Information Security Officer
Mendix · Rotterdam (hybrid)
Hybrid
mid
information security
Apply on Mendix →
About Us:
Mendix, part of Siemens Digital Industries Software, is looking for a proactive Information Security Officer to help protect our information assets, strengthen compliance with evolving regulations, and build a security-first outlook across the organization. It's a phenomenal opportunity to make a real, visible impact on the resilience of our digital infrastructure.
What you'll be doing:
As an Information Security Officer, you will support a range of operational security activities, including:
Control Design & Operating Effectiveness: Assess the effectiveness of existing security controls against defined risks, and flag gaps or improvement areas.
Compliance Monitoring & Reporting: Monitor compliance against security frameworks and regulatory requirements (e.g., SOC 1 & 2, ISO 27001, NIST, C5, ISO 42001), conduct gap assessments against applicable laws, regulations, and internal frameworks, and report status and findings to relevant partners.
Audit Support: Support internal and external audits by gathering, assessing, and providing vital evidence to demonstrate compliance.
Evidence lifecycle management: Handle collection, secure storage and archival of security evidence to ensure its integrity and availability for audits.
Policy & Standard Development: Research, establish, and maintain information security policies, standards, and procedures tailored to specific organizational needs and emerging threats.
Security Culture & Communication: Communicate security requirements, policy updates, and risk information clearly to relevant teams to support a security-conscious culture.
Control Implementation & Maintenance: Collaborate with applicable departments to ensure security controls are successfully implemented, maintained, and continuously optimized.
What you'll bring:
We're looking for someone with a proven foundation in information security and a proactive, diligent approach.
Skills & Qualifications:
Experience: 3-5 years of dynamic experience in an Information Security, IT Audit, or Compliance role, with a working understanding of core information security principles and practices.
Cloud Security Expertise: Understanding of security controls, and best practices within cloud environments (e.g., AWS, Azure, GCP). Familiarity with cloud security tools is a plus.
Framework & Regulation Knowledge: Solid grasp and practical experience with a range of information security standards, frameworks, and regulations (e.g., ISO/IEC 27001 family, GDPR, SOC 2 Trust principles).
Enterprise IT Familiarity: Familiarity with enterprise data environments, system integrations, and software development lifecycles (SDLC).
Certifications: An active information security certification (e.g., CISM, CISSP, ISO 27001 Lead Implementer, CompTIA Security+) is required.
Analytical Thinking: Good analytical and problem-solving skills, with the ability to perform gap analyses and support development of practical solutions.
Communication: Clear written and verbal communication skills in English, able to explain security topics to both technical and non-technical audiences.
Initiative & Collaboration: High level of initiative, self-direction, and the ability to work independently while also being a strong team player and collaborating optimally across departments.
Posted 2026-06-15