Cyber Risk Manager

OverheidZZP

Eindhoven

On-site

EUR 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Optie tot verlenging

Job summary

Technische Universiteit Eindhoven zoekt een Cyber Risk Manager om een integraal cyberrisicobeheerproces op te zetten en uit te voeren, met focus op ISO27001- en NIS2-compliance en continuïteit binnen de organisatie.

Je maakt risk assessments, BIAs en risico-registers, ontwikkelt templates, dashboards en rapportages, en coördineert risk-ownership en deadlines met diverse stakeholders binnen onderwijs en onderzoek.

Qualifications

  • Ervaring met het opzetten en uitvoeren van cyber risk assessments.
  • Kennis van ISO 27001, NIS2 en risicomanagement framework.
  • Inzicht in Business Impact Analysis (BIA) en continuïteitsplanning.
  • Ervaring met risk registers en rapportage.
  • Sterke communicatieve vaardigheden en stakeholder engagement.

Responsibilities

  • Ontwikkelen en beheren van een geïntegreerd cyber risk management proces.
  • Uitvoeren van risico-, bedrijfsimpact- en continuïteitsanalyses.
  • Ontwerpen van registers, rapportages en dashboards.
  • Rapporteren aan GRC-manager en afdelingen.
  • Toezicht houden op risk owners en remediation acties.

Skills

Cyber risk assessment
ISO27001
NIS2
GRC tooling
Stakeholder management
Risk management
BIAs

Tools

Risk registers

Job description

Over de functie

In het kort: Je gaat een integraal cyberrisicobeheerproces opzetten en uitvoeren, risico’s en business impact analyseren, registers, rapportages en dashboards ontwikkelen, en zo ISO27001- en NIS2-compliance en continuïteit binnen de organisatie versterken.

De TU Eindhoven is op zoek naar de tijdelijke invulling voor de rol Cyber Risk Manager.

1.2 Aanleiding en doelstelling van de opdracht

De TU/e is op zoek naar een Cyber Risk Manager. Onderstaande algemene omschrijving en gevraagde competenties zijn in het Engels geschreven, omdat de voertaal Engels is.

General

The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. This requires a solid cyber risk management process that is integrated in the overall risk management capability. At this point in time the (cyber) risk management capacity is very limited. The transformation required for NIS2 & ISO27001 requires more capacity & expertise in be ready before July 2028.

TU/e consists of various departments, where education and research are conducted, and a number of support services. You will be part of the GRC team within Library and Information Services (LIS) organization. This team will play a prominent role in implementation of cyber risk management, ISO27001 certification & NIS2 readiness. You report to the GRC manager.

1.3 Functieprofiel en kernvaardigheden

Brief description of the work

  • Improved Cyber Risk Assessment Methodology
  • A documented and practical risk assessment methodology aligned with ISO 27001, ISO 27005, NIS2, and the TU/e risk management framework.
  • Standard templates, scoring criteria, risk categories, impact scales, and guidance for assessing inherent and residual risk.
  • Clear criteria for risk acceptance, escalation, treatment, and management approval.
  • Completed Risk Assessments
  • Risk assessments for agreed critical services, systems, projects, suppliers, research environments, and organisational units.
  • Clear documentation of assets, threats, vulnerabilities, existing controls, risk scenarios, likelihood, impact, and residual risk.
  • Prioritised findings and recommendations that can be translated into concrete improvement actions.
  • Formal identification of risk owners and action owners.
  • Business Impact Analyses
  • Completed BIAs for critical education, research, operational, and supporting processes.
  • Identification of critical activities, supporting systems, data, suppliers, facilities, people, and other dependencies.
  • Documented impact assessments covering operational, financial, legal, regulatory, reputational, safety, and information-security consequences.
  • Defined Maximum Tolerable Periods of Disruption, recovery priorities, Recovery Time Objectives, and Recovery Point Objectives.
  • Risk Register and Treatment Plans
  • An up-to-date and structured cyber and IT risk register.
  • Documented risk treatment plans, including actions, priorities, responsible owners, deadlines, and target risk levels.
  • Formal records of accepted, transferred, avoided, or mitigated risks.
  • Monitoring of overdue actions, unresolved risks, and risks exceeding the approved risk appetite.
  • Management Reporting and Dashboards
  • Periodic management reports on the overall cyber-risk exposure of LIS and TU/e.
  • Dashboards showing risk levels, trends, critical risks, treatment progress, overdue actions, and risk acceptance decisions.
  • Clear escalation reports for risks requiring management or executive decision-making.
  • Reporting that supports ISO 27001 management reviews and NIS2 governance responsibilities.
  • Integration into the Risk PDCA Cycle
  • A functioning risk management cycle covering identification, assessment, treatment, monitoring, review, and improvement.
  • Defined review frequencies and triggers for reassessment, such as major changes, incidents, new threats, projects, or supplier changes.
  • Evidence that risk assessments and BIAs are periodically reviewed and kept current.
  • Recommendations for improving the maturity and consistency of risk management across TU/e.
  • Business Continuity and Resilience Requirements
  • Recovery and continuity requirements based on BIA outcomes.
  • Prioritised recommendations for business continuity, disaster recovery, crisis management, backup, redundancy, and cyber resilience.
  • Identification of gaps between required and actual recovery capabilities.
  • Input for continuity plans, disaster-recovery plans, crisis exercises, and resilience testing.
  • Compliance and Audit Evidence
  • Documented evidence demonstrating that cyber risks are systematically identified, assessed, treated, monitored, and reviewed.
  • Traceability between risks, ISO 27001 controls, NIS2 obligations, policies, and improvement actions.
  • Audit-ready documentation supporting internal audits, external certification, regulatory supervision, and management accountability.
  • Support for the preparation and follow-up of ISO 27001 and NIS2 assessments.
  • Knowledge Transfer and Stakeholder Enablement
  • Workshops, guidance, and practical training for service owners, risk owners, project managers, researchers, and technical teams.
  • Clear instructions explaining roles, responsibilities, assessment methods, and expected evidence.
  • Transfer of knowledge to the internal Risk Manager and GRC team.
  • Increased stakeholder capability to independently identify, assess, and manage cyber risks.
Key End Products
  • At minimum, the assignment should result in:
  • An approved cyber-risk assessment methodology.
  • Standard risk assessment and BIA templates.
  • A prioritised portfolio of completed risk assessments and BIAs.
  • An updated risk register with assigned ownership.
  • Approved risk treatment and risk acceptance records.
  • A management dashboard and periodic reporting cycle.
  • A documented risk PDCA process.
  • Integration of risk management into relevant project and change processes.
  • An improvement roadmap for remaining ISO 27001 and NIS2 risk-management gaps.
Core Competencies for a Cyber Risk Manager
  • Cyber Risk Assessment
  • Ability to identify assets, threats, vulnerabilities, dependencies, and existing controls.
  • Experience assessing likelihood, impact, inherent risk, and residual risk using a consistent methodology.
  • Ability to translate identified risks into practical mitigation measures, formal risk acceptance, and clear ownership.
  • Understanding of risk appetite, risk tolerance, and escalation criteria.
  • Business Impact Analysis
  • Ability to identify critical education, research, IT, and business processes.
  • Experience assessing the operational, financial, legal, reputational, safety, and information-security impact of disruption.
  • Ability to determine maximum tolerable downtime, recovery priorities, critical dependencies, Recovery Time Objectives and Recovery Point Objectives.
  • Ability to translate BIA outcomes into business continuity, disaster recovery, and resilience requirements.
  • Knowledge of ISO 27001 and NIS2
  • Strong working knowledge of ISO 27001, ISO 27005, and information-security risk management.
  • Understanding of NIS2 requirements relating to risk management, incident handling, business continuity, supply-chain security, governance, and management accountability.
  • Ability to link identified risks to applicable ISO 27001 controls and NIS2 obligations.
  • Experience supporting auditability, evidence collection, risk reporting, and continuous improvement.
  • Analytical and Structured Working
  • Ability to bring structure to complex and decentralised IT environments.
  • Strong analytical skills and attention to the quality and consistency of risk and BIA data.
  • Ability to identify cross-organisational dependencies, concentration risks, and systemic risks.
  • Experience with risk registers, dashboards, reporting, and GRC tooling.
  • Stakeholder Management and Facilitation
  • Strong workshop and interview skills for facilitating risk assessments and BIAs.
  • Ability to engage effectively with service owners, researchers, architects, engineers, project managers, and management.
  • Ability to challenge stakeholders constructively while maintaining trust and cooperation.
  • Strong communication skills and the ability to explain cyber risks in clear business language.
  • Pragmatic Implementation
  • Ability to translate frameworks and regulatory requirements into workable processes.
  • Focus on proportionality, avoiding unnecessary complexity and administrative burden.
  • Ability to embed risk management into projects, changes, procurement, architecture, and service management.
  • Strong ownership and follow-up skills to ensure that risk treatment actions are completed.
  • TU/e-Specific Organisational Awareness
  • Ability to work in a highly autonomous and decentralised university environment.
  • Understanding of the specific needs of scientific research, education, laboratories, research infrastructure, and operational technology.
  • Sensitivity to academic freedom, innovation, data sovereignty, and the need for flexible IT solutions.
  • Ability to balance security, compliance, resilience, usability, and research objectives.
Eisen
  • Dienstverband: Detachering
  • De aangeboden kandidaat voldoet minimaal aan de kwalificaties en competenties zoals opgegeven in het functieprofiel (1.3). De Inschrijver toont dit aan door het uploaden van een actueel CV van de kandidaat.
Wensen
  • Geen wensen
Overige informatie

Optie tot verlenging: Ja, telkens 3 maanden tot maximale looptijd 2 jaar, daarna eventueel langer met wederzijds goedvinden

Gespreksdatum: 06/10/2026 tussen 14:00 en 17:00, tijdstip n.t.b.

Dienstverband: Detachering

Over de opdrachtgever

De Technische Universiteit Eindhoven is een vooraanstaande technische universiteit gevestigd in Eindhoven. De universiteit richt zich op onderzoek en onderwijs op het gebied van technologie, engineering en innovatie. Met ongeveer 11.000 studenten en 3.500 medewerkers is de universiteit een belangrijke speler in de wereld van technologie en wetenschap. De Technische Universiteit Eindhoven biedt diverse bachelor- en masteropleidingen aan op gebieden zoals werktuigbouwkunde, elektrotechniek, informatica en biomedische technologie. Daarnaast is de universiteit actief betrokken bij onderzoek en innovatieprojecten in samenwerking met bedrijven en andere kennisinstellingen. De focus ligt op het ontwikkelen van nieuwe technologieën en oplossingen die bijdragen aan maatschappelijke uitdagingen en economische groei.

De sluitingsdatum van deze opdracht is de harde deadline van onze opdrachtgever.

  • Om je krachtig voor te kunnen dragen hebben wij minimaal één werkdag nodig om samen met jou alle bescheiden in orde te maken.
  • Naast een actueel en op de opdracht gericht CV zullen wij altijd vragen om een bondige persoonlijke motivatiebrief (inclusief een toelichting per functie-eis en -wens) en een indicatief uurtarief/maandloon.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Workplace Engineer Subject Matter Expert
Workplace Engineer Subject Matter Expert

OverheidZZP • Eindhoven

On-site
EUR 70,000 - 95,000
Project Manager Secure Modern Workplace - Digital Safety
Project Manager Secure Modern Workplace - Digital Safety

OverheidZZP • Eindhoven

On-site
EUR 90,000 - 120,000
Cyber Risk Manager
Cyber Risk Manager

ResultaatGroep B.V. • Eindhoven

Hybrid
EUR 103,000 - 172,000
Workplace Engineer Subject Matter Expert 32u/w
Workplace Engineer Subject Matter Expert 32u/w

DC Engineers B.V. • Eindhoven

On-site
EUR 70,000 - 90,000
Programmamanager Integriteit & Sociale Veiligheid
Programmamanager Integriteit & Sociale Veiligheid

Eindhoven University of Technology • Eindhoven

On-site
EUR 75,000 - 92,000
ABP pensioenregeling
OpenUp mentale ondersteuning
Sportcentrum op campus tegen voordelig
+1
Studentendecaan/Student counselor (0,8 fte)
Studentendecaan/Student counselor (0,8 fte)

Services, Education and Student Affairs • Eindhoven

On-site
EUR 41,000 - 64,000
ABP pensioenregeling
OpenUp mentale ondersteuning
Reiskostenvergoeding woon-werkverkeer
+1
Project secretaresse
Project secretaresse

OverheidZZP • Eindhoven

On-site
EUR 30,000 - 40,000
Cyber Risk Manager
Cyber Risk Manager

Bright-Professionals • Eindhoven

On-site
EUR 70,000 - 105,000
Sr. Projectmanager Vastgoed
Sr. Projectmanager Vastgoed

Eindhoven University of Technology • Eindhoven

On-site
EUR 71,000 - 91,000
ABP pensioenregeling
Reiskostenvergoeding
Sportcentrum TU/e toegankelijk
+1
Studentendecaan/Student counselor (0,8 fte)
Studentendecaan/Student counselor (0,8 fte)

Karlstad University • Eindhoven

On-site
EUR 41,000 - 64,000
Reiskostenvergoeding
Mentoring & coaching
OpenUp mentale ondersteuning
+1