SIGNAL STABLE · UTRECHT, NL

Michiel
van Es

Head of Product — Cybersecurity Enablement Tooling, bol

Twenty-plus years turning sprawling, fast-moving systems into ones people can trust — first as the engineer keeping the lights on, now as the product leader setting the strategy.

20+ years in the field
6 companies, one throughline
2 products led at bol
Portrait of Michiel van Es CH. 01 — LIVE

01 / ABOUT

Security that doesn't get in the way.

I'm a security professional with two decades of experience engineering, managing, and facilitating the people behind big, dynamic tech companies. I've spent my career on the side of the systems most people never think about — until something goes wrong.

These days that means setting direction as Head of Product for Cybersecurity Enablement Tooling at bol: deciding where the roadmap goes, what gets built, and how my teams are set up to do their best work. The job has changed shape a few times — sysadmin, security engineer, compliance officer, team lead, product manager — but the instinct underneath has stayed the same: find the control that protects the business without slowing it down.

Build for scale

Solutions that hold up inside big, dynamic, fast-moving tech companies — not just in a slide deck.

Lead the people

Engineering and product work is a people problem first. Set teams up to succeed, then get out of the way.

Move the needle

As Head of Product, the question is never "is it secure" alone — it's whether it actually shifts outcomes.

02 / CAREER TRACE

A log of the last 24 years.

Read top to bottom, like a commit history — each role building the context for the next.

2025 — Present 1 yr 6 mo
CURRENT

Head of Product — Cybersecurity Enablement Tooling

bol · Utrecht, NL · Hybrid

Own the roadmap and strategy for the Cybersecurity Enablement Tooling domain, covering two products: Secure Login and Security Insights.

2022 — 2024 2 yr 1 mo

Group Product Manager

bol · Utrecht, NL · Hybrid

Responsible for the user experience of Security Insights. Set strategy and vision alongside product teams and managers, kept it aligned to company strategy, and made sure stakeholder input actually fed back into the roadmap.

2022 — 2024 2 yr 11 mo

Team Lead & Product Manager

bol

Led the team and acted as Product Owner for the IT security team building the tooling that shows colleagues how they're tracking against their security KPIs. Advised on IT compliance strategy as an internal expert.

2019 — 2021 3 yr

Team Lead, Product Owner & IT Compliance Officer

bol · The Randstad, NL

Led a team of 5 engineers focused on SecOps — scalable security monitoring, vulnerability scanning, dashboarding, and reviewing what scrum teams were shipping. Also led a mixed team of developers and IT auditors to build solutions for the IT compliance programme. As Compliance Officer, kept the company aligned to AVG/GDPR, financial audit, and PCI-DSS requirements — pragmatically, using an in-house control framework.

2015 — 2021 6 yr 9 mo

IT Compliance Officer & Project Lead, GDPR and Cloud

bol.com · Papendorp

Focused on GDPR, SOX/ICFR, PCI-DSS and ACM8 — and built an automation tool that let IT managers, control owners, risk managers, and engineers stay in control of compliance and risk with minimal friction. Led the GDPR and Cloud projects: audit readiness on one side, secure cloud provisioning on the other. Supported Ahold/Delhaize audits at bol.com.

  • Pragmatic IT compliance & controls automation
  • Disaster recovery
  • Patch management
  • 3rd-party library scanning in the build pipeline
  • GDPR PII inventory
2014 — 2015 5 mo

IT Compliance Officer

Booking.com · The Randstad, NL

Kept Booking.com compliant with SOX and PCI-DSS, working directly with engineers, developers, team leads, and auditors to find the balance between compliance and velocity — without losing the culture along the way.

2013 — 2014 1 yr 4 mo

IT Security Lead

bol.com · The Randstad, NL

Owned security for bol.com's environment end to end: BIA/risk analysis across all sites and applications, a security baseline for the new data center, a full PCI-DSS v3.0 SAQ, automated vulnerability scanning, and a monitoring & alerting platform — plus the reporting and stakeholder buy-in needed to actually get it all implemented.

2012 — 2013 1 yr 2 mo

Security Engineer

Sanoma Media · Amsterdam, NL

Secured the online environment behind 172 Sanoma Digital Netherlands websites and 500+ servers — vulnerability scanning against OWASP Top 10 and OSSTM, external audit coordination, ISO 27001/27002 policy work, and the ongoing dialogue with legal on Dutch and EU data law (WBP).

2010 — 2012 1 yr 10 mo

Security Engineer

TomTom · The Randstad, NL

Split between tier-2 system administration across 700+ servers in up to 3 data centers, and security engineering: vulnerability scanning, WAF administration, hardening procedures, AAA setup, and firewall rules — plus a standing seat in CAB meetings to keep releases stable.

2002 — 2010 8 yr 8 mo

Senior System Administrator / Engineer & Security Officer

Info.nl

Built the security foundation from the ground up using ISO 27002 as the target framework. Stood up 802.1X network access control, vulnerability scanning with OpenVAS/Nikto/Acunetix, two-factor authentication and external pentests for a major Dutch financial institution, and patch management across 500+ servers via Spacewalk.

2000 — 2002 2 yr 1 mo

System Administrator

Interswitch BV

Where it started: supporting 100 users at one of the Netherlands' biggest telcos on Novell Netware, NT and Windows 2000, alongside a Lucent ISDN phone central. First lessons in keeping a system stable for people who just need it to work.

03 / FOCUS

Where the dial's set right now.

Product strategy

Roadmap, vision, and prioritization for security tooling that has to serve hundreds of engineering teams — not just look good in a quarterly review.

Cybersecurity enablement

Secure Login and Security Insights: tools that make the secure path the easy path, instead of a separate step people skip.

People leadership

Years of team-lead and product-owner experience translate directly into how I build and back the teams reporting into the domain today.

Compliance, pragmatically

GDPR, SOX/ICFR, PCI-DSS, ACM8 — frameworks I've lived inside for over a decade, applied with the lightest touch that still holds up to audit.

04 / OFFLINE

Same instinct, lower stakes.

Outside of work, I tune a different kind of signal. I tweak and mod vacuum-tube guitar amps — biasing, tube-matching, chasing the tone — and I design my own overdrive pedal, the Esmeister.

It's the same underlying habit that's run through every role on the timeline above: take a complex system, understand exactly what's happening inside it, and tune it until it's stable, predictable, and sounds right. Just without an auditor waiting on the other end.

Tube biasing Amp servicing Pedal design The Esmeister