Skip to content

Open nowPosted 8 hours agoWe saw it 0 min after it went up

Head of Information Security

ACT Group20 open roles

Where
Amsterdam, Noord-Holland, Netherlands
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowHead of Information SecurityACT Group · Amsterdam, Noord-Holland, Netherlands
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on ACT Group's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. ACT Group postings stay open a median of 4 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 8 hours ago

ACT Group median: 4 days open

The posting

Your Role in Our Story:

ACT is strengthening its data, technology and AI capabilities as we build a more integrated digital platform alongside our core environmental commodities trading and market-making business. This transformation is commercially driven, enabling us to scale, deepen client relationships and support increasingly complex and digital markets.

As Senior Information Security Officer, you will own ACT’s enterprise information security strategy and governance at Group level, spanning our core operations, emerging digital businesses and client-facing technology platforms. You will define the security risk appetite, lead our response to an evolving threat landscape, and ensure security and resilience are embedded by design as our technology landscape develops.

Working across business and technology leadership, you will translate commercial ambition into a pragmatic and scalable security posture that protects our systems and data while maintaining the trust of clients, counterparties and regulators. In essence, your role involves:

Strategy & Governance

  • Own the Group-wide information security strategy and roadmap across ACT’s core market-making business and digital and client-facing platforms, aligned with business goals and industry frameworks such as ISO 27001 and NIST CSF. Define and maintain ACT’s cyber risk appetite.
  • Establish and lead security governance, including policies, standards and control frameworks, with clear accountability across the Group. Report on security posture and material incidents to executive leadership and, where relevant, the Board.

Client Platforms & Secure-by-Design

  • Embed security-by-design into new products and client platforms, partnering with Data, Architecture and Commercial teams to ensure emerging digital capabilities are secure from inception, while acting as a credible security voice to clients and counterparties.
  • Oversee application, product and SaaS security, embedding security throughout the software development lifecycle for internal and client-facing platforms, and assessing third-party services handling ACT and counterparty data.

Risk & Resilience

  • Lead enterprise security risk management, including risk assessments, vulnerability management and third-party/supply-chain risk, driving timely mitigation across core and digital environments.
  • Direct incident preparedness and response, coordinating detection, containment, eradication and recovery, while continuously strengthening incident and crisis-management plans.

Infrastructure & Emerging Technology

  • Secure ACT’s cloud and infrastructure through Zero-Trust-aligned controls, including identity and access management, segmentation and encryption, across a hybrid and multi-platform environment.
  • Govern emerging technology and AI security, extending security oversight to AI and data platforms, including model and data-exposure risks and AI-enabled threats, as ACT expands its use of AI.

Compliance & Leadership

  • Ensure regulatory and compliance alignment, including GDPR, DORA and relevant sector obligations, advising the business on required adaptations and coordinating audits and certifications.
  • Lead the security function and strengthen security culture across the Group, developing the team, raising security awareness, and acting as ACT’s primary authority and trusted advisor on cyber security to executives and business leaders, working alongside existing teams and capabilities.

Your Expertise:

To be successful in this role, we are looking for candidates with the following qualifications and attributes:

  • A Bachelor’s degree in Information Security, Computer Science or a related field. A relevant Master’s degree is an advantage.
  • 10–15 years of progressive experience in information security and cybersecurity, including at least 5 years in a senior security role, with ownership of enterprise security strategy, governance and risk management.
  • Broad security leadership experience across incident response, cloud and infrastructure security, product/application security and regulatory compliance. Experience securing client-facing platforms or digital products is highly valuable.
  • Experience within trading, financial services, commodities or another data-intensive and regulated environment is highly advantageous.
  • Strong knowledge of security frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework and CIS Controls, with practical experience implementing them.
  • Good understanding of data protection, regulatory and compliance requirements, including GDPR, DORA and standards such as SOC 2.
  • Professional certifications such as CISSP, CISM or CISA, or equivalent, are highly desirable.
  • Strong analytical, communication and stakeholder-management skills, with the ability to translate complex security risks into clear business implications and advise technical teams, executives, business stakeholders and clients.

If you meet these criteria and are ready to contribute your expertise to a dynamic and challenging environment, we encourage you to apply.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against ACT Group's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on ACT Group's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    ACT Group's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.