Security Governance & Risk Lead - ISO 27001, AI

PwC South Africa

Amsterdam

Hybrid

Confidential

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Competitive salary
Annual bonus
Permanent contract
Training programs
Mobility benefits
32 vacation days
Well-being budget
OpenUp access
Hybrid work arrangement

Job summary

PwC Netherlands is seeking a proactive security governance leader to own the CISO office's internal control, audit readiness, and regulatory programs. You’ll implement frameworks like ISO 27001, SOC 2, NIS2, and DORA, shaping AI governance and leading annual security risk assessments across PwC NL.

You’ll work with auditors, business, and tech teams to embed security into day‑to‑day operations, report to senior stakeholders, and drive continuous control improvements in a hybrid work environment.

Qualifications

  • 5+ years of professional experience in information security, IT governance, compliance, risk management, and internal control.
  • Hands-on experience implementing and maintaining ISO 27001, SOC 2, and NIS2.
  • Solid understanding of internal audit processes, control testing, issue remediation, and how to build evidence that meets regulator and auditor standards.
  • Knowledge of AI governance, AI risk, and emerging technology controls, plus previous hands-on IT or cybersecurity experience as a strong advantage.
  • Fluent in Dutch at a professional level.

Responsibilities

  • Lead the CISO office's work on the internal PwC control framework and act as SME for internal audit, including preparation, evidence testing, remediation tracking, and control maturity improvement.
  • Drive the implementation, upkeep, and continuous improvement of ISO 27001, SOC 2, NIS2, and DORA, and manage the CISO office pillar of PwC NL's internal IT Unified Control Framework.
  • Lead the global and local annual security risk assessment and manage PwC NL's security awareness campaigns.
  • Implement and maintain the firm's approach to AI governance and risk management, including policy development, risk assessment, control definition, and oversight of responsible use.
  • Partner with internal committees and lines of service to ensure security, risk, and control requirements are understood, workable, and embedded across the business.

Skills

information security
IT governance
compliance
risk management
internal control
ISO 27001
SOC 2
NIS2
DORA
AI governance
audit readiness

Job description

PwC Netherlands is seeking a proactive security governance leader to own the CISO office's internal control, audit readiness, and regulatory programs. You’ll implement frameworks like ISO 27001, SOC 2, NIS2, and DORA, shaping AI governance and leading annual security risk assessments across PwC NL.

You’ll work with auditors, business, and tech teams to embed security into day‑to‑day operations, report to senior stakeholders, and drive continuous control improvements in a hybrid work environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance & Risk Leader (Hybrid)
Security Governance & Risk Leader (Hybrid)

PwC Nederland • Amsterdam

Hybrid
EUR 110,000 - 140,000
Competitive salary
Permanent contract
Training programs
+5
Business Information Security Officer (BISO)
Business Information Security Officer (BISO)

PwC Nederland • Amsterdam

Hybrid
EUR 110,000 - 140,000
Competitive salary
Permanent contract
Training programs
+5
Business Information Security Officer (BISO)
Business Information Security Officer (BISO)

PwC South Africa • Amsterdam

On-site
Confidential
Competitive salary
Annual bonus
Permanent contract
+6
IT Security Lead — Microsoft Stack & ISO 27001
IT Security Lead — Microsoft Stack & ISO 27001

NUNC Capital • Amsterdam

Hybrid
EUR 56,000 - 67,000
Gross monthly salary €5,000–€6,000
8% holiday allowance
25 vacation days
+5
CISO: Governance, Risk & Cyber Resilience Lead
CISO: Governance, Risk & Cyber Resilience Lead

IBgids • Eindhoven

Hybrid
Hybride werken
Vakantiedagen 28
Onkostenvergoeding €70/maand
+5
Senior ICT Risk & Compliance Lead (2LoD, ISO27001, PCI DSS)
Senior ICT Risk & Compliance Lead (2LoD, ISO27001, PCI DSS)

Care Professionals • Amsterdam, Utrecht

On-site
EUR 90,000 - 130,000
ISO 27001 Security Officer & Risk Governance
ISO 27001 Security Officer & Risk Governance

SendCloud • Eindhoven

Hybrid
EUR 70,000 - 90,000
Flexible hybrid work model
€500 home office budget
28 holidays per year
+5
Strategic InfoSec Officer - ISO 27001 & NIS2 (Hybrid)
Strategic InfoSec Officer - ISO 27001 & NIS2 (Hybrid)

IBgids • Eindhoven

Hybrid
EUR 75,000 - 100,000
Hybride werkmodel vanuit Eindhoven
Directe betrokkenheid bij directie
Professionele groei richting CISO
Senior GRC Advisor – ISO 27001, NIS2 & Privacy Compliance
Senior GRC Advisor – ISO 27001, NIS2 & Privacy Compliance

IBgids • Utrecht

On-site
Mobiliteitsvergoeding
Netto onkostenvergoeding
Pensioenregeling
+1
Global Information Security Leader
Global Information Security Leader

Stake Logic • Eindhoven

Hybrid
EUR 90,000 - 130,000