7 hours, 41 minutes ago

Information Security Analyst (second line)

IMPORTANT INFORMATION

Only applications that meet the criteria set out by Aquafin (skills, work experience, language proficiency, and availability) in this job post will be considered. If the above is not respected, Aquafin reserves the right to reject the application.
Attached you will find several documents that are an integral part of the “Statement of Work” and are deemed to have been read and approved upon the consultant’s start.

About Aquafin

At Aquafin, we connect people with people, water, and technology. We stay ahead of change and work towards an environment that is in harmony with water. We do this through water purification and sewage management, but also through innovation and energy transition.

Every day, we contribute to better water quality and a healthy living environment. We realize infrastructure projects that collect and purify domestic wastewater and are constantly working to optimize our existing networks and installations. In this way, we support the ambition to achieve the ecological objectives for our waterways.

As an Information Security Analyst (Second Line), you support the NIS2 implementation and preparations for the audit for our organization (essential).

In this second-line role, you independently assess the quality of documentary evidence and implementation evidence that is provided by the domains (first line) based on CyFun guidance. You also validate that the evidence supports the scores and is not based on assumptions so that it will withstand scrutiny by the external auditor. You provide feedback to the domain owners. In addition, you formulate tangible improvement points for them to work on.

You are also responsible for file building, including an evidence register, that can be submitted to the auditor without rework.

We will first work towards the important level, and you will continue to support preparations for the essential level after April 2027.

You have 3 to 6 years of experience in information security, compliance, or IT audit. You are familiar with control frameworks such as CyFun, ISO 27001, and/or CIST CSF. You are able to interpret and assess technical evidence such as configuration exports, log files, tickets, recovery and scan reports. Your role is situated in the second line and does not include operational tasks such as pentesting, SOC activities, or engineering.

The function reports to the CISO and requires a critical, analytical, and independent attitude. The CISO supports you in case of doubt, methodology, and escalation. The first line is responsible for self-assessment, providing evidence, and remediation.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration