You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Thijs VerwaalTV

Thijs Verwaal

interim CISO, CISSP-ISSMP CCSP GSTRT

€ 1.200/dag
Utrecht, NL
15+ jaar

Gemiddelde responstijd: 1 uur

Over Thijs

Industrial Engineer with 18+ years of IT experience and 10+ years in senior cybersecurity
leadership roles across financial services, SaaS, Web3, and global enterprise environments.
Proven track record in defining & executing security strategies aligned with business
objectives, building certified ISO27001 & NIST-aligned ISMS programs, achieving regulatory
compliance (DORA, GDPR) and leading high-impact security transformation programs.
Strong board-level communicator with an entrepreneurial mindset and hands-on expertise
across GRC, cloud & application security, DevSecOps, secure AI governance & adoption.
  • Nederlands

    Tweetalig / moedertaal

  • Engels

    Tweetalig / moedertaal

  • Duits

    Beperkte professionele capaciteit

Kan op locatie werken
Utrecht (tot 50km)

Werkervaring

  • Scaler Global
    Chief Security Officer (CISO)
    januari 2024 - Vandaag (2 jaren en 5 maanden)
    Amsterdam, Netherlands
    • • Designed and implemented an ISO 27001–compliant ISMS from greenfield, including continuous & automated control monitoring, enabling scalable governance for a growing SaaS organisation. Led and completed audits for ISO27001, ISAE3000 & SOC2 certifications, managing external auditors and internal stakeholders end-to-end.
    • • Designed and led the AI transformation program, including roadmap, milestones, and operating model. Started with Implementing an AI governance, including AI risk assessment framework, AI technology register, and Acceptable AI Use policy.
    • • Partnered with Engineering to enable secure AI experimentation and defined an AI adoption lifecycle for scaling successful use cases.
    • • Defined and executed a security vision, multi-year strategy and roadmap, aligned with business growth objectives.
    • • Directed security program management across IAM, vulnerability management, device hardening, security awareness, secure office IT.
    • • Executed threat-led penetration testing of the SaaS platform to identify vulnerabilities and ensured remediation in a timely manner.
    • • Completed customer security & privacy risk assessments as part of client due diligence, supporting sales & contract closure.
    Information Security Management IT Project & Program Management ISO 27001 SOC2 AI Transformation
  • LYNX Beleggen
    Head of Information Security (CISO)
    januari 2024 - mei 2025 (1 jaar en 4 maanden)
    Amsterdam, Netherlands
    • • Led the Information Security function as 2nd Line of Defence, overseeing policy, control design and independent risk assessments.
    • • Defined an AI governance including AI risk assessment framework, introduced Responsible AI Usage training to educate personnel.
    • • Developed and executed an Information Security Strategy and Security Project Portfolio to remediate identified gaps.
    • • Led the DORA Remediation program, coordinating several Security Projects to close operational resilience & control deficiencies.
    • • Performed a Control Maturity Assessments against DNB Good Practice for Information Security, to measure and report control maturity from Second Line of Defence, ensuring audit-ready DORA compliance ahead of regulatory deadlines.
    • • Supported Privacy Office with setting up similar maturity approach to privacy controls using the NOREA Privacy Control Framework.
    • • Organised bi-weekly IT risk management sessions with the CTO & CFRO, delivered monthly board-level security reporting, and participated in the Business Risk & Compliance Committee.
    DORA Information Security Management IT Project & Program Management AI Risk Management Enterprise Risk Management
  • Gala Web3 Entertainment
    Director of Security (CISO)
    januari 2022 - december 2023 (1 jaar en 11 maanden)
    • • Defined a Web3 cybersecurity strategy with Board approval, focused on Product Application Security risks.
    • • Built & led a fully remote Global Security team, focused on Secure Product Development Lifecycle & Continuous Vulnerability Management.
    • • Launched a Web3 Bug Bounty Program with $1 million bounty pool, increasing responsible disclosure & external security testing coverage.
    • • Achieved CertiK Security Score of 95.18%, positioning GALA as world's most secure altcoin after Bitcoin & Ethereum.
    Web3 Blockchain Product Security Bug Bounty Greenfield

Aanbevelingen

Wees de eerste die Thijs aanbeveelt

Help deze freelancer om te schitteren door te vertellen hoe het is om met hem of haar te werken.

Deze freelancerprofielen matchen ook met zoekopdracht.

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Opleidingen

  • MGT514: Security Strategic Planning, Policy, and Leadership
    SANS Institute
    2023
    GSTRT certification | GIAC
  • How to Manage Remote Teams
    GitLab
    2023
    How to Manage Remote Teams

Diploma's

  • GSTRT - Security Strategic Planning, Policy, and Leadership
    GIAC
    2024
    Strategische Planning Policy Security Leadership Security Strategy
  • CBSP - Certified Blockchain Security Professional
    Blockchain Training Alliance
    2023
    Blockchain

Vaardigheden

Categorieën