€7.984 — €9.125 / maand
Nog 10 dagen

Dit ga je doen

De TU/e is op zoek naar een Cyber Risk Manager. Onderstaande algemene omschrijving en gevraagde
competenties zijn in het Engels geschreven, omdat de voertaal Engels is.

General
The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically
committed to achieving ISO27001 compliance maturity in the coming years. This requires a solid cyber risk
management process that is integrated in the overall risk management capability. At this point in time the
(cyber) risk management capacity is very limited. The transformation required for NIS2 & ISO27001 requires
more capacity & expertise in be ready before July 2028.

TU/e consists of various departments, where education and research are conducted, and a number of
support services. You will be part of the GRC team within Library and Information Services (LIS) organization.
This team will play a prominent role in implementation of cyber risk management, ISO27001 certification &
NIS2 readiness. You report to the GRC manager.

Brief description of the work

1. Improved Cyber Risk Assessment Methodology and the TU/e risk management framework. inherent and residual risk.
2. Completed Risk Assessments and organisational units. impact, and residual risk. • Formal identification of risk owners and action owners.

3. Business Impact Analyses • Identification of critical activities, supporting systems, data, suppliers, facilities, people, and other
dependencies. safety, and information-security consequences. Recovery Point Objectives.

4. Risk Register and Treatment Plans • Documented risk treatment plans, including actions, priorities, responsible owners, deadlines, and
target risk levels. • Monitoring of overdue actions, unresolved risks, and risks exceeding the approved risk appetite.

5. Management Reporting and Dashboards • Dashboards showing risk levels, trends, critical risks, treatment progress, overdue actions, and risk
acceptance decisions. • Reporting that supports ISO 27001 management reviews and NIS2 governance responsibilities.

6. Integration into the Risk PDCA Cycle review, and improvement. threats, projects, or supplier changes. • Recommendations for improving the maturity and consistency of risk management across TU/e.

7. Business Continuity and Resilience Requirements • Prioritised recommendations for business continuity, disaster recovery, crisis management, backup,
redundancy, and cyber resilience. • Input for continuity plans, disaster-recovery plans, crisis exercises, and resilience testing.

8. Compliance and Audit Evidence monitored, and reviewed. • Audit-ready documentation supporting internal audits, external certification, regulatory supervision,
and management accountability.

9. Knowledge Transfer and Stakeholder Enablement researchers, and technical teams. • Transfer of knowledge to the internal Risk Manager and GRC team.

Key End Products • An approved cyber-risk assessment methodology. • A prioritised portfolio of completed risk assessments and BIAs. • Approved risk treatment and risk acceptance records. • A documented risk PDCA process. • An improvement roadmap for remaining ISO 27001 and NIS2 risk-management gaps.
Core Competencies for a Cyber Risk Manager
For the Cyber Risk Manager role at TU/e, the following competencies are particularly important. They align
with the requested role, which focuses on the risk management PDCA cycle, stakeholder collaboration, risk
treatment, reporting, and translating technical risks into impacts on research, education, and business
operations.
1. Cyber Risk Assessment • Experience assessing likelihood, impact, inherent risk, and residual risk using a consistent
methodology. clear ownership. 2. Business Impact Analysis • Experience assessing the operational, financial, legal, reputational, safety, and information-security
impact of disruption. Recovery Time Objectives and Recovery Point Objectives. requirements.
3. Knowledge of ISO 27001 and NIS2 • Understanding of NIS2 requirements relating to risk management, incident handling, business
continuity, supply-chain security, governance, and management accountability. • Experience supporting auditability, evidence collection, risk reporting, and continuous improvement.
4. Analytical and Structured Working • Strong analytical skills and attention to the quality and consistency of risk and BIA data. • Experience with risk registers, dashboards, reporting, and GRC tooling.

5. Stakeholder Management and Facilitation • Ability to engage effectively with service owners, researchers, architects, engineers, project
managers, and management. • Strong communication skills and the ability to explain cyber risks in clear business language.
6. Pragmatic Implementation • Focus on proportionality, avoiding unnecessary complexity and administrative burden. management. 7. TU/e-Specific Organisational Awareness • Understanding of the specific needs of scientific research, education, laboratories, research
infrastructure, and operational technology. • Ability to balance security, compliance, resilience, usability, and research objectives.
Let op:
1. Gezien de aard van onderhavige opdracht is het niet mogelijk om hiervoor als zzp’er zelfstandig in te
schrijven. Indien een Opdrachtnemer ervoor kiest om een ZZP’er bij de TU/e te plaatsen, omdat dit in
zijn of haar optiek mogelijk is, komen alle verplichtingen, ook die krachtens de belasting-,
zorgverzekerings- en socialeverzekeringswetgeving met betrekking tot Personeel van Opdrachtnemer,
ten laste van Opdrachtnemer. Opdrachtnemer vrijwaart Opdrachtgever tegen elke aansprakelijkheid
die daarmee verband houdt waaronder mede begrepen aanspraken van het Personeel van
Opdrachtnemer gebaseerd op het beweerdelijk bestaan van een arbeidsovereenkomst met
Opdrachtgever, alsmede aanspraken van derden (zoals de Belastingdienst) in dit verband. Zie ook
artikel 13 van de Overeenkomst.
2. De Inschrijver dient -door middel van het overleggen van een uittreksel uit het Handelsregister- aan te
tonen dat hij personeel uit mag lenen en voldoet aan de voorwaarden vanuit de Wet Allocatie
Arbeidskrachten door Intermediairs (Waadi).

Dit ben jij

  • A documented and practical risk assessment methodology aligned with ISO
    27001, ISO 27005, NIS2, and the TU/e risk management framework
  • Standard templates, scoring criteria, risk categories, impact scales, and
    guidance for assessing inherent and residual risk
  • Clear criteria for risk acceptance, escalation, treatment, and management
    approval
  • Risk assessments for agreed critical services, systems, projects,
    suppliers, research environments, and organisational units
  • Clear documentation of assets, threats, vulnerabilities, existing
    controls, risk scenarios, likelihood, impact, and residual risk
  • Prioritised findings and recommendations that can be translated into
    concrete improvement actions
  • Formal identification of risk owners and action owners
  • Completed BIAs for critical education, research, operational, and
    supporting processes
  • Identification of critical activities, supporting systems, data,
    suppliers, facilities, people, and other dependencies
  • Documented impact assessments covering operational, financial, legal,
    regulatory, reputational, safety, and information-security consequences
  • Defined Maximum Tolerable Periods of Disruption, recovery priorities,
    Recovery Time Objectives, and Recovery Point Objectives
  • An up-to-date and structured cyber and IT risk register
  • Documented risk treatment plans, including actions, priorities,
    responsible owners, deadlines, and target risk levels
  • Formal records of accepted, transferred, avoided, or mitigated risks
  • Monitoring of overdue actions, unresolved risks, and risks exceeding the
    approved risk appetite
  • Periodic management reports on the overall cyber-risk exposure of LIS and
    TU/e
  • Dashboards showing risk levels, trends, critical risks, treatment
    progress, overdue actions, and risk acceptance decisions
  • Clear escalation reports for risks requiring management or executive
    decision-making
  • Reporting that supports ISO 27001 management reviews and NIS2 governance
    responsibilities
  • A functioning risk management cycle covering identification, assessment,
    treatment, monitoring, review, and improvement
  • Defined review frequencies and triggers for reassessment, such as major
    changes, incidents, new threats, projects, or supplier changes
  • Evidence that risk assessments and BIAs are periodically reviewed and
    kept current
  • Recommendations for improving the maturity and consistency of risk
    management across TU/e
  • Recovery and continuity requirements based on BIA outcomes
  • Prioritised recommendations for business continuity, disaster recovery,
    crisis management, backup, redundancy, and cyber resilience
  • Identification of gaps between required and actual recovery capabilities
  • Input for continuity plans, disaster-recovery plans, crisis exercises,
    and resilience testing
  • Documented evidence demonstrating that cyber risks are systematically
    identified, assessed, treated, monitored, and reviewed
  • Traceability between risks, ISO 27001 controls, NIS2 obligations,
    policies, and improvement actions
  • Audit-ready documentation supporting internal audits, external
    certification, regulatory supervision, and management accountability
  • Support for the preparation and follow-up of ISO 27001 and NIS2
    assessments
  • Workshops, guidance, and practical training for service owners, risk
    owners, project managers, researchers, and technical teams
  • Clear instructions explaining roles, responsibilities, assessment
    methods, and expected evidence
  • Transfer of knowledge to the internal Risk Manager and GRC team
  • Increased stakeholder capability to independently identify, assess, and
    manage cyber risks
  • At minimum, the assignment should result in
  • An approved cyber-risk assessment methodology
  • Standard risk assessment and BIA templates
  • A prioritised portfolio of completed risk assessments and BIAs
  • An updated risk register with assigned ownership
  • Approved risk treatment and risk acceptance records
  • A management dashboard and periodic reporting cycle
  • A documented risk PDCA process
  • Integration of risk management into relevant project and change
    processes
  • An improvement roadmap for remaining ISO 27001 and NIS2 risk-management
    gaps
  • Ability to identify assets, threats, vulnerabilities, dependencies, and
    existing controls
  • Experience assessing likelihood, impact, inherent risk, and residual risk
    using a consistent methodology
  • Ability to translate identified risks into practical mitigation measures,
    formal risk acceptance, and clear ownership
  • Understanding of risk appetite, risk tolerance, and escalation criteria
  • Ability to identify critical education, research, IT, and business
    processes
  • Experience assessing the operational, financial, legal, reputational,
    safety, and information-security impact of disruption
  • Ability to determine maximum tolerable downtime, recovery priorities,
    critical dependencies, Recovery Time Objectives and Recovery Point
    Objectives
  • Ability to translate BIA outcomes into business continuity, disaster
    recovery, and resilience requirements
  • Strong working knowledge of ISO 27001, ISO 27005, and
    information-security risk management
  • Understanding of NIS2 requirements relating to risk management, incident
    handling, business continuity, supply-chain security, governance, and
    management accountability
  • Ability to link identified risks to applicable ISO 27001 controls and
    NIS2 obligations
  • Experience supporting auditability, evidence collection, risk reporting,
    and continuous improvement
  • Ability to bring structure to complex and decentralised IT environments
  • Strong analytical skills and attention to the quality and consistency of
    risk and BIA data
  • Ability to identify cross-organisational dependencies, concentration
    risks, and systemic risks
  • Experience with risk registers, dashboards, reporting, and GRC tooling
  • Strong workshop and interview skills for facilitating risk assessments
    and BIAs
  • Ability to engage effectively with service owners, researchers,
    architects, engineers, project managers, and management
  • Ability to challenge stakeholders constructively while maintaining trust
    and cooperation
  • Strong communication skills and the ability to explain cyber risks in
    clear business language
  • Ability to translate frameworks and regulatory requirements into workable
    processes
  • Focus on proportionality, avoiding unnecessary complexity and
    administrative burden
  • Ability to embed risk management into projects, changes, procurement,
    architecture, and service management
  • Strong ownership and follow-up skills to ensure that risk treatment
    actions are completed
  • Ability to work in a highly autonomous and decentralised university
    environment
  • Understanding of the specific needs of scientific research, education,
    laboratories, research infrastructure, and operational technology
  • Sensitivity to academic freedom, innovation, data sovereignty, and the
    need for flexible IT solutions
  • Ability to balance security, compliance, resilience, usability, and
    research objectives

Het proces

Dit verhaal gaat over jou

01

De zoektocht – waar begin je?

Elke maand ontvangen we honderden vacatures. Die publiceren we op onze website, maar we blijven niet achteroverleunen. Ons team gaat actief op zoek naar de juiste match. Misschien vind jij ons, of wij jou – hoe dan ook: we maken snel contact.

02

De kennismaking – een goed gesprek, geen kruisverhoor

Jij ziet een interessante opdracht of wij denken dat er een goed bij je past. We bellen om je beter te leren kennen en de opdracht door te nemen. Wat vind jij belangrijk? Wat zijn je ambities? We houden het persoonlijk én to the point. Zo verkennen we samen wat de juiste match voor je is en wat daarmee ook het beste voor de klant is.

Gemeente Noordoostpolder vacatures

03

Afspraken maken – helder en zonder kleine lettertjes

Past de opdracht bij jouw expertise? Top. We bespreken de voorwaarden, je gewenste salaris en hoe de opdracht eruitziet. Omdat het om overheidsvacatures gaat, kunnen de eisen complex zijn en het proces tijdrovend – maar daar helpen wij je soepel doorheen.

04

Introductie – wij regelen de papierwinkel

Je levert een bijgewerkt cv, motivatie en eventuele referenties aan. Wij stellen de introductie samen, volledig afgestemd op de wensen van de opdrachtgever. Alles wat we bespreken komt daarin terug – eerlijk, transparant en geen verrassingen.

05

Even geduld – maar we houden je op de hoogte

Overheidsprocessen kunnen soms traag zijn. Wij geven je vooraf een realistische tijdlijn en houden je tussendoor op de hoogte. Geen radiostilte, maar duidelijke updates.

06

Op gesprek – goed voorbereid op pad

Word je uitgenodigd? Mooi! We plannen samen het gesprek en bereiden het grondig voor. We geven je tips & tricks en duiken in de inhoud van de opdracht. Het doel: jouw kansen maximaliseren.

07

Go of No-Go – samen evalueren

Na het gesprek evalueren we hoe het ging. Wil jij door en ziet de opdrachtgever het ook zitten? Dan koppelen we je aan één van onze uitzendpartners. Zij regelen het uitzendcontract. Is het toch geen match? Dan halen we feedback op en zoeken we verder.

08

Aan de slag – alles geregeld, jij kunt starten

Bij een succesvolle bemiddeling leggen we alle afspraken vast in een overeenkomst. Je uitzendpartner regelt het contract, de administratie en zorgt ervoor dat je netjes en op tijd betaald wordt. Jij hoeft alleen maar te focussen op je werk (en een taart sturen mag altijd 😉).

09

Service – ook ná de start zijn we er voor je

Zolang je aan de opdracht werkt, blijven wij je aanspreekpunt. Ook kan je regelmatig uitnodigingen van ons verwachten voor kleine events en borrels bij ons op kantoor. Heb je vragen over je opdracht, verlenging of indexaties? Eén belletje en we helpen je verder. Is de opdracht afgerond? Dan zoeken we met plezier naar een volgende uitdaging voor je.

Iets voor jou?

Laat het ons weten!

Reageer op deze vacature via TenMonks en ons recruitment team neemt contact met je op om de match te verkennen.

Iets voor jou?

Reageer dan vandaag nog!

Feedback