Cyber Lead.
The organisation is looking for a security professional who takes real ownership of security and compliance. You'll join a team that is digitising fast, where reliable and secure IT is essential to the service they deliver. At the heart of the role sits direction and oversight: you bring structure and the right priorities to security and keep firm oversight of it.
Most of your time goes into steering: you actively manage external security and IT partners, bring internal stakeholders on board, build awareness, and safeguard the roadmap and the associated risks. Alongside that - roughly a third of your time - you get hands-on with the technology yourself, working in the Azure environment and the SIEM. You don't only steer from a distance; you also test and improve things yourself. Both sides of the role are inseparable.
You'll work within an existing IT team, with colleagues to spar with and lean on - including an internal knowledge holder who continues to carry the compliance side alongside you. You are the driving force behind security in substance, not the manager of a team. How the role develops further is largely up to you.
What you'll do.
- You actively steer external security and IT partners, including parties responsible for monitoring, cloud and infrastructure. You set and safeguard agreements on SLAs, quality and turnaround time, and keep a grip on delivery even where it sits with partners.
- You lead security incidents and coordinate their handling with those partners, keeping oversight of quality and turnaround time.
- You build the security roadmap and risk management approach, and land these with buy-in across the organisation.
- You steer compliance around ISO 27001, NIS2 and related standards together with an internal knowledge holder who carries this part with you, making sure the standards translate into measures that genuinely work in the Azure environment.
- You build security awareness across the organisation and bring colleagues along.
- You get hands-on with the technology yourself where needed - roughly a third of your time - configuring and reviewing cloud security, identity and monitoring, and getting to the bottom of issues independently.
You'll work in a Microsoft- and Azure-oriented landscape. The tooling spans categories such as a SIEM and monitoring platform, identity and access management (IAM), cloud security posture management and hardening, and endpoint and email security.
Who this role suits.
This role suits you if you get energy from both steering and testing things yourself: you're as sharp in a conversation with a vendor or with management as you are in an Azure console. You take ownership and thrive on bringing structure and direction.
This is explicitly not a pure management or GRC role, nor a pure engineering role:
- If you come from a role where you mainly steered, wrote policy or directed compliance, and haven't done hands-on technical work for a while, this isn't the right fit.
- If you're looking for a purely technical build role and see vendor steering, stakeholder management and incident coordination as a side issue, this isn't the right fit either - steering forms the largest part of this role.
What you bring.
- Demonstrable, recent hands-on experience with cloud security in a Microsoft and Azure environment: posture, hardening, identity and access management, conditional access. You've done this yourself, not only directed it.
- Practical experience with a SIEM and monitoring platform: you've set up and reviewed detections or rules yourself, not just read reports.
- Demonstrable experience steering external security partners on agreements and incident quality, including incident coordination.
- The seniority to lead security and compliance operationally: you've previously built a security roadmap independently and landed it with buy-in across an organisation.
Nice to have: demonstrable success in building security awareness within an organisation; experience working towards ISO 27001 and NIS2 certification; relevant certifications, for example in cloud security, Azure or incident response.
What the organisation offers.
- A clear mandate and a lot of ownership: you set the security roadmap, steer the external partners, and shape the security direction within a digitising organisation.
- A place in an existing IT team with colleagues to spar with - you won't be on your own.
- Room for training and certifications to keep your technical depth and knowledge current.
- A company car.
- Hybrid working: roughly three days a week at the office in the Hoofddorp area or on location at branches across the country, with the remaining days from home. A move to a new office location in the Amsterdam area is planned for early 2027.
- A salary that fits your experience: approximately €6,500 to €9,000 gross per month on a full-time basis.
Apply now.
Your details go straight into our system — no middlemen, no mailing lists.