Information Security Officer (ISO)
Be the Information Security Officer at Sendcloud in Eindhoven: own ISO 27001, drive risk-based decisions, and enable fast, safe growth with hands-on governance. 🚀
📍Eindhoven HQ (3 days in office) | 🗓️ 40hrs per week
🚀 This is what you tell people at parties
We didn't become Europe's leading e-commerce shipping platform by playing it safe. Sendcloud powers 30,000+ online retailers, marketplaces, and fulfillment companies. Helping them ship smarter, grow faster, and actually get shit done for their customers. Boring logistics? Not here. We're building the platform that solves shipping, at scale, globally!
As Information Security Officer, you make sure we can scale fast and safely: keeping our ISO 27001 security program strong, turning security risks into clear decisions, and working with Engineering, Platform, IT, Legal/Privacy, and Support to protect our customers, our people, and our business. Security here is a business enabler, not a checkbox — and this isn't an entry-level seat on the sidelines. You'll lead audits, run risk governance, and influence Engineering leadership from EM to VP.
🧐 The Role
Role Description
- As the Information Security Officer, you own our information security program end-to-end, combining pragmatic governance with hands-on program leadership.
- You keep our ISO 27001 ISMS healthy and audit-ready while driving real security improvements across the company.
- You build clarity, influence stakeholders, and make sure important security work actually gets done — not just documented.
- You participate in architecture forums as a required security reviewer, not the decision maker, helping teams catch security implications early without slowing delivery.
🎯 What you'll do
- Own our ISO 27001 ISMS and keep it always-on — internal audits, evidence, management reviews, corrective actions, and external audit readiness.
- Run security risk management that leads to decisions — maintaining a living risk register, driving mitigations with owners and timelines, and enabling explicit risk acceptance when needed.
- Drive security governance that teams can actually use — practical policies and standards for access, data handling, vendor risk, and incident response.
- Lead security incident governance — classification, escalation, post-incident learning loops, and preventing repeats, in partnership with Platform, Engineering, and Support.
- Manage third-party and vendor security risk — risk tiering, due diligence, and working with Legal on security requirements and ongoing assurance.
- Enable safe use of AI and agentic workflows with clear guardrails, including visibility on shadow IT/AI in collaboration with IT and Platform.
- Report to leadership on security posture, top risks, incidents, audit outcomes, and progress.
✅ What you bring to the table
Personally
- You're pragmatic — you balance security, speed, and customer impact through risk-based thinking rather than defaulting to "no."
- You have a hands-on ownership mentality — you don't just write policies, you help make them real.
- You can influence, challenge, and drive follow-through with stakeholders at every level, up to VP.
Professionally
- 3+ (typically 5+) years of relevant experience, with proven ownership of an ISMS/audit cycle (ISO 27001 or equivalent) and the ability to drive cross-functional remediation independently — ideally in SaaS/tech or a fast-paced scale-up.
- Proven experience operating or significantly contributing to an ISO 27001 ISMS, driving audit readiness and remediation.
- Strong written and verbal communication in English — you turn complex security topics into clear actions and decisions.
- Nice to have: experience preparing for SOC 2 readiness or similar assurance frameworks.
- Nice to have: familiarity with AI governance and AI risk management concepts, or strong curiosity to learn fast.
- Nice to have: certifications such as CISSP, CISM, CISA, Security+, or ISO 27001 Lead Implementer/Auditor.
- Nice to have: experience with vendor security reviews, security questionnaires, and enterprise customer trust requirements.
❤️ Our Values
- 💩 No bullshit: Big egos suck. Be open, honest and transparent. Share your mistakes openly and learn from them. Don't just talk about problems, solve them.
- 🎯 Grow & win: Be highly curious, adaptable & proactive. Embrace discomfort and change. Keep an open mindset and learn from others. You invest in our growth, so we invest in yours.
- 🎠 Have fun: Work hard, laugh harder. Not everything has to be serious. Be yourself, especially if you're the good kind of crazy. Sendcloud is an adventure, not a corporate maze, enjoy the ride.
🎉 Benefits
💸 Salary - From €70,000 gross annually, incl. 8% holiday allowance (higher possible based on experience and skill set).
🧠 Brain Benefits - €2,000 learning budget · Courses, certifications & conferences · Growth in an international team
🌴 Time Benefits - 28 days of paid vacations per year · Extra day off on your birthday · Swap public holidays for meaningful ones
✈️ Sabbatical Benefits - 4 weeks fully paid every 3 years
🏡 Home Benefits - Flexible hybrid model (3 days/week in office) · €500 home office budget
💪 Body Benefits - Company gym · Free lunch every Monday · Fresh fruit · Barista coffee
🚌 Travel Benefits - Monthly commuting allowance
🪑 Future Benefits - Pension scheme · Employee discount programs
🐾 Vibe Benefits - Dog-friendly office · After-hours drinks at the Sendcloud Bar
- Department
- IT & Security
- Role
- Information Security Officer
- Locations
- Eindhoven HQ
- Remote status
- Hybrid
- Yearly salary
- €70,000