Information & Security Officer

We are actively looking for a Information & Security Officer. Are you highly motivated and ready to join our next-gen security team?

Get in touch

Are you the responsible rebel we are looking for?

Because 'we have a policy for that' is not the same as being secure.

Hunt & Hackett helps European companies prevent, detect and respond to today’s most advanced adversaries, safeguarding them against cyberthreats such as espionage. We don’t just stir a bit into security strategies; our talented team of responsible rebels shakes them up to build, operate and maintain digital immune systems for our customers to outsmart their digital adversaries.

To extend our multidisciplinary team, we are now hiring a Information & Security Officer. Do you enjoy turning ISO 27001 requirements into controls people can actually work with? Does a clean risk register give you the same quiet satisfaction others get from inbox zero? Can you challenge an engineer, an analyst and a member of management without becoming the compliance police? And have you spent enough time in or around SOC operations, red teaming, penetration testing, incident response or fast-moving development teams to know that a control can be compliant on paper and useless in production? Then Hunt & Hackett might be the best next step in your career.

 

Information Security Officer at Hunt & Hackett

An information & Security officer at Hunt & Hackett is not a human checkbox or the person who only appears when an audit starts. You help keep our ISMS in shape and both our feet in reality. This means clear policies, sensible controls, risks with owners and actions that actually get closed. You work alongside colleagues from security operations, incident response, developers and the wider business. We are not trying to build a utopian security world where budgets are unlimited, systems never change and users never make mistakes. That world does not exist. A control is only useful if it works on a calm Tuesday and at 02:00 during an incident. We don't expect you to know every clause by heart. We do expect you to ask good questions, follow through and learn quickly. Your responsibilities include: 

  • [Keep the ISMS real]: maintain and improve policies, procedures, control descriptions and supporting records. If a document describes a parallel universe instead of Hunt & Hackett, you help bring it back to reality.
  • [Risk without theatre]: help identify and assess information security risks, maintain the risk register and follow up on treatment actions. You distinguish between what seriously reduces risk, what helps a little and what mainly makes the framework look complete. A risk without an owner is just a well-documented future surprise.
  • [Audit-ready, not audit-panicked]: coordinate internal reviews and support external audits, including the collection and validation of evidence. Evidence should be part of the process, not an archaeological expedition the week before the auditor arrives.
  • [Close the loop]: work with operational and technical teams to evaluate controls, exceptions, incidents and audit findings. You turn lessons from the SOC, incident response, red teaming and development into practical improvements instead of another meeting about improvements.
  • [Make security understandable]: give colleagues pragmatic advice, contribute to security awareness and translate requirements into language people can use. 'Because ISO says so' is not considered a complete explanation.

 

The Hunt & Hackett wish list. The right candidate has

  • [GRC foundation]: you have experience with information security governance, risk, compliance or audit and understand how an ISMS works. Familiarity with ISO 27001 and SOC 2 is valuable. Knowing where to find the right clause and what it means in practice matters more than reciting it from memory.
  • [Practical security mileage]: you have worked in or closely with one or more practical security fields, such as SOC operations, red teaming, penetration testing, incident response, security engineering or technical infrastructure. Experience with DevOps, SRE or high-paced development teams is equally relevant.
  • [Technical curiosity]: you don't need to be the person popping shells or carrying the pager today, but you should understand what happens on the other side of a policy. You are comfortable asking technical colleagues how something really works and curious enough to keep asking when the first answer is 'it depends'.
  • [Structure and follow-through]: you can maintain accurate documentation, collect evidence, track actions and follow up with owners until matters are properly closed. You like details, but you don't lose sight of why they matter.
  • [Communication]: you can explain security requirements in plain language, ask constructive questions and write concise policies, reports and recommendations. You are comfortable working in English; Dutch is an advantage.
  • [Pragmatism]: you can distinguish between controls that materially reduce risk, controls that help a little and controls that are theoretically elegant but practically useless. You prefer a workable 80% solution that people actually use over a perfect control that only exists on paper. You can explain the trade-off, make a conscious decision and revisit it when the circumstances change.

Please note: this is a wish list, not a bingo card. If you recognize yourself in most of it and can explain how you would grow into the rest, we encourage you to apply. At Hunt & Hackett, potential and the ability to learn count for a lot.


What is your wish list? As a minimum, Hunt & Hackett offers you:

    • A monthly salary of course; 
    • The opportunity to safeguard Europe’s leading organizations;
    • A unique culture of ‘responsible rebellion’ where you can learn from the best to get the most out of yourself;
    • The most innovative approach to get the job done;
    • Being part of a winning team, with room for fun, learning and developing yourself;
    • A proper laptop to get the job done;
    • A modern pension, which is transparent and can be controlled by yourself;
    • Employee share participation scheme;
    • Compensation for your travel costs
    • Daily lunch is in us; we prepare and enjoy it as a team
 

A culture of ‘responsible rebellion’

Only (very) talented, multidisciplinary teams of threat hunters, intelligence analysts, reverse engineers, data scientists, developers and hackers are able to outsmart the increasingly professional community of cyber attackers. We pride ourselves as a force for the good and as such we think and act as responsible rebels. We are not ‘just another security company’, and our people are not ‘just employees’. Everyone at Hunt & Hackett wants to be the best in their field and focuses at delivering next-gen levels of service. This means that we live by:

    • Security first: a foundational core value that underscores our company's unwavering commitment to prioritizing security in all aspects of our operations.
    • Pushing the envelope: Everyone at our teams takes the responsibility to make our work better every day, by being creative to color outside of the lines if needed.​
    • Everything is important: Tiny details have a huge impact, especially in security. We are system thinkers that oversee the big picture and who are simultaneously obsessive about details. That’s why we champion tradecraft.
    • Perseverance: To become successful, you will have to endure challenges, errors, failures and obstacles along the way. These may take weeks, months, or years to overcome.
    • Ego is the enemy: Ego ultimately prevents us from learning, holds us back and makes us overreach. It is therefore important to battle that inner force that destroys great empire's, companies, careers and tears apart relationships.

We’d love to hear from you! For more information or to apply, please fill out the form below. If you're viewing this on a Job Posting site, please still do fill out the form on our website (https://www.huntandhackett.com/jobs)

 

Better safe than sorry. We like to be certain when we’re adding new colleagues to our team. Therefore we use a stringent application process that includes three personal conversations and an assignment. Do note that a pre-employment screening is part of the application and selection process and precedes employment.

 

We like to do our own matchmaking. Recruitment agencies, please don't call us. We'll call you (actually, we probably won't).


 

Application Form

Submit a talent!

Introduce your network

Recruiting skilled security professionals is a quest in itself. Do you know someone who could be the perfect fit for our team? Please let us know and if it's a match we'll have a nice reward for you!

Interested?

Get in touch