Cybersecurity is essential to keeping our global offshore operations safe and reliable. As Information Security Officer (CGRC), you set the governance and risk foundation that protects our IT, OT, and information assets.
Your role in the story
As Information Security Officer (CGRC), you lead cybersecurity governance across IT and OT at Heerema. You define policies and standards, drive risk assessments, and ensure compliance with regulations such as ISO, NIS2, and GDPR, working closely with IT, OT, and the business to embed security controls into daily operations and projects.
What you will be working on
- Defining and maintaining the cybersecurity governance framework, including top‑level security directives, policies, and supporting standards
- Establishing clear CGRC roles and responsibilities (RACI) across IT, OT, and the business
- Planning, executing and maintaining cybersecurity risk assessments, including project and third‑party risk
- Mapping security requirements to external frameworks and regulations (e.g. ISO/IEC 27001/2, NIST CSF/800‑53, IEC 62443, GDPR, NIS2, IMO)
- Coordinating internal and external audits and managing audit findings and remediation
- Defining CGRC KPIs, maturity metrics, dashboards, and management reporting
- Developing and delivering role‑based cybersecurity awareness and training
- Maintaining cybersecurity incident response governance, post‑incident reviews, and regulatory reporting in collaboration with relevant teams
- Building strong partnerships across IT, OT, Legal, Compliance, Quality, HR, and external stakeholders
Key ingredients for success
- HBO or WO degree; relevant certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, or IEC 62443 are preferred
- 5+ years of experience in information security, risk, or compliance roles with demonstrable GRC leadership across IT and/or OT
- Hands‑on experience with security frameworks (ISO/IEC 27001/2, NIST CSF/800‑53), privacy (GDPR), EU directives (e.g. NIS2), and IMO cybersecurity requirements
- Strong understanding of risk methodologies, control testing, audit practices, and evidence management
- Ability to structure policies and standards and operate governance processes across complex organizations
- Strong communication skills, able to translate between technical and non‑technical audiences in English and Dutch
- Comfortable working across IT, OT, and operational environments, balancing regulatory obligations with business realities
Benefits
- Strong compensation & benefits, including an annual bonus plan tied to company performance
- Bonus basis = your annual gross salary + 13th month + 8% holiday allowance
- Future‑proof pension: gross scheme covering base + 13th month + holiday allowance, with no mandatory contribution up to €72,488.52
- 30 days off to recharge, with the option to buy 10 extra days
- Free access to an in‑house gym, including fitness classes
- Activities to connect with colleagues (e.g. Friday‑afternoon get‑together)
- A modern and easily accessible office in Leiden