Chief Information Security Officer at Backbase (2020-09 – Present)
Lead enterprise cybersecurity strategy, governance, risk management and security operations across Backbase's fintech platform.
- Partner with executive leadership to align security priorities with business growth and risk appetite
- Develop and maintain governance for secure agentic software development
- Drive secure innovation on the Backbase SaaS platform through security-by-design and a defensible security architecture
- Build and mature incident response, threat detection and resilience capabilities
- Drive security roadmap and improvements
- Accountable for maintaining a mature security posture, SOC 2 program and DORA readiness
- Develop and lead a high-performing security organisation with knowledge sharing, succession planning and operational excellence
Director of Information Security at Backbase (2019-09 – 2020-08)
- Responsible for the security of the Backbase software and guidance for customer deployments
- Lead the security discipline for development and professional services teams
- Responsible for cloud security and the security of the Backbase managed platform
- Build the SOC for the Backbase SaaS offering
- Develop incident handling processes and capabilities
Security Architect at Backbase (2017-03 – 2019-08)
- Define security architecture for the Backbase platform
- Implement a secure SDLC and control effectiveness
- Build and lead the application security team
- Drive application security requirements in the Backbase software
- Responsible for Information Security education, training and awareness for development teams
- Consult clients on secure deployment of Backbase solutions
Information Security Officer at CSC (2015-11 – 2017-02)
- Create and manage Information Security policies and procedures
- Manage Information Security education, training and awareness
- Manage ISO27001 and NEN7510 certification of the Leiden Data Centre
- Manage security testing of solutions deployed in the Netherlands
- Lead Incident handling and response, including incident response policies, plans and procedures
- Manage Data Protection and Data Breach Notification procedures
Security Architect at CSC (2011-08 – 2015-11)
- Security assessment, including internal penetration testing and compliance with NEN7510 regulations
- Lead security practice for the SaaS offering
- Set and drive NFRs and platform policies for solutions developed in the Netherlands
- Define and implement security controls in SDLC; lead security improvements to the SDLC
- Responsible for Information Security education, training and awareness for development teams
- Define security architecture and requirements for private cloud deployments
Senior/Principal Technical Consultant at CSC (2003-08 – 2011-08)
- Design technical infrastructure and consult clients on network, server and storage configurations
- Lead consultant for virtualised environments and architecture lead for the SaaS offering
- Design and implement disaster recovery processes
- Troubleshoot performance and stability issues | Lead support for mission critical systems
System Engineer/Technical Consultant at CSC (1999-02 – 2003-08)
- Server administrator for Windows and Linux systems
- DBA for SQL Server and Oracle databases, including maintenance, performance tuning and recovery
Technical Consultant at Yokogawa Denki (2000 – 2000)
- One-year placement, providing training on infrastructure and database topics