Skip to sign up

Job matched to your search

Cybersecurity & GRC Consultant (NIS2 & ISO 27001)

Zybrstate · Amsterdam

Amsterdam · RemoteFull-TimePosted Aug 11, 2026

Free · Join 5,000+ job seekers using Qarera

How well do you match this role?

Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.

↑ tap the skills you have
Loading sign-in…
Free · no credit card · 30 seconds

Job description

Company Description

Zybrstate is a premier cybersecurity consultancy, founded in 2014, that builds end-to-end security ecosystems for organizations facing complex digital threats and regulatory demands. The firm operates across strategic leadership and GRC, security program management, security operations, IT audit, compliance, and pre-audit readiness.

At Zybrstate, we deliver institutional trust, GRC advisory, and digital resilience to mid-market and enterprise organizations. Cybersecurity is no longer just an IT operational requirement—it is a core business enabler and the ultimate metric of corporate governance. We bridge the gap between technical architecture and board-level compliance, ensuring our clients remain resilient, proactive, and permanently audit-ready.

Role Description

As a Cybersecurity & GRC Consultant (NIS2 & ISO 27001), you will lead and support engagements that help clients design, implement, and optimize security governance and compliance frameworks. In this full-time remote role, you will perform gap assessments against NIS2 and ISO 27001, develop remediation plans, and guide clients through implementation and certification readiness.

We are seeking an experienced Cybersecurity & GRC Consultant who combines deep regulatory knowledge with pragmatic execution skills. In this role, you will act as a trusted advisor to C-level executives, CISOs, and compliance officers, helping them navigate the evolving European cyber threat and regulatory landscape.

Key Responsibilities

  • Regulatory Advisory & Gap Analysis: Conduct readiness assessments, risk assessments, and compliance roadmaps for clients subject to NIS2, DORA, GDPR, and ISO 27001.
  • ISMS Architecture & Implementation: Design, deploy, and audit Information Security Management Systems (ISMS) tailored to client business environments.
  • Risk Management & Governance: Develop business impact analyses (BIA), risk registers, third-party vendor risk management strategies, and operational resilience frameworks.
  • Incident Response & Operational Resilience: Assist clients in establishing incident response plans, reporting structures (under NIS2/DORA mandates), and continuous posture monitoring frameworks.
  • Executive Alignment: Translate complex legal and technical requirements into actionable, business-focused strategies for executive boards, CFOs, CIOs, and compliance directors.
  • vCISO Support: Serve as a fractional/Virtual CISO for key client accounts, offering continuous guidance, policy reviews, and audit support.

Qualifications

  • Core Expertise: Deep hands-on implementation experience with NIS2, ISO/IEC 27001, DORA, or GDPR.
  • Professional Experience: 5–8+ years in cybersecurity, GRC, information security auditing, or risk management.
  • Preferred Certifications: CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor, NIS2 Lead Implementer, CRISC, or CIPP/E.
  • Communication: Exceptional verbal and written communication skills in English. Dutch language proficiency is highly preferred for NL enterprise engagements.
  • Comfort working independently in a remote environment, managing multiple client projects, and meeting deadlines without close supervision.

Don’t just read the job — see if you’ll get it.

Get your match score, a resume tailored to this exact role, and jobs like it — free.

Check my fit for this job
Loading sign-in…
Apply →