ISO 27001 Security Governance Lead - Assurance & Risk

DLA Piper

Amsterdam

On-site

EUR 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

DLA Piper is seeking an Information Security Governance Lead to drive assurance activities across the firm’s information security program. You will coordinate ISO 27001 certification activities, assess control effectiveness and support the risk management framework with enterprise risk teams.

You will collaborate with stakeholders to ensure controls protect the organization, meet client commitments, and comply with regulatory and contractual obligations within risk tolerance.

Qualifications

  • Experience operating or supporting an ISO 27001 Information Security Management System.
  • Knowledge of information security control frameworks and assurance methodologies.
  • Knowledge of Cyber Essentials Plus.
  • Ability to assess the effectiveness of security controls and identify improvement opportunities.

Responsibilities

  • Own and maintain the ISO 27001:2022 Information Security Management System.
  • Coordinate internal and external certification audits.
  • Manage the lifecycle of policies, standards and supporting documentation.
  • Facilitate management reviews and support continual improvement activities.
  • Ensure security governance processes remain aligned to business objectives and evolving risk.
  • Design and operate a programme of security control testing and assurance activities.
  • Assess the effectiveness of administrative, technical and operational controls.
  • Produce assurance reports and communicate outcomes to relevant stakeholders.
  • Monitor remediation activities and support closure of identified weaknesses.
  • Develop assurance dashboards, metrics and management reporting.
  • Support the ongoing maturity of the security governance framework.
  • Review the impact of regulatory, industry and client requirements on the control environment.
  • Contribute to internal security awareness and governance initiatives.
  • Support external client requests relating to security assurance and certification activities where required.
  • Facilitate identification, assessment and evaluation of security risks.
  • Provide analysis and recommendations to support risk-based decisions.
  • Monitor risk treatment activities and provide challenge where appropriate.
  • Support risk acceptance and exception management processes

Skills

ISO 27001 knowledge
Audit coordination
Risk management
Control effectiveness assessment
Security governance frameworks
Regulatory/commercial obligations
Security reporting to stakeholders
Risk-based decision support
Threats and vulnerability awareness

Education

ISO 27001 Lead Implementer/Auditor, CISSP/CISM/CRISC

Tools

ISO 27001 information security management system

Job description

DLA Piper is seeking an Information Security Governance Lead to drive assurance activities across the firm’s information security program. You will coordinate ISO 27001 certification activities, assess control effectiveness and support the risk management framework with enterprise risk teams.

You will collaborate with stakeholders to ensure controls protect the organization, meet client commitments, and comply with regulatory and contractual obligations within risk tolerance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Governance Lead
Information Security Governance Lead

DLA Piper • Amsterdam

On-site
EUR 90,000 - 130,000
Security Governance & Risk Lead - ISO 27001, AI
Security Governance & Risk Lead - ISO 27001, AI

PwC South Africa • Amsterdam

Hybrid
Confidential
Competitive salary
Annual bonus
Permanent contract
+6
ISO 27001 Security Officer & Risk Governance
ISO 27001 Security Officer & Risk Governance

SendCloud • Eindhoven

Hybrid
EUR 70,000 - 90,000
Flexible hybrid work model
€500 home office budget
28 holidays per year
+5
Security & Compliance Leader: ISO, GDPR, NIS2 & Risk
Security & Compliance Leader: ISO, GDPR, NIS2 & Risk

S[&]T • Delft

On-site
EUR 70,000 - 100,000
ISO & GDPR Security Lead: Policy, Risk & Compliance
ISO & GDPR Security Lead: Policy, Risk & Compliance

Robin Radar Systems • Delft

On-site
EUR 70,000 - 95,000
Great Place to Work
Pension plan
Commuting allowance
+4
Information Security Leader & Compliance Advocate
Information Security Leader & Compliance Advocate

Prime Vision • Delft

On-site
EUR 90,000 - 120,000
IT Security Specialist - Risk, IAM & ISO 27001 Architect
IT Security Specialist - Risk, IAM & ISO 27001 Architect

Levy Global • Utrecht

On-site
EUR 70,000 - 110,000
Security & Privacy Leader - Enterprise GRC & Resilience
Security & Privacy Leader - Enterprise GRC & Resilience

Just Brands - Fashion & Retail • Lijnden

On-site
EUR 90,000 - 130,000
End-of-year bonus
Lunch provided
Gym access
+2
GRC & IS Consultant — Shape Compliance & Security Strategy
GRC & IS Consultant — Shape Compliance & Security Strategy

Software Search • Netherlands

Hybrid
EUR 9,000 - 11,000
Laptop and phone
Training budget
Events & meetups
+1
Security & Compliance Lead: ISO 27001 & Risk
Security & Compliance Lead: ISO 27001 & Risk

Stcorp • Netherlands

Remote
EUR 70,000 - 90,000