Head of Information Security, Netherlands

Head of Information Security, Netherlands

Full-Time 80000 - 100000 € / year (est.) No home office possible
Ant Group

At a Glance

  • Tasks: Lead and oversee Information Security strategies and compliance in a dynamic financial services environment.
  • Company: Join Ant International, a leader in digital payment solutions and global commerce innovation.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Engage with top regulators and lead initiatives that shape the future of digital finance.
  • Why this job: Make a significant impact on global security standards and drive innovation in a collaborative culture.
  • Qualifications: 8+ years in ICT risk or cybersecurity, with strong knowledge of regulatory frameworks and cloud security.

The predicted salary is between 80000 - 100000 € per year.

Ant International powers the future of global commerce with digital innovation for everyone and every business to thrive. In close collaboration with partners, we support merchants of all sizes worldwide to realise their growth aspirations through a comprehensive range of tech-driven digital payment and financial services solutions. With a focus on Travel, Trade, Technology, and Talent, Ant International is committed to enhancing the digital mindset and capacities of businesses worldwide. Through fostering collaborative efforts with partners, we are driving responsible innovation and increasing market accessibility for global SMEs.

What you will be doing:

  • Governance & Strategy: Develop, maintain, and oversee the Information Security and ICT Risk Management Frameworks in line with DORA, ISO 27001, NIST, and other applicable standards. Establish, maintain, and enforce security policies, standards, and procedures. Provide independent second-line challenge to first-line controls and risk management activities. Report on security posture to the Board and leadership team.
  • Regulatory Compliance & Engagement: Ensure full compliance with DORA (ICT risk management, incident reporting, resilience testing, third-party risk), PSD2-SCA, PCI-DSS, SWIFT CSP, GDPR (as it relates to ICT), and EBA guidelines. Act as the primary liaison for DNB, EBA, and other regulators; manage regulatory inquiries, audits, inspections, and reporting obligations.
  • Incident & Access Management: Own and manage end-to-end response to security incidents and data breaches, including coordination, escalation, investigation, containment, and regulatory reporting in line with DORA and GDPR. Oversee access control governance, including user provisioning, privileged access, and periodic access reviews. Manage KMS and (CBD) security practices in accordance with internal policies and regulatory expectations.
  • Third-Party & Outsourced Security Oversight: Maintain ownership of all outsourced security activities (e.g., SOC, penetration testing providers), ensuring service quality, SLA adherence, and alignment with security and compliance requirements. Manage the ICT third-party risk lifecycle, including due diligence, ongoing monitoring, and maintenance of the DORA register of critical ICT third-party providers.
  • Risk, Resilience & Assurance: Identify, assess, prioritise, and report ICT and cyber risks; define key risk indicators and present risk posture to the Board and Risk Committees. Oversee digital operational resilience testing (including threat-led penetration testing) and disaster recovery from an ICT perspective. Monitor the governance and technical effectiveness of cybersecurity controls (SIEM, EDR, DLP, IAM, vulnerability management, and data security) and track remediation of audit and assessment findings.
  • Culture, Collaboration & Stakeholder Engagement: Deliver security awareness programmes and foster a security-conscious culture. Advise the local entity Board, senior management, and technology teams on risk posture, outsourcing, and major technology changes. Collaborate with and provide subject-matter expertise to the EMEA Information Security team on regional projects and BAU activities.

What we are looking for:

  • 8+ years’ experience in ICT risk, cybersecurity governance, or audit within financial services.
  • Proven experience implementing DORA and engaging with DNB or comparable EU regulators.
  • Strong technical foundation in cloud security, IT infrastructure, application security, and cyber threats.
  • Strong knowledge of cloud security controls, SIEM, EDR, DLP, IAM, and security architecture.
  • Awareness of AI security risks and controls.
  • Experience in incident response and third-party security management.
  • Ability to influence stakeholders, present to Boards and regulators, and operate independently in a second-line role.
  • Fluent in English and Dutch.
  • Demonstrated ability to lead complex security compliance, incident response, and security initiatives in regulated environments.

Head of Information Security, Netherlands employer: Ant Group

Ant International is an exceptional employer, offering a dynamic work environment in the Netherlands that champions innovation and collaboration. With a strong commitment to employee growth, we provide comprehensive training and development opportunities, fostering a culture of security awareness and teamwork. Our focus on digital transformation in global commerce ensures that you will be at the forefront of cutting-edge technology while enjoying the benefits of a supportive workplace that values your contributions.

Ant Group

Contact Detail:

Ant Group Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Information Security, Netherlands

Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or conferences related to information security. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your expertise! Create a personal blog or LinkedIn posts where you share insights about ICT risk management, compliance, or cybersecurity trends. This not only showcases your knowledge but also helps you stand out to potential employers.

Tip Number 3

Don’t just apply; engage! When you find a role that excites you, reach out to current employees on LinkedIn. Ask them about their experiences and the company culture. This can give you valuable insights and make your application more memorable.

Tip Number 4

Apply through our website! We love seeing candidates who take the initiative. Tailor your application to highlight your experience with DORA, GDPR, and other relevant regulations. Make it clear why you're the perfect fit for the Head of Information Security role!

We think you need these skills to ace Head of Information Security, Netherlands

Governance & Strategy
Information Security Frameworks
DORA Compliance
ISO 27001
NIST Standards
Regulatory Compliance
Incident Response Management

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Head of Information Security role. Highlight your experience in ICT risk and cybersecurity governance, especially any work with DORA or EU regulators. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you the perfect fit for our team. Don’t forget to mention your experience with cloud security and incident response.

Showcase Your Achievements:When detailing your experience, focus on specific achievements rather than just responsibilities. Did you lead a successful incident response? Did you implement a new security framework? We love numbers and results, so make them stand out!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at Ant International!

How to prepare for a job interview at Ant Group

Know Your Frameworks

Make sure you’re well-versed in DORA, ISO 27001, and NIST standards. Brush up on how these frameworks apply to the role and be ready to discuss your experience with them. This shows you’re not just familiar but can actively contribute to governance and strategy.

Showcase Your Compliance Knowledge

Prepare to talk about your experience with regulatory compliance, especially with DNB and EBA. Have specific examples ready that demonstrate how you've managed audits or regulatory inquiries in the past. This will highlight your ability to navigate complex compliance landscapes.

Incident Management Experience

Be ready to discuss your approach to incident response and access management. Share specific incidents you've managed, detailing your role in coordination, investigation, and reporting. This will illustrate your hands-on experience and problem-solving skills in high-pressure situations.

Engage with Stakeholders

Think about how you’ve influenced stakeholders in previous roles. Prepare examples of how you’ve communicated risk posture to boards or senior management. This will show your ability to engage effectively and foster a security-conscious culture within an organisation.