Security & Privacy Leader — Practical GRC for Retail

Just Brands - Fashion & Retail

Hoofddorp

On-site

EUR 90,000 - 120,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

End-of-year bonus
Lunch program
Gym access
Social events
Staff discount

Job summary

Just Brands - Fashion & Retail in the Amsterdam area seeks a Security & Privacy Officer (Information Security / GRC) to translate risk into clear business decisions and embed privacy by design across processes.

You will own governance aligned with ISO 27001 and NIST CSF, manage the cyber risk register, and lead BIA/BC-DR initiatives, partnering with Legal/DPO on GDPR/AVG compliance. Prior retail/e-commerce experience is a plus.

Qualifications

  • Bachelor's degree in Information Security, IT, Business Administration or similar (or equivalent experience).
  • 5+ years of experience in information security, IT governance, and/or privacy/compliance roles.
  • Experience implementing or governing ISO 27001 and/or NIST CSF, plus GDPR/AVG.
  • Experience with risk management, audit preparation and working with external parties (auditors, regulators, vendors).
  • Confidence driving governance in organizations with limited dedicated security resources.
  • Familiarity with modern identity and cloud environments (e.g., Microsoft 365, Okta/Identity & MFA, cloud SaaS and enterprise systems).
  • Certifications are a strong plus (CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CIPP/E or similar).
  • Experience in retail/e-commerce or distributed environments is a plus.

Responsibilities

  • Own and govern security governance, policies and standards aligned with ISO 27001 and NIST CSF.
  • Own the cyber risk register, risk scoring and MT-level risk reviews.
  • Lead Business Impact Analysis (BIA) and translate outcomes into BC/DR requirements.
  • Govern control effectiveness: access reviews, patch compliance, monitoring and endpoint protection.
  • Establish incident response, escalation paths and GDPR breach notification integration.
  • Drive privacy governance: data classification, DPIAs and records of processing.
  • Run third-party/vendor risk management and contract/SLAs governance.
  • Own audit readiness: evidence, documentation and regulatory interactions.
  • Build awareness with HR/Marketing: training completion and phishing metrics.
  • Report top risks and compliance status to MT; partner with Legal/DPO on regulatory changes.

Skills

Information security
IT governance
Privacy/compliance
Risk management
Audit readiness
Vendor risk management
ISO 27001
NIST CSF
GDPR/AVG
Cloud security
Security governance

Education

Bachelor's degree in Information Security / IT / Business Admin

Tools

Microsoft 365
Okta/Identity & MFA

Job description

Just Brands - Fashion & Retail in the Amsterdam area seeks a Security & Privacy Officer (Information Security / GRC) to translate risk into clear business decisions and embed privacy by design across processes.

You will own governance aligned with ISO 27001 and NIST CSF, manage the cyber risk register, and lead BIA/BC-DR initiatives, partnering with Legal/DPO on GDPR/AVG compliance. Prior retail/e-commerce experience is a plus.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Privacy Leader - Enterprise GRC & Resilience
Security & Privacy Leader - Enterprise GRC & Resilience

Just Brands - Fashion & Retail • Lijnden

On-site
EUR 90,000 - 130,000
End-of-year bonus
Lunch provided
Gym access
+2
SECURITY & PRIVACY OFFICER
SECURITY & PRIVACY OFFICER

Just Brands - Fashion & Retail • Lijnden

On-site
EUR 90,000 - 130,000
End-of-year bonus
Lunch provided
Gym access
+2
Security & Privacy Officer
Security & Privacy Officer

Just Brands - Fashion & Retail • Hoofddorp

On-site
EUR 90,000 - 120,000
End-of-year bonus
Lunch program
Gym access
+2
GRC & IS Consultant — Shape Compliance & Security Strategy
GRC & IS Consultant — Shape Compliance & Security Strategy

Software Search • Netherlands

Hybrid
EUR 9,000 - 11,000
Laptop and phone
Training budget
Events & meetups
+1
Regional Information Security Lead - GDPR/NIS2 & AI Act
Regional Information Security Lead - GDPR/NIS2 & AI Act

Doghouse Recruitment • Amsterdam

On-site
EUR 88,000 - 95,000
Up to 95000 EUR OTE per year
Non-contributory pension
Working from home allowance €2.40 per day
+2
Security Governance & Risk Lead - ISO 27001, AI
Security Governance & Risk Lead - ISO 27001, AI

PwC South Africa • Amsterdam

Hybrid
Confidential
Competitive salary
Annual bonus
Permanent contract
+6
Hybrid InfoSec & Privacy Specialist (GDPR, ISO27001, NIST)
Hybrid InfoSec & Privacy Specialist (GDPR, ISO27001, NIST)

Braskem • Rotterdam

Hybrid
EUR 70,000 - 90,000
Medior Privacy, Security & AI Compliance Counsel
Medior Privacy, Security & AI Compliance Counsel

GRCPerfect • Rotterdam

On-site
EUR 70,000 - 90,000
Fitness membership
Strategic Information Security Leader
Strategic Information Security Leader

Qabird • Delft

On-site
EUR 70,000 - 100,000
Profit sharing
Flexible hours
Vacation add-on
+2
Security Governance & Risk Leader (Hybrid)
Security Governance & Risk Leader (Hybrid)

PwC Nederland • Amsterdam

Hybrid
EUR 110,000 - 140,000
Competitive salary
Permanent contract
Training programs
+5