🇳🇱 Amsterdam, Netherlands · 19h ago
HEAD OF INFORMATION SECURITY
F2F.com
LinkedInleadEnglish-friendly
Head of Information SecurityAre you a hands-on security leader who wants to take real ownership? At F2F.com, we're looking for a Head of Information Security who sets the direction, rolls up their sleeves and helps us build a platform creators can trust.This role is open to residents of the Netherlands only.About The RoleWe are looking for a proactive, hands on Head of Information Security who takes real ownership of security at F2F.com. You set the direction, but you also roll up your sleeves: you review code with our engineers, step in when something goes wrong and keep things practical rather than bureaucratic.In a growing company like ours, security only works when everyone understands why it matters. You work across the whole company, not just with the development team: with our support and safety teams on escalations, with leadership on risk and with every colleague on awareness. From our engineers to our office manager, you make sure everyone knows what good security looks like in their daily work. In the near future, you will also lead our journey towards ISO 27001 certification.What you will doStrategy and governanceDevelop, implement and maintain practical information security policies aligned with our business goals, without unnecessary bureaucracy.Assess security risks, maintain the risk register and advise leadership on mitigation strategies.Oversee security evaluations of third party suppliers and keep track of data flows to external vendors.Prepare and guide the ISO 27001 certification process, building an ISMS that fits the size and pace of our organisation.Hands on security engineeringPerform regular code reviews to identify, document and remediate vulnerabilities (such as the OWASP Top 10 and business logic flaws).Partner with software engineers to design secure services, API integrations and database interactions.Integrate SAST, DAST and dependency scanning into our CI/CD pipelines.Design and implement robust Identity and Access Management (IAM) for internal and customer facing systems.Act as our go to expert on cryptography, token authentication, secure session handling, and cooperate with legal and compliance on matters such as legally required security measures, privacy and data protection and the secure use of AI within the organisation.Incident response and escalationsLead incident response: preparation, detection, containment and thorough reviews afterwards.Take the lead in escalations, working closely with our support team and safety team, and prevent escalations where possible by managing risks early.Work with our partner on device management and endpoint security, including MDM rollout and EDR/XDR monitoring.Set up threat intelligence and dashboards to report monthly on security posture, incidents and threat vectors.Security awareness across the companyTake the whole organisation along in security awareness, translating technical risks into clear and practical guidance that every colleague understands.Build a security culture where people know what to do and feel comfortable raising concerns.What you bringStrong interpersonal skills and organisational sensitivity: you can explain security to a developer, a support agent and a founder, each in their own language.Proven ability to drive organisational change and implement security measures that people actually adopt.Leadership in escalations, combined with a preventive mindset.Proactive and self directed: you see what needs to be done and act on it without waiting to be asked.5+ years of practical experience in software development or security engineering, with a focus on Python, Node and API security.Comfortable in CI/CD: SAST/DAST/SCA integration, IaC review and cloud (AWS).Deep technical understanding of application security, secure code design and API security.Experience running or building an ISMS (ISO 27001 or NIST CSF), ideally in a small or medium sized organisation. Experience guiding an ISO 27001 certification is a strong plus.Nice to have: experience with MDM, EDR/XDR endpoint monitoring and zero trust solutions.Fluency in English and Dutch is a plus.What we OfferCompetitive salary and strong secondary benefits24 vacation daysFully paid pension plan, no employee contributionFree lunch at the officeNS Business CardFlexible working hours and hybrid working€1,000 personal development budget per yearGym subscription via ClassPass or a sports venue of your choiceLease-a-bike schemeSalary between €6000 - €9500Interested?Sound like your next move? We'd love to hear from you, portfolio or side project included if you have one. Send your CV and motivation letter to Recruitment@f2f.com. Apply now and come help us build a platform creators can trust.apply nowSourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.