Security & Privacy Officer

Just Brands - Fashion & Retail

Hoofddorp

On-site

EUR 90,000 - 120,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

End-of-year bonus
Lunch program
Gym access
Social events
Staff discount

Job summary

Just Brands - Fashion & Retail in the Amsterdam area seeks a Security & Privacy Officer (Information Security / GRC) to translate risk into clear business decisions and embed privacy by design across processes.

You will own governance aligned with ISO 27001 and NIST CSF, manage the cyber risk register, and lead BIA/BC-DR initiatives, partnering with Legal/DPO on GDPR/AVG compliance. Prior retail/e-commerce experience is a plus.

Qualifications

  • Bachelor's degree in Information Security, IT, Business Administration or similar (or equivalent experience).
  • 5+ years of experience in information security, IT governance, and/or privacy/compliance roles.
  • Experience implementing or governing ISO 27001 and/or NIST CSF, plus GDPR/AVG.
  • Experience with risk management, audit preparation and working with external parties (auditors, regulators, vendors).
  • Confidence driving governance in organizations with limited dedicated security resources.
  • Familiarity with modern identity and cloud environments (e.g., Microsoft 365, Okta/Identity & MFA, cloud SaaS and enterprise systems).
  • Certifications are a strong plus (CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CIPP/E or similar).
  • Experience in retail/e-commerce or distributed environments is a plus.

Responsibilities

  • Own and govern security governance, policies and standards aligned with ISO 27001 and NIST CSF.
  • Own the cyber risk register, risk scoring and MT-level risk reviews.
  • Lead Business Impact Analysis (BIA) and translate outcomes into BC/DR requirements.
  • Govern control effectiveness: access reviews, patch compliance, monitoring and endpoint protection.
  • Establish incident response, escalation paths and GDPR breach notification integration.
  • Drive privacy governance: data classification, DPIAs and records of processing.
  • Run third-party/vendor risk management and contract/SLAs governance.
  • Own audit readiness: evidence, documentation and regulatory interactions.
  • Build awareness with HR/Marketing: training completion and phishing metrics.
  • Report top risks and compliance status to MT; partner with Legal/DPO on regulatory changes.

Skills

Information security
IT governance
Privacy/compliance
Risk management
Audit readiness
Vendor risk management
ISO 27001
NIST CSF
GDPR/AVG
Cloud security
Security governance

Education

Bachelor's degree in Information Security / IT / Business Admin

Tools

Microsoft 365
Okta/Identity & MFA

Job description

Make security and privacy real, practical, and business-ready.
Lijnden (Amsterdam Area) | Operations / IT (Information Security / GRC) | 40 hours | Full-time

At Just Brands, we build menswear brands with character. PME Legend, Cast Iron and Vanguard each have their own voice, their own audience and their own place in the market. As we operate across retail and e-commerce, the stakes around information security and data privacy keep rising. Threats move fast, regulations are complex, and the impact of getting it wrong is real: disruption, reputational damage, and GDPR/AVG exposure.

But what really sets us apart is how we work together.

We’re team first. No ego, no unnecessary layers, no endless talking, no corporate theatre. We back each other, speak up, take ownership and keep pushing for better. We work hard, stay sharp and make sure there’s room to enjoy the ride too.

That’s where you come in.

Why this role matters

This is where GRC (Governance, Risk & Compliance) becomes resilience. As our Security & Privacy Officer (Information Security / GRC), you set the governance standards that keep our business safe and compliant without slowing it down. You translate security and privacy risks into clear, business-relevant decisions, drive the right priorities at MT level, and embed security and privacy into daily operations and projects. You are not here to write policies that no one follows.

You are here to make sure risk is understood, controls work, and the organization stays compliant and prepared.
What you’ll do
  • Own and maintain security and privacy governance (policies, standards, lifecycle) aligned with ISO 27001 and NIST CSF;
  • Own the cyber risk register, risk scoring and treatment plans, and run MT-level risk review rhythms;
  • Lead the Business Impact Analysis (BIA) and translate outcomes into business continuity and disaster recovery (BC/DR) requirements;
  • Govern control effectiveness: access reviews, patch compliance, monitoring/logging and endpoint protection, and drive corrective actions when controls deviate;
  • Establish and govern incident response, escalation paths and communications, including GDPR breach notification integration;
  • Drive privacy governance: data classification, handling standards, DPIAs, records of processing and privacy-by-design;
  • Run third-party / vendor risk management, embedding security and privacy requirements into contracts and SLAs;
  • Own audit readiness: evidence, documentation and representation in audits and regulatory interactions;
  • Build awareness with HR/Marketing: training completion, phishing simulation metrics and behavioral improvement;
  • Report to MT on top risks, incidents, control effectiveness, awareness metrics and compliance status;
  • Partner with privacy stakeholders (Legal/DPO) and translate regulatory change (e.g., EU security developments like NIS2 where applicable) into practical actions.
What makes this role exciting
  • You have enterprise-wide impact without needing a big team to get things done;
  • You sit at the intersection of IT, business leadership and regulation, where decisions actually matter;
  • You build governance that fits a lean, pragmatic organization (no over-engineering);
  • You lead a high-visibility deliverable (BIA) that influences continuity priorities across the business;
  • You shape how security and privacy show up in projects, systems and vendor relationships.
You’ll probably love this role if you…
  • like turning complex risk into clear actions people can execute;
  • prefer pragmatic governance over theoretical perfection;
  • can influence without hierarchy and don’t wait for permission to improve things;
  • stay calm when the pressure is on (incidents, audits, escalations);
  • enjoy balancing trade-offs: security vs usability, speed vs control, cost vs risk;
What you bring
  • Bachelor’s degree in Information Security, IT, Business Administration or similar (or equivalent experience);
  • 5+ years of experience in information security, IT governance, and/or privacy/compliance roles;
  • Hands‑on experience implementing or governing ISO 27001 and/or NIST CSF, plus GDPR/AVG;
  • Experience with risk management, audit preparation and working with external parties (auditors, regulators, vendors);
  • Confidence driving governance in organizations with limited dedicated security resources;
  • Familiarity with modern identity and cloud environments (e.g., Microsoft 365, Okta/Identity & MFA, cloud SaaS and enterprise systems);
  • Certifications are a strong plus (CISSP, CISM, ISO 27001 Lead Implementer/Auditor, CIPP/E or similar);
  • Experience in retail/e-commerce or distributed environments is a plus.
What Just Brands is really like

We’re team first. We keep it direct, make clear decisions and take ownership. No ego. Just practical collaboration, honest conversations and a team that likes improving what matters.

You’ll join a company where:

  • People help each other out;
  • Ideas and people matter more than job titles;
  • Hard work matters, and so does enjoying the ride;
  • If something can be better, we improve it.
What you get

You step into a high-impact governance role with real visibility and influence. You’ll help protect the business, strengthen resilience, and build a security and privacy baseline that scales as we grow.

Pay transparency

For this P3 role, we work with a salary range that reflects the level, scope and responsibility of the position. Based on a full-time 40-hour week, the salary range is based on the annual P3 salary band.

Your final salary depends on your experience, background, ecommerce expertise, platform knowledge, product data experience, project management skills and the level of ownership you bring to the role.

On top of that, you get:

  • End-of-year bonus equal to one gross monthly salary;
  • Healthy and varied lunch every day;
  • Exclusive access to our own Gym, including classes such as boxing, yoga and padel;
  • Parties and drinks that will be talked about for years to come;
  • Staff discount on our clothing.
Ready to raise the bar on security and privacy?

If you want a role where your judgment, structure and influence directly reduce risk and improve resilience across the business, this could be your next step.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SECURITY & PRIVACY OFFICER
SECURITY & PRIVACY OFFICER

Just Brands - Fashion & Retail • Lijnden

On-site
EUR 90,000 - 130,000
End-of-year bonus
Lunch provided
Gym access
+2
Security & Privacy Leader - Enterprise GRC & Resilience
Security & Privacy Leader - Enterprise GRC & Resilience

Just Brands - Fashion & Retail • Lijnden

On-site
EUR 90,000 - 130,000
End-of-year bonus
Lunch provided
Gym access
+2
Information Security Officer
Information Security Officer

Doghouse Recruitment • Amsterdam

On-site
EUR 88,000 - 95,000
Up to 95000 EUR OTE per year
Non-contributory pension
Working from home allowance €2.40 per day
+2
Security & Privacy Leader — Practical GRC for Retail
Security & Privacy Leader — Practical GRC for Retail

Just Brands - Fashion & Retail • Hoofddorp

On-site
EUR 90,000 - 120,000
End-of-year bonus
Lunch program
Gym access
+2
Medior Legal Counsel (Privacy, Security & AI Compliance).
Medior Legal Counsel (Privacy, Security & AI Compliance).

GRCPerfect • Rotterdam

On-site
EUR 70,000 - 90,000
Fitness membership
GRC/IS Consultant
GRC/IS Consultant

Software Search • Netherlands

Hybrid
EUR 9,000 - 11,000
Laptop and phone
Training budget
Events & meetups
+1
Information Security Officer (ISO)
Information Security Officer (ISO)

SendCloud • Eindhoven

Hybrid
EUR 70,000 - 90,000
Flexible hybrid work model
€500 home office budget
28 holidays per year
+5
Technical Information Security Officer
Technical Information Security Officer

Prime Vision • Netherlands

Hybrid
EUR 104,000 - 130,000
Profit-sharing scheme
Additional vacation days
Snacks & coffee in Grand Café
+2
Manager, Firm Security Insights Capability
Manager, Firm Security Insights Capability

McKinsey & Company • Amsterdam

On-site
EUR 120,000 - 180,000
Exceptional benefits
Enterprise Security Officer
Enterprise Security Officer

Prodrive Technologies • Eindhoven

On-site
EUR 85,000 - 120,000
Performance-based salary
33 days of leave per year
Pension plan and travel allowance
+3