Job matched to your search
Cybersecurity & GRC Consultant (NIS2 & ISO 27001)
Zybrstate · Amsterdam
Free · Join 5,000+ job seekers using Qarera
How well do you match this role?
Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.
Job description
Company Description
Zybrstate is a premier cybersecurity consultancy, founded in 2014, that builds end-to-end security ecosystems for organizations facing complex digital threats and regulatory demands. The firm operates across strategic leadership and GRC, security program management, security operations, IT audit, compliance, and pre-audit readiness.
At Zybrstate, we deliver institutional trust, GRC advisory, and digital resilience to mid-market and enterprise organizations. Cybersecurity is no longer just an IT operational requirement—it is a core business enabler and the ultimate metric of corporate governance. We bridge the gap between technical architecture and board-level compliance, ensuring our clients remain resilient, proactive, and permanently audit-ready.
Role Description
As a Cybersecurity & GRC Consultant (NIS2 & ISO 27001), you will lead and support engagements that help clients design, implement, and optimize security governance and compliance frameworks. In this full-time remote role, you will perform gap assessments against NIS2 and ISO 27001, develop remediation plans, and guide clients through implementation and certification readiness.
We are seeking an experienced Cybersecurity & GRC Consultant who combines deep regulatory knowledge with pragmatic execution skills. In this role, you will act as a trusted advisor to C-level executives, CISOs, and compliance officers, helping them navigate the evolving European cyber threat and regulatory landscape.
Key Responsibilities
- Regulatory Advisory & Gap Analysis: Conduct readiness assessments, risk assessments, and compliance roadmaps for clients subject to NIS2, DORA, GDPR, and ISO 27001.
- ISMS Architecture & Implementation: Design, deploy, and audit Information Security Management Systems (ISMS) tailored to client business environments.
- Risk Management & Governance: Develop business impact analyses (BIA), risk registers, third-party vendor risk management strategies, and operational resilience frameworks.
- Incident Response & Operational Resilience: Assist clients in establishing incident response plans, reporting structures (under NIS2/DORA mandates), and continuous posture monitoring frameworks.
- Executive Alignment: Translate complex legal and technical requirements into actionable, business-focused strategies for executive boards, CFOs, CIOs, and compliance directors.
- vCISO Support: Serve as a fractional/Virtual CISO for key client accounts, offering continuous guidance, policy reviews, and audit support.
Qualifications
- Core Expertise: Deep hands-on implementation experience with NIS2, ISO/IEC 27001, DORA, or GDPR.
- Professional Experience: 5–8+ years in cybersecurity, GRC, information security auditing, or risk management.
- Preferred Certifications: CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, NIS2 Lead Implementer, CRISC, or CIPP/E.
- Communication: Exceptional verbal and written communication skills in English. Dutch language proficiency is highly preferred for NL enterprise engagements.
- Comfort working independently in a remote environment, managing multiple client projects, and meeting deadlines without close supervision.
More jobs in Amsterdam
Browse related jobs
Don’t just read the job — see if you’ll get it.
Get your match score, a resume tailored to this exact role, and jobs like it — free.
Check my fit for this job