(Senior) Manager IT Audit

Brightlyn

Den Haag

On-site

EUR 70,000 - 95,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Coaching and mentoring
Modern office facilities
Access to gym and food services

Job summary

A cutting-edge consulting firm in The Hague is looking for a Senior Manager in IT Audit & Security Risk. The role focuses on leading cyber risk assessments, improving security governance, and translating audit findings into actionable plans. Ideal candidates have 6-9 years of relevant experience, a Master's degree, and certifications like CISSP or CISM. Fluency in Dutch and English is required. Join a company that values advisory depth and client impact while working closely with executive leadership.

Qualifications

  • 6-9 years in IT Audit, Technology Risk, or IT Assurance.
  • Experience in advisory roles with senior management.
  • Fluency in Dutch and English.

Responsibilities

  • Lead IT, security, and cyber risk assessments.
  • Translate findings into prioritized improvement plans.
  • Advise on compliance with NIS2 and DORA.

Skills

IT Audit
Technology Risk
Cybersecurity
Stakeholder management
Governance

Education

Master’s degree from a research university
Relevant certifications (CISSP, CISM, CISA)

Tools

ISO 27001
NIST CSF
COBIT

Job description

Brightlyn – The Hague, South Holland, Netherlands

Overview

A role for experienced IT Audit professionals seeking deeper advisory impact.

Have you built a strong career in IT Audit or Technology Risk as a (Senior) Manager IT‑Audit at a Big‑4 and are you ready to take the next step? A step where you go beyond reporting findings and start helping organizations truly get in control of information security and cyber risk?

At Brightlyn, we work with society‑critical organizations to strengthen security governance, manage cyber risk, and meet regulatory requirements in a pragmatic, effective, and defensible way. This role is designed for IT Audit professionals who want to apply their audit expertise in a broader, more impactful advisory context.

Extending IT Audit Experience into Security and Cyber‑Risk

You already know how to:

  • assess IT governance, risk, and controls;
  • work with frameworks like ISO 27001, COBIT, and NIST;
  • challenge management constructively;
  • communicate complex risk topics to boards and executives.

At Brightlyn, you build on those exact skills—but instead of stopping at assurance, you:

  • help clients design and improve controls;
  • guide them through cyber regulations such as NIS2 and DORA;
  • translate findings into practical roadmaps that actually get implemented.

This role expands your scope while building on your IT Audit background.

Your Role

As a (Senior) Manager IT Audit & Security Risk, you act as a trusted advisor to senior management, boards, and risk committees. You leverage your audit skills to assess, structure, and improve security governance, risk management, and controls—while translating regulatory and security requirements into pragmatic, achievable solutions. You combine your audit mindset with security and cyber risk expertise to help organizations become demonstrably in control of their information security.

You will assist and lead clients in automating their IT and security control testing, moving from manual, periodic assessments to more efficient and scalable approaches. This includes advising on control design, data‑driven testing, and the use of tooling to enable continuous or semi‑continous assurance.

This role is ideal if you enjoy:

  • moving from assessing controls to helping organizations improve them;
  • combining assurance, advisory, and security;
  • working close to decision‑makers on complex risk topics.
Key Responsibilities
  • Lead IT, security, and cyber risk assessments, focusing on governance, risk management, and internal controls.
  • Translate audit‑style findings into concrete, prioritized improvement plans aligned with business objectives.
  • Advise on compliance with NIS2, DORA, ISO 27001, and related standards—focusing on intent, proportionality, and practicality.
  • Support organizations in strengthening security governance, roles & responsibilities, and risk ownership.
  • Perform and oversee targeted reviews such as ransomware readiness assessments and regulatory gap analyses.
  • Act as a sparring partner for CISOs, CIOs, Risk Managers, and Boards.
  • Contribute to the development of new security, risk, and compliance services.
  • Present clearly and confidently at executive and board level.
Qualifications

We believe this role fits you well if you bring:

  • A background (6‑9 years) in IT Audit, Technology Risk, or IT Assurance, ideally at Manager or Senior Manager level (Big‑4 or similar).
  • A Master’s degree from a research university (WO level); a post‑master degree (e.g. RE) is a strong plus.
  • Relevant professional certifications such as CISSP, CISM and/or CISA.
  • Fluency in Dutch and English, written and spoken.
  • A proven ability to assess, structure, and explain IT and security risks.
  • Affinity with information security and cybersecurity, even if your career started from audit.
  • Interest or experience in cyber regulations such as NIS2, DORA, or similar regulatory frameworks.
  • Strong experience with frameworks such as ISO 27001, COBIT, NIST CSF, or comparable control frameworks.
  • Excellent communication and stakeholder management skills, including board‑level interactions.
  • A pragmatic, advisory mindset and the confidence to challenge and guide clients.
Why Brightlyn?
  • From assurance to impact: Help organizations improve instead of just report.
  • Closer to decision‑making: Work directly with boards and senior leadership.
  • Advisory depth: Combine audit, security, and regulation in one role.
  • Growth & learning: Coaching, mentoring, and room to deepen your security expertise.
  • Great culture & location: A modern office in the Binckhorst district, with facilities, food, drinks, and a gym.
Details
  • Seniority level: Mid‑Senior level
  • Employment type: Full‑time
  • Job function: Accounting / Auditing and Finance
  • Industries: IT Services and IT Consulting
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

(Senior) Manager IT Audit & Assurance
(Senior) Manager IT Audit & Assurance

Deloitte Netherlands • Amsterdam

On-site
EUR 120,000 - 160,000
(Senior) Manager IT Audit & Assurance
(Senior) Manager IT Audit & Assurance

Deloitte Netherlands • Noord-Holland

On-site
EUR 120,000 - 180,000
Cybersecurity Consultant
Cybersecurity Consultant

Highberg B.V. • Zoetermeer

On-site
EUR 70,000 - 98,000
Competitive salary
Performance pay
Pension provisions
+3
IT Auditor/Manager
IT Auditor/Manager

Hanami International • Rotterdam

On-site
USD 70,000 - 117,000
Senior IT Auditor
Senior IT Auditor

PwC Nederland • Rotterdam

Hybrid
EUR 55,000 - 75,000
Competitief salaris
30 vakantiedagen
Persoonlijk well-being budget
+1
Senior IT Auditor
Senior IT Auditor

PwC Nederland • Amsterdam

Hybrid
EUR 55,000 - 80,000
Competitief salaris
Aantrekkelijke pensioenregeling
Hybride werken
+3
Senior Consultant IT Risk & Control
Senior Consultant IT Risk & Control

PwC Nederland • Amsterdam

Hybrid
EUR 65,000 - 85,000
Competitive salary
Attractive pension plan
Customised training for professional growth
+4
Senior IT Auditor
Senior IT Auditor

PwC Nederland • Groningen

Hybrid
EUR 50,000 - 70,000
Competitief salaris
30 vakantiedagen
Hybride werk optie
+2
Senior IT Auditor
Senior IT Auditor

PwC Nederland • Utrecht

Hybrid
EUR 60,000 - 80,000
Competitief salaris
30 vakantiedagen per jaar
Flexibiliteit van hybride werken
+1
Senior IT Auditor
Senior IT Auditor

PwC Nederland • Eindhoven

Hybrid
EUR 55,000 - 75,000
Competitief salaris
Aantrekkelijke pensioenregeling
Opleidingen voor professionele groei
+4