Connecting Odds
Back to jobs
Sendcloud

Information Security Officer (ISO)

Discovered
Sendcloud
Eindhoven, NLPosted 5 months ago (Mar 5, 2026)

About the role

πŸ“Eindhoven HQ (3 days in office) | πŸ—“οΈ 40hrs per week

πŸš€ This is what you tell people at parties

We didn't become Europe's leading e-commerce shipping platform by playing it safe. Sendcloud powers 30,000+ online retailers, marketplaces, and fulfillment companies. Helping them ship smarter, grow faster, and actually get shit done for their customers. Boring logistics? Not here. We're building the platform that solves shipping, at scale, globally! As Information Security Officer, you make sure we can scale fast and safely: keeping our ISO 27001 security program strong, turning security risks into clear decisions, and working with Engineering, Platform, IT, Legal/Privacy, and Support to protect our customers, our people, and our business. Security here is a business enabler, not a checkbox β€” and this isn't an entry-level seat on the sidelines. You'll lead audits, run risk governance, and influence Engineering leadership from EM to VP.

Role Description

β€’ As the Information Security Officer, you own our information security program end-to-end, combining pragmatic governance with hands-on program leadership. β€’ You keep our ISO 27001 ISMS healthy and audit-ready while driving real security improvements across the company. β€’ You build clarity, influence stakeholders, and make sure important security work actually gets done β€” not just documented. β€’ You participate in architecture forums as a required security reviewer, not the decision maker, helping teams catch security implications early without slowing delivery.

🎯 What you'll do

β€’ Own our ISO 27001 ISMS and keep it always-on β€” internal audits, evidence, management reviews, corrective actions, and external audit readiness. β€’ Run security risk management that leads to decisions β€” maintaining a living risk register, driving mitigations with owners and timelines, and enabling explicit risk acceptance when needed. β€’ Drive security governance that teams can actually use β€” practical policies and standards for access, data handling, vendor risk, and incident response. β€’ Lead security incident governance β€” classification, escalation, post-incident learning loops, and preventing repeats, in partnership with Platform, Engineering, and Support. β€’ Manage third-party and vendor security risk β€” risk tiering, due diligence, and working with Legal on security requirements and ongoing assurance. β€’ Enable safe use of AI and agentic workflows with clear guardrails, including visibility on shadow IT/AI in collaboration with IT and Platform. β€’ Report to leadership on security posture, top risks, incidents, audit outcomes, and progress.

Personally

β€’ You're pragmatic β€” you balance security, speed, and customer impact through risk-based thinking rather than defaulting to "no." β€’ You have a hands-on ownership mentality β€” you don't just write policies, you help make them real. β€’ You can influence, challenge, and drive follow-through with stakeholders at every level, up to VP.

Professionally

β€’ 3+ (typically 5+) years of relevant experience, with proven ownership of an ISMS/audit cycle (ISO 27001 or equivalent) and the ability to drive cross-functional remediation independently β€” ideally in SaaS/tech or a fast-paced scale-up. β€’ Proven experience operating or significantly contributing to an ISO 27001 ISMS, driving audit readiness and remediation. β€’ Strong written and verbal communication in English β€” you turn complex security topics into clear actions and decisions. β€’ Nice to have: experience preparing for SOC 2 readiness or similar assurance frameworks. β€’ Nice to have: familiarity with AI governance and AI risk management concepts, or strong curiosity to learn fast. β€’ Nice to have: certifications such as CISSP, CISM, CISA, Security+, or ISO 27001 Lead Implementer/Auditor. β€’ Nice to have: experience with vendor security reviews, security questionnaires, and enterprise customer trust requirements.

❀️ Our Values

β€’

πŸ’© No bullshit

Big egos suck. Be open, honest and transparent. Share your mistakes openly and learn from them. Don't just talk about problems, solve them. β€’

🎯 Grow & win

Be highly curious, adaptable & proactive. Embrace discomfort and change. Keep an open mindset and learn from others. You invest in our growth, so we invest in yours. β€’

🎠 Have fun

Work hard, laugh harder. Not everything has to be serious. Be yourself, especially if you're the good kind of crazy. Sendcloud is an adventure, not a corporate maze, enjoy the ride.

πŸŽ‰ Benefits

πŸ’Έ Salary - From €70,000 gross annually, incl. 8% holiday allowance (higher possible based on experience and skill set). 🧠 Brain Benefits - €2,000 learning budget Β· Courses, certifications & conferences Β· Growth in an international team 🌴 Time Benefits - 28 days of paid vacations per year Β· Extra day off on your birthday Β· Swap public holidays for meaningful ones ✈️ Sabbatical Benefits - 4 weeks fully paid every 3 years 🏑 Home Benefits - Flexible hybrid model (3 days/week in office) Β· €500 home office budget πŸ’ͺ Body Benefits - Company gym Β· Free lunch every Monday Β· Fresh fruit Β· Barista coffee 🚌 Travel Benefits - Monthly commuting allowance πŸͺ‘ Future Benefits - Pension scheme Β· Employee discount programs 🐾 Vibe Benefits - Dog-friendly office Β· After-hours drinks at the Sendcloud Bar

Not published in this posting

The company didn't include about the role, qualifications in the source posting. The hiring team may have more details on their own site.

Sign in to open the original posting

Apply on Sendcloud

This role was discovered from a public careers page. Applications are handled by the hiring team at Sendcloud.

Attribution: sourced from Sendcloud's public Teamtailor board.

AI job toolkit

Sign in to see how well your profile matches this role, draft a cover letter, prepare for the interview, and find people who can introduce you.

Sign in to unlock