
📍 Eindhoven (Hybrid - 2 days/week onsite) | Full-time
“At Sendcloud, we build Europe’s leading shipping automation platform - helping over 25,000 e-commerce businesses grow. I help make sure we can scale fast and safely: keeping our ISO 27001 security program strong, turning security risks into clear decisions, and working with Engineering, Platform, IT, Legal/Privacy and Support to protect our customers, our people, and our business. Security here is a business enabler - not a checkbox.”
We’re looking for an Information Security Officer who can combine pragmatic governance with hands-on program leadership. You’ll own our information security program and help ensure our ISO 27001 ISMS stays healthy and audit-ready - while driving real security improvements across the company.
This is a role for someone who enjoys building clarity, influencing stakeholders, and making sure important work actually gets done.
You’ll be involved in:
Owning our ISO 27001 ISMS (and keeping it always-on) → internal audits, evidence, management reviews, corrective actions, and external audit readiness
Running security risk management that leads to decisions → maintaining a living risk register, driving mitigations with owners and timelines, and enabling explicit risk acceptance when needed
Driving security governance that teams can actually use → practical policies and standards for access, data handling, vendor risk, and incident response
Leading security incident governance → classification, escalation, post-incident learning loops, and preventing repeats (in partnership with Platform/Engineering/Support)
Managing third-party and vendor security risk → risk tiering, due diligence, and working with Legal on security requirements and ongoing assurance
Enabling safe use of AI and agentic workflows → clear guardrails for AI tooling and automation so we can adopt AI safely without slowing teams down (including visibility on shadow IT/AI in collaboration with IT/Platform)
Being at the table for architecture decisions with security impact → you’ll participate in relevant architecture forums as a required security reviewer (not the decision maker), especially around identity/auth migrations, service-to-service patterns, and high blast-radius platform changes - to help teams catch security implications early and keep delivery moving
Reporting and stakeholder alignment → clear updates to leadership on security posture, top risks, incidents, audit outcomes, and progress
💩 No bullshit: We value honesty, transparency, and openness. Mistakes are for learning.
🎯 Grow & Win: Keep learning and improving - from each other, from challenges, and from feedback.
🎠 Have fun: Be yourself! We work hard together and enjoy the ride as a team.
All CVs must be submitted in English.
Sendcloud is one of the fastest growing tech companies in Europe and we are building a world-class team! We are well on our way to become Europe's number 1 shipping platform for e-commerce. See a job that gets you excited? Leave your resume and motivation. 😁 Please keep in mind that as part of our employment policy, all new employees are subject to pre-employment screening. Your personal information will be verified by the Ministry of Justice and Security. You can read more information about the screening process on VOG (Certificate of Conduct) here .
Jobb.ai is an independent skill benchmarking platform. Applications are submitted on the employer's official website.