Senior GRC Consultant

mnemonic

Utrecht

Hybrid

EUR 85,000 - 110,000

Full time

5 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive salary
Bonus scheme
Share scheme
Pension
Insurance cover
Training opportunities
Flexible working model
Central Utrecht office
Work-life balance
Social activities

Job summary

mnemonic, a leading European cybersecurity firm, seeks a Senior GRC Consultant for the Netherlands. You will work with clients across Benelux and Nordics to design, implement and manage governance, risk and compliance programs.

You will collaborate with executive teams, translate regulatory requirements into concrete improvements, and drive ISMS initiatives. A hybrid Utrecht-based role with occasional travel to Oslo is expected.

Qualifications

  • At least 5 years of information security and GRC experience, preferably in a consultancy environment.
  • Experience translating governance, risk and compliance frameworks into concrete organisational solutions.
  • Strong analytical, organisational and communication skills; fluent in Dutch and English.

Responsibilities

  • Independently lead consultancy projects in information security and GRC from analysis to implementation.
  • Act as security manager or CISO-for-hire for clients and embed security programmes.
  • Translate regulatory requirements into governance structures and operating models (e.g., NIS2, GDPR, DORA, EU AI Act).
  • Advise boards and management on governance, risk and maturity development.
  • Present technical findings to management in business terms and align with strategic priorities.
  • Plan and perform risk analyses, security assessments and resilience exercises.
  • Establish and grow ISMS and support compliance initiatives.
  • Collaborate with business and technical teams across projects.
  • Manage multiple parallel projects from planning to delivery.
  • Contribute to strengthening mnemonic’s GRC offering and participate in pre-sales.

Skills

GRC experience
Governance
Risk management
Compliance
ISMS knowledge
ISO 27001

Education

HBO/WO degree in IT or security

Job description

Do you want to provide strategic advice and actually see your recommendations put into practice? At mnemonic, you’ll help some of Europe’s most business-critical organisations, across the Benelux, the Nordics and the UK, to strengthen their resilience against threats and manage their risks. We translate governance, risk and security into choices that really matter for our clients. You’ll rarely spend two weeks doing the same thing: one day you might be advising a client’s C-suite on where to focus their cybersecurity efforts. The next, you could be leading a strategic security project or stepping in as CISO-for-hire.


mnemonic’s success and growth has created the need for us to strengthen our GRC team in the Netherlands and we are looking for a Senior GRC Consultant who will work closely with clients and wants to contribute to the further development of our services.


If you ask one of our GRC colleagues why they work for mnemonic, you’ll often hear the same answers: the unique in-house expertise, a flat organisational structure and a close-knit atmosphere with scope for social activities. You can see from the figures that this approach works well: our staff turnover is below 5 per cent, exceptionally low for our industry, and our client retention rate is around 95 per cent.


About the role

mnemonic was founded in 2000 and, with 450 employees, has become one of Europe’s largest independent pure-play cybersecurity firms. You’ll be working alongside an international team of security specialists on complex and meaningful challenges. We work for some of the most critical organisations and infrastructures and are best known for our Security Operations Centers (SOC) and Managed Detection and Response (MDR) services, through which we protect clients on a daily basis against today’s most advanced cyber threats.


As a Senior GRC Consultant, you’ll play a key role in our advisory services in the field of Governance, Risk & Compliance. You’ll work closely with clients and support organisations in setting up, developing and managing their information security programmes within complex and business-critical environments.


You will work on highly complex projects, often in direct collaboration with executive boards and management teams. In doing so, you will translate risks, regulations and strategic objectives into structures, processes and concrete improvements. You will collaborate with both business and technical teams, often in environments where security is essential to the organisation’s continuity.


The role is based at our office in Utrecht, with the option to work flexibly from the office and from home. As our head office is in Oslo, you may occasionally be required to travel there.


Your responsibilities


  • Independently leading and carrying out consultancy projects in the field of information security and GRC, from analysis through to implementation.

  • Acting as a security manager or CISO-for-hire for clients, steering their security programme and embedding it within the organisation.

  • Translating legal and regulatory requirements and risks into governance structures, operating models and practical working methods. Examples include NIS2, CbW, BIO, DORA, the GDPR, the EU AI Act and the CRA.

  • Advising boards and management teams on governance, risks and maturity development.

  • Communicating / presenting technical findings to a management audience that want to relate the findings to their strategic and financial priorities.

  • Planning and carrying out risk analyses, security assessments and crisis and resilience exercises.

  • Establishing and further developing Information Security Management Systems (ISMS) and supporting compliance initiatives.

  • Collaborating with both business stakeholders and technical teams.

  • Managing multiple parallel projects, from planning and scope definition through to stakeholder engagement and delivery.

  • Contributing to the further development of mnemonic’s GRC offering.

  • Participating in client meetings and supporting pre‑sales activities.


Is this you?

You have a completed higher professional education (HBO) or university (WO) degree, for example in IT, information security or a similar field. In addition, you have at least 5 years’ experience in information security and GRC, preferably in a consultancy environment.


You have practical experience with governance, risk management and compliance, and know how to translate frameworks into concrete solutions within organisations. For example, you have worked on risk analyses, policy development or the implementation of management systems (ISMS). You also have a good knowledge of frameworks such as ISO 27001, NIST or similar standards.


You are analytical, organised and a strong communicator. You take ownership of your assignments and are able to explain complex topics in a way that is understandable to both technical and non-technical audiences. You have a good command of Dutch and English, both spoken and written.


You follow the current trends in IT and are passionate about staying on top of what the industry is talking about. New and “first time” assignments are an opportunity for learning and you lean in to learning while doing.


Certifications

The certifications listed below help us identify suitable candidates and give you an idea of what might be valuable to obtain for this role. They are an advantage, not a requirement:



  • CISSP, CISM or CISA

  • CIPP/E or CIPM (privacy)

  • CCSP or CCSK (cloud security)

  • PRINCE2 or a comparable project management certification


What we can offer

The role offers a great deal of responsibility and excellent opportunities for professional development. In addition, mnemonic offers you:



  • A competitive salary, a bonus scheme and a share scheme designed to encourage long-term collaboration.

  • A good pension scheme and insurance cover.

  • Ample opportunities for training, courses and attending professional conferences.

  • A flexible working model and a centrally located office in Utrecht.

  • An informal, pleasant working environment that prioritises work-life balance for everyone, including colleagues with families.

  • A close-knit team atmosphere with social activities, events and outings with colleagues.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC/IS Consultant
GRC/IS Consultant

Software Search • Netherlands

Hybrid
EUR 9,000 - 11,000
Laptop and phone
Training budget
Events & meetups
+1
Senior GRC Advisor & CISO-for-Hire Lead
Senior GRC Advisor & CISO-for-Hire Lead

mnemonic • Utrecht

Hybrid
EUR 85,000 - 110,000
Competitive salary
Bonus scheme
Share scheme
+7
Information Security Officer
Information Security Officer

Nmbrs • Amsterdam

Hybrid
EUR 64,000 - 78,000
4-day workweek
Pension plan with 15% contribution
Personal coach
+4
GRC Professional (Governance, Risk & Compliance)
GRC Professional (Governance, Risk & Compliance)

Securance Advisory • Utrecht

On-site
Maandsalaris tussen €3.600 en €5.600
Aantrekkelijke bonusregeling
Flexibele werktijden
+2
GRC Professional (Governance, Risk & Compliance)
GRC Professional (Governance, Risk & Compliance)

Securance • Utrecht

On-site
EUR 36,000 - 62,000
Hybrid working
Bonus scheme (13th month)
Laptop en telefoonvergoeding
+5
Governance, Risk and Compliance Lead - NL
Governance, Risk and Compliance Lead - NL

Capgemini • Utrecht

On-site
EUR 85,000 - 115,000
Hybride werken
Opleidingsmogelijkheden
Marktconform salaris
+2
Information Security Officer
Information Security Officer

Nmbrs BV • Amsterdam

Hybrid
EUR 64,000 - 78,000
Pension plan 15%
Personal coach
Training budget and development
+3
Information Security Officer
Information Security Officer

MVProfessionals • Eindhoven

Hybrid
EUR 75,000 - 100,000
Strategische rol bij directie
Autonomie in security governance
Loopbaanpad richting CISO
+1
Senior GRC Specialist - NL
Senior GRC Specialist - NL

Capgemini • Utrecht

On-site
EUR 70,000 - 90,000
Vast contract
Goed salaris met groeimogelijkheden
Onbeperkt trainingen
+3
Senior Cybersecurity Solutions Consultant
Senior Cybersecurity Solutions Consultant

EPAM Systems • Amsterdam

Hybrid
EUR 110,000 - 150,000
26 paid holiday days
Pension plan scheme
Disability insurance (WGA Shortfall)
+8