hybrid working
Company pension scheme
Employee stock programme
+1
Cyber Risk Officer
Cyber Risk Officer

Vanderlande • Veghel

On-site
40 vacation days including flexible budget
Flexible working hours
Health & Wellbeing budget
+3
GRC/IS Consultant
GRC/IS Consultant

Software Search • Netherlands

Hybrid
EUR 9,000 - 11,000
Laptop and phone
Training budget
Events & meetups
+1
GRC Professional (Governance, Risk & Compliance)
GRC Professional (Governance, Risk & Compliance)

Securance • Utrecht

On-site
EUR 36,000 - 62,000
Hybrid working
Bonus scheme (13th month)
Laptop en telefoonvergoeding
+5
Senior IT Security Specialist (S) (Rotterdam Office, NL)
Senior IT Security Specialist (S) (Rotterdam Office, NL)

Qabird • Rotterdam

On-site
EUR 70,000 - 90,000
Senior/Principal OT Security Consultant
Senior/Principal OT Security Consultant

DNV • Amsterdam

On-site
EUR 70,000 - 110,000
Senior/Principal OT Security Consultant
Senior/Principal OT Security Consultant

DNV GL • Amsterdam

On-site
EUR 90,000 - 130,000
Profit Share
Insurance
Pension Schemes
+5