Ministerie van Volksgezondheid, Welzijn en Sport (VWS)
Max 115 p/u
Utrecht
36 uur p/w
ICT Informatievoorziening
19de december, 2025
26ste december, 2025
Job Description
We are seeking a specialist with extensive knowledge and experience in information security, particularly in threat management and supplier management (including chain management). You will be working under the supervision of, and in collaboration with, the CISO of the core department. Functional collaboration will take place within the VWS group (such as CIBG, RIVM, and IGJ), especially with the threat specialist of the VWS group. The core department is not an IT company, so it’s crucial to be able to connect with the business, which in this case consists of policy officers, scientific staff, and specialist implementers. The core department is often in the public and political spotlight, requiring good administrative sensitivity and high-quality work. You will work pleasantly and collegially with the CISO/PO, CIO office, and other stakeholders within the OBP. The job package is dynamic.
Responsibilities
Help map all information systems within the core department.
Inventory the ICT elements of the information systems to quickly identify threats applicable to the systems of the core department.
Establish a system/methodology to quickly analyze threats and take action when a threat is applicable.
Collaborate with the threat specialist of the VWS group.
Contribute to and participate in the development of new and improvement of existing policies, and translate these into practice.
Support departments in risk analysis, including in the context of the IB image (performing quick scans IB, BIO analyses, etc).
Perform compliance checks, partly in response to ADR and AR findings.
Support the CISO in discussions with departments and possibly present matters to the board, and write notes for this.
Work on process improvement based on evaluations, if necessary.
Knowledge, Experience, Skills, and Abilities
Demonstrable and relevant knowledge and experience in information security.
Relevant certifications such as CISSP, CISM, CISA, CRISC, C/CISO.
Demonstrable experience with supplier and chain management.
Demonstrable experience with the implementation of threat or vulnerability management.
Demonstrable experience with the execution and/or assessment of risk analyses.
Knowledge of current legislation and standards, policy and implementation practice at the national government or within the Ministry of VWS.
Preferably, knowledge of the geopolitical playing field of information security and the ability to translate this knowledge into insights regarding possible threats to the public sector.
ICT-related knowledge and experience and the ability to act as a policy advisor with administrative organization sensitivity and provide advice (including drafting administrative notes). Ability to translate technical content to non-technical audiences.
Practical hands-on mentality, solution-oriented, flexible, good communication skills, and comfortable speaking in front of groups.
Omdat het proces verloopt via een aanbesteding is het belangrijk dat je een goede kans maakt om de opdracht te winnen. Bij een match starten we het offertetraject, bij twijfel laten we dit binnen 1 werkdag weten.
De procedure verloopt via een aanbesteding. De eerste introductie doen wij daarom op papier.
Wij houden van eerlijk en transparant zaken doen.
Als je aan slag gaat via Bij Oranje hanteren we de
volgende voorwaarden:
Wij houden van eerlijk en transparant zaken doen.
Als je aan de slag gaat via Bij Oranje Detachering dan
hanteren we de volgende voorwaarden: