Turn this role into an interview — a resume and cover letter built around what this employer wants.
PostNL is seeking an Information Security Officer focused on Third-Party Risk Management. You will manage cyber risk across suppliers and partnerships, ensuring assessments, onboarding, and reassessments meet security requirements while enabling business goals.
You will collaborate with IT, legal, and business stakeholders, shaping risk mitigation and compliance programs within a large, regulated organization.
As Information Security Officer (Third-Party Risk Management) you are responsible for managing and strengthening PostNL's security posture across suppliers and customer-facing partnerships. You combine cybersecurity expertise with stakeholder management skills, ensuring that third-party risks are identified, assessed and mitigated in a structured and pragmatic way.
Strategic impact: Third-party risk is high on the board agenda. Your work directly contributes to resilience and compliance. Complex stakeholder landscape: You operate at the intersection of IT, business, legal and suppliers. Maturity growth: You contribute to further professionalizing TRPM within a large, regulated organization. Visibility: You interact with senior management and external strategic partners. Development: Opportunity to deepen expertise in regulatory frameworks (NIS2, DORA-like principles, supply chain security).
As an Information Security Officer (ISO) focused on Third-Party Risk Management (TPRM), you will be part of our Cyber Security Office (CSO) within the Suppliers & Customers domain. This domain is responsible for managing cyber risks related to suppliers, customers, and strategic partners. In this role, you help ensure that our external partnerships meet security requirements while supporting business continuity and operational goals. You understand that security should enable the business. You will perform third-party security risk assessments, including due diligence, onboarding, and periodic reassessments. Also you evaluate supplier compliance against ISO 27001, NIST Cyber Security Framework (CSF), and our internal security policies. You define, coordinate, and monitor mitigation plans together with business owners and suppliers. Also you support audits and evidence-gathering activities related to supplier security and compliance. You balance risk mitigation, regulatory compliance, and operational feasibility. By building strong relationships with internal and external stakeholders, you help create a secure and resilient supplier ecosystem that supports our business ambitions. You contribute to the further development and improvement of our Third-Party Risk Management framework, processes, and tooling. The Senior Information Security Officer position is typically positioned within salary scale 11. However, for candidates who can demonstrate relevant team-lead experience and capabilities, the role may be expanded to include team lead responsibilities and be evaluated at salary scale 12.
We do a background check during the application. We hereby ask you for a Certificate of Good Conduct (VOG). We will also check your references and may conduct a tailor‑made investigation. We are looking for new colleagues who want to work with us to build the PostNL of the future. We therefore return mail from recruitment agencies. As part of the recruitment process, candidates undergo an assessment designed to evaluate their competencies and skills relevant to the position.