Magnet.me  -  Het slimme netwerk waar studenten en professionals hun stage of baan vinden.

Het slimme netwerk waar studenten en professionals hun stage of baan vinden.

Information Security Officer (ISO)

Geplaatst 29 jul. 2026
Delen:
Werkervaring
3 tot 8 jaar
Full-time / part-time
Full-time
Functie
Salaris
€ 70.000 per jaar
Opleidingsniveau
Taalvereiste
Engels (Vloeiend)

Bouw aan je carrière op Magnet.me

Maak een profiel aan en ontvang slimme aanbevelingen op basis van je gelikete vacatures.

Be the Information Security Officer at Sendcloud in Eindhoven: own ISO 27001, drive risk-based decisions, and enable fast, safe growth with hands-on governance. 🚀

As Information Security Officer, you make sure we can scale fast and safely: keeping our ISO 27001 security program strong, turning security risks into clear decisions, and working with Engineering, Platform, IT, Legal/Privacy, and Support to protect our customers, our people, and our business. Security here is a business enabler, not a checkbox — and this isn't an entry-level seat on the sidelines. You'll lead audits, run risk governance, and influence Engineering leadership from EM to VP.

🚀 This is what you tell people at parties

Sendcloud powers 30,000+ online retailers, marketplaces, and fulfillment companies. Helping them ship smarter, grow faster, and actually get shit done for their customers. We're building the platform that solves shipping, at scale, globally.

🧐 The Role

Role Description

  • As the Information Security Officer, you own our information security program end-to-end, combining pragmatic governance with hands-on program leadership.
  • You keep our ISO 27001 ISMS healthy and audit-ready while driving real security improvements across the company.
  • You build clarity, influence stakeholders, and make sure important security work actually gets done — not just documented.
  • You participate in architecture forums as a required security reviewer, not the decision maker, helping teams catch security implications early without slowing delivery.

🎯 What you'll do

  • Own our ISO 27001 ISMS and keep it always-on — internal audits, evidence, management reviews, corrective actions, and external audit readiness.
  • Run security risk management that leads to decisions — maintaining a living risk register, driving mitigations with owners and timelines, and enabling explicit risk acceptance when needed.
  • Drive security governance that teams can actually use — practical policies and standards for access, data handling, vendor risk, and incident response.
  • Lead security incident governance — classification, escalation, post-incident learning loops, and preventing repeats, in partnership with Platform, Engineering, and Support.
  • Manage third-party and vendor security risk — risk tiering, due diligence, and working with Legal on security requirements and ongoing assurance.
  • Enable safe use of AI and agentic workflows with clear guardrails, including visibility on shadow IT/AI in collaboration with IT and Platform.
  • Report to leadership on security posture, top risks, incidents, audit outcomes, and progress.

✅ What you'll bring to the table

Personally

  • You're pragmatic — you balance security, speed, and customer impact through risk-based thinking rather than defaulting to "no."
  • You have a hands-on ownership mentality — you don't just write policies, you help make them real.
  • You can influence, challenge, and drive follow-through with stakeholders at every level, up to VP.

Professionally

  • 3+ (typically 5+) years of relevant experience, with proven ownership of an ISMS/audit cycle (ISO 27001 or equivalent) and the ability to drive cross-functional remediation independently — ideally in SaaS/tech or a fast-paced scale-up.
  • Proven experience operating or significantly contributing to an ISO 27001 ISMS, driving audit readiness and remediation.
  • Strong written and verbal communication in English — you turn complex security topics into clear actions and decisions.
  • Nice to have: experience preparing for SOC 2 readiness or similar assurance frameworks.
  • Nice to have: familiarity with AI governance and AI risk management concepts, or strong curiosity to learn fast.
  • Nice to have: certifications such as CISSP, CISM, CISA, Security+, or ISO 27001 Lead Implementer/Auditor.
  • Nice to have: experience with vendor security reviews, security questionnaires, and enterprise customer trust requirements.

❤️ Our Values

  • 💩 No bullshit: Big egos suck. Be open, honest and transparent. Share your mistakes openly and learn from them. Don't just talk about problems, solve them.
  • 🎯 Grow & win: Be highly curious, adaptable & proactive. Embrace discomfort and change. Keep an open mindset and learn from others. You invest in our growth, so we invest in yours.
  • 🎠 Have fun: Work hard, laugh harder. Not everything has to be serious. Be yourself, especially if you're the good kind of crazy. Sendcloud is an adventure, not a corporate maze, enjoy the ride.

🎉 Benefits

🧠 Brain Benefits - €2,000 learning budget · Courses, certifications & conferences · Growth in an international team

🌴 Time Benefits - 28 days of paid vacations per year · Extra day off on your birthday · Swap public holidays for meaningful ones

✈️ Sabbatical Benefits - 4 weeks fully paid every 3 years

🏡 Home Benefits - Flexible hybrid model (3 days/week in office) · €500 home office budget

💪 Body Benefits - Company gym · Free lunch every Monday · Fresh fruit · Barista coffee

🚌 Travel Benefits - Monthly commuting allowance

🪑 Future Benefits - Pension scheme · Employee discount programs

🐾 Vibe Benefits - Dog-friendly office · After-hours drinks at the Sendcloud Bar

SendCloud is de verzendoplossing die iedere webwinkel veel tijd en kosten bespaart. De kosten van een verzending via SendCloud zijn lager, simpelweg door ons inkoopvoordeel bij PostNL. Daarnaast scheelt het tijd, labels worden automatisch gegenereerd door ons systeem en ze hoeven alleen nog maar te worden geprint. De pakketten worden automatisch voorgemeld, deze zijn direct klaar om afgegeven te worden…


SendCloud is de verzendoplossing die iedere webwinkel veel tijd en kosten bespaart. De kosten van een verzending via SendCloud zijn lager, simpelweg door ons inkoopvoordeel bij PostNL. Daarnaast scheelt het tijd, labels worden automatisch gegenereerd door ons systeem en ze hoeven alleen nog maar te worden geprint. De pakketten worden automatisch voorgemeld, deze zijn direct klaar om afgegeven te worden bij of opgehaald te worden door PostNL. Alle verzendingen worden achteraf gefactureerd.

Wij bieden een compleet systeem waarmee de kleine of middelgrote webwinkelier al zijn pakketten gemakkelijk verzendklaar kan maken. Dankzij de verregaande integratie met verschillende webshop systemen zoals Magento, OpenCart, SEOshop en vele andere, is het mogelijk om alle zendingen direct te importeren naar SendCloud. Hier kan vervolgens voor alle zendingen een verzendmethode worden aangevraagd, in één keer of individueel. Een pakket kan verzonden worden met de 24-uurs service van PostNL in heel Europa, eventueel met handtekening voor ontvangst of verzekerd. Daarnaast neemt het systeem veel tijdrovend werk uit handen door middel van een koppeling tussen de webwinkel en onze verzendomgeving.

ICT
Eindhoven
80 medewerkers