Introduction
- 36 hours per week
- Start date: ASAP
- End date: 30 September 2027
- Hybrid working, 1-2 days from the office.
- Travelling abroad is required for this role.
- Candidates have to live in the Netherlands.
Function
You will join the Supply Chain Security (SCS) team, part of the Corporate Information Security Office (CISO) department, within the Cyber Defence grid. CISO is responsible for the bank’s information security globally, across all subsidiaries and countries. The grid Cyber Defence is responsible for the security operations activities of ABN AMRO, and within our team we continuously provide visibility into the security posture of the vendors of ABN AMRO. The 20 Supply Chain Security team members are experienced in information security and vendor relations. The team is diverse in both nationalities and professional background, which makes it a great place to work and develop yourself.
You can imagine that security is a major asset within the bank.
As an Information Security Expert you will be responsible to manage, monitor and report on the performance and the status of the security posture of our vendors. This role is specifically aimed at conducting end to end audits.
The team works according to the DevOps & Agile methodology.
The working language within the team is English.
For your work you often engage with various stakeholders such as; Risk, Procurement, Contract Owners and our suppliers.
With the following results (SMART)
– The Information security expert is responsible for conducting comprehensive, end‑to‑end audits of systems, processes, SaaS platforms, and internal controls to ensure compliance, security, operational efficiency, and risk mitigation.
– This role involves detailed analysis, evidence gathering, root‑cause identification, and actionable reporting to stakeholders across Security, IT, Compliance, and Business units.
– The expert provides insight into gaps, emerging risks, and improvement opportunities.
Requirements
Technical Skills
– Strong understanding of IT platforms, applications, security architectures, cloud/SaaS models, and shared responsibilities.
– Hands-on experience assessing configurations, access controls, authentication, security settings, system behaviour, logs, audit trails, and monitoring data.
– Solid IAM knowledge, including RBAC, PAM, access governance, and user lifecycle controls.
– Able to evaluate control design and operating effectiveness using direct system evidence.
– Knowledge of IT and cloud security, compliance requirements, internal policies, and frameworks such as ISO 27001, SOC 2, NIST, CIS, and GDPR.
Analytical Skills: Excellent attention to detail, critical thinking, and problem-solving; able to identify patterns, anomalies, root causes, and risks.
Interpersonal Skills: Communicates complex findings clearly to non-technical audiences; collaborates effectively across Security, IT, DevOps, Compliance, and Business teams; produces strong documentation, reports, and presentations.
Experience
– Typically 6–8 years of experience in internal audit, security auditing, IT risk, compliance, or a related field.
– SaaS experience is highly desirable; exposure to security posture reviews
Preferred Certifications (Not mandatory, but beneficial)
– CISA (Certified Information Systems Auditor)
– ISO 27001 Lead Audit
Information
Priya Jha +31(0)20-3337629
Application
Priya Jha +31(0)20-3337629