Job detail for Manager Information Security & Compliance

E
Manager Information Security & Compliance
Ecare
Todayvia fourdayweek

Use AI to assess how you fit

Thousands of healthcare professionals rely on our software and the sensitive data processed within it every day. At the same time, we are developing new applications for practitioners and exploring how AI and data can responsibly contribute to healthcare. This is only possible if information security, compliance, and continuity are demonstrably well-managed — not just on paper, but in daily practice.

Much is already in place, but information, processes, and are still fragmented, and existing findings must be demonstrably followed up. As Manager Information Security & Compliance, you will bring oversight, cohesion, and progress. You will provide direction to a small specialist team and help Ecare continue to grow safely and responsibly.

What will you do?

You are responsible for the further and positioning of Information Security & Compliance within Ecare. You are not starting from scratch: there are policy documents, processes, audit reports, and continuity plans, some of which need to be reviewed, made more accessible, and more firmly embedded in the organization.

Within this, you have three assignments:

  1. Demonstrably manage risks, audits, and findings

You will map out risks and priorities, coordinate internal and external audits, and ensure that findings are effectively followed up and embedded.

2. Establish one integrated and functional management system

You will connect standards (such as ISO 27001 and NEN 7510), risks, processes, , and evidence into one practical system that becomes part of daily operations — rather than a separate approach for each standard.

3. Anchor Information Security & Compliance within the organization

You will ensure that ownership lies where it belongs: with the board, management, and process owners. You set frameworks, monitor, advise, and escalate where necessary, but you do not take over their .

Specifically, you will work on:

  • managing assurance and compliance issues, including ISAE 3402 and the Cyber Security Act;

  • implementing, testing, and improving Business Continuity, incident, and crisis management;

  • increasing security awareness through targeted training and communication;

  • timely involvement of Information Security & Compliance in new technology, products, AI, and data usage;

  • managing related product compliance such as MDR;

  • representing Ecare substantively to clients, auditors, and other stakeholders.

You do not need to be the deepest expert in every area yourself. However, you know what is needed, ask the right questions, and organize additional expertise when necessary.

How you work

You report directly to the Director of Finance and Risk Management and advise the board on risks, priorities, and necessary investments. You lead the Compliance Coordinator and work closely with Engineering, Product, HR, Finance, Sales, and other process owners.

This is not a role where you perform all measures yourself or only produce policy: you ensure it is clear what needs to happen, why, by whom, and when. You distinguish between main issues and side issues so that colleagues are not overloaded with rules without reducing important risks.

For this, you need authority in addition to substantive knowledge. You are accessible and collaborative, but firm — you address people when agreements are not met. You switch smoothly between a Security Engineer, Product Owner, board member, client, and auditor, and distill complex topics into clear choices.

What makes this role interesting

Ecare has grown from a quirky challenger into one of the larger players in Dutch healthcare software. We want to maintain that entrepreneurial mentality, while our position requires more cohesion and professional risk management. In this position:

  • you have direct influence on a business-critical domain and enable safe, responsible innovation with AI and data;

  • you provide direction to a small specialist team and have the space to shape processes, systems, and team composition;

  • you work on current issues regarding information security, business continuity, legislation, and MDR;

  • you represent Ecare substantively to clients, auditors, and other stakeholders, and can deploy external expertise where necessary;

  • you get space to invest in your own development and, as an experienced professional, take a next step toward broader strategic responsibility.

A monthly salary between € 5.500 and € 7.500 gross based on 40 hours per week, depending on your knowledge and experience. A 32-hour contract is negotiable.

We are not looking for someone who knows every framework by heart, but a solid professional who creates oversight and gets the organization moving.

You have:

  • extensive experience with information security and compliance within ICT, software, or SaaS;

  • demonstrable knowledge of ISO 27001 and preferably NEN 7510;

  • experience with audits, risk management, and the practical translation of standards and policy into concrete measures;

  • knowledge of business continuity and incident management;

  • sufficient substantive and personal authority to advise the board, professionals, clients, and auditors;

  • experience with or demonstrable aptitude for leading a small professional team;

  • excellent communication skills in Dutch.

Experience in healthcare ICT or with ISAE 3402, the Cyber Security Act, or MDR is welcome, but not a hard requirement. More importantly, you grasp new topics quickly and organize specialist knowledge when needed.