F2

HEAD OF INFORMATION SECURITY

Salary
€6K–€9.5K
Hiring from
Netherlands
Work type
Hybrid
Posted
Is this job info correct?
Show job description
Head of Information Security

Are you a hands-on security leader who wants to take real ownership? At F2F.com, we're looking for a Head of Information Security who sets the direction, rolls up their sleeves and helps us build a platform creators can trust.

This role is open to residents of the Netherlands only.

About The Role

We are looking for a proactive, hands on Head of Information Security who takes real ownership of security at F2F.com. You set the direction, but you also roll up your sleeves: you review code with our engineers, step in when something goes wrong and keep things practical rather than bureaucratic.

In a growing company like ours, security only works when everyone understands why it matters. You work across the whole company, not just with the development team: with our support and safety teams on escalations, with leadership on risk and with every colleague on awareness. From our engineers to our office manager, you make sure everyone knows what good security looks like in their daily work. In the near future, you will also lead our journey towards ISO 27001 certification.

What you will do

Strategy and governance

  • Develop, implement and maintain practical information security policies aligned with our business goals, without unnecessary bureaucracy.
  • Assess security risks, maintain the risk register and advise leadership on mitigation strategies.
  • Oversee security evaluations of third party suppliers and keep track of data flows to external vendors.
  • Prepare and guide the ISO 27001 certification process, building an ISMS that fits the size and pace of our organisation.

Hands on security engineering

  • Perform regular code reviews to identify, document and remediate vulnerabilities (such as the OWASP Top 10 and business logic flaws).
  • Partner with software engineers to design secure services, API integrations and database interactions.
  • Integrate SAST, DAST and dependency scanning into our CI/CD pipelines.
  • Design and implement robust Identity and Access Management (IAM) for internal and customer facing systems.
  • Act as our go to expert on cryptography, token authentication, secure session handling, and cooperate with legal and compliance on matters such as legally required security measures, privacy and data protection and the secure use of AI within the organisation.

Incident response and escalations

  • Lead incident response: preparation, detection, containment and thorough reviews afterwards.
  • Take the lead in escalations, working closely with our support team and safety team, and prevent escalations where possible by managing risks early.
  • Work with our partner on device management and endpoint security, including MDM rollout and EDR/XDR monitoring.
  • Set up threat intelligence and dashboards to report monthly on security posture, incidents and threat vectors.

Security awareness across the company

  • Take the whole organisation along in security awareness, translating technical risks into clear and practical guidance that every colleague understands.
  • Build a security culture where people know what to do and feel comfortable raising concerns.

What you bring

  • Strong interpersonal skills and organisational sensitivity: you can explain security to a developer, a support agent and a founder, each in their own language.
  • Proven ability to drive organisational change and implement security measures that people actually adopt.
  • Leadership in escalations, combined with a preventive mindset.
  • Proactive and self directed: you see what needs to be done and act on it without waiting to be asked.
  • 5+ years of practical experience in software development or security engineering, with a focus on Python, Node and API security.
  • Comfortable in CI/CD: SAST/DAST/SCA integration, IaC review and cloud (AWS).
  • Deep technical understanding of application security, secure code design and API security.
  • Experience running or building an ISMS (ISO 27001 or NIST CSF), ideally in a small or medium sized organisation. Experience guiding an ISO 27001 certification is a strong plus.
  • Nice to have: experience with MDM, EDR/XDR endpoint monitoring and zero trust solutions.
  • Fluency in English and Dutch is a plus.

What we Offer

  • Competitive salary and strong secondary benefits
  • 24 vacation days
  • Fully paid pension plan, no employee contribution
  • Free lunch at the office
  • NS Business Card
  • Flexible working hours and hybrid working
  • €1,000 personal development budget per year
  • Gym subscription via ClassPass or a sports venue of your choice
  • Lease-a-bike scheme
  • Salary between €6000 - €9500

Interested?

Sound like your next move? We'd love to hear from you, portfolio or side project included if you have one. Send your CV and motivation letter to Recruitment@f2f.com. Apply now and come help us build a platform creators can trust.

‍

apply now

Similar jobs

Apply on LinkedIn