TomTom
Cyber Security Internship
TomTomNetherlands19 hours ago
Full-timeEngineering, Information Technology
Join a Security GRC team that is modernizing how risk, compliance, and assurance work is run in a large organization. In this 6‑month internship, you’ll help redesign and connect our governance content, evidence, and remediation workflows inside the Atlassian suite (Jira + Confluence). You’ll gain practical exposure to security compliance and regulatory topics (e.g., ISO 27001, TISAX, NIS2, CRA) through real, structured work—focused on controls, policies, risks, and mitigation tracking rather than highly technical “hands-on IT” activities.

What You'll Do

  • Revamp and interlink our GRC content in Confluence and Jira to create a “single way of working” (pages linked to tickets, risks, remediation actions, and dashboards).
  • Support the migration of key compliance and audit content from Word/Excel into structured Confluence pages and Jira issues (with consistent metadata and traceability).
  • Help build Jira templates for security assessments so interviews/evidence capture are structured and findings can be generated and tracked consistently.
  • Contribute to a control model that keeps control definitions in Confluence while enabling assessment/implementation tracking in Jira (including linkage to risks and remediation plans).
  • Assist with compliance and regulatory workstreams (e.g., ISO 27001 / TISAX, and growing focus on NIS2 and CRA) collect evidence, track actions, and support gap-analysis follow-ups.
  • Create and maintain Jira dashboards/views that provide visibility on compliance status, open findings, and remediation progress.
  • Improve process and documentation hygiene by reducing duplication and redundancy across repositories, and modernizing how evidence and decisions are stored and referenced.

What You'll Need

  • Strong organization skills and attention to detail; comfortable structuring information and managing follow-ups.
  • Interest in process improvement and documentation optimization (turning “messy” information into consistent, traceable workflows).
  • Strong written communication in English; able to summarize, structure, and link information clearly.
  • Working knowledge of Word and Excel, with interest in converting unstructured content into structured Jira/Confluence workflows.
  • Able to work with increasing autonomy after initial guidance; proactive in identifying and implementing improvements.
  • Any degree is welcome; we value transferable skills and an interest in governance, risk, compliance, audit, or regulatory topics (security background is a plus, not required).
  • Motivation to learn how security governance operates in a large organization (policies, controls, risks, and mitigation tracking), rather than a highly technical IT role.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Key Skills

Ranked by relevance