Security Risk Manager

WestPoint Search

Utrecht

On-site

EUR 90,000 - 140,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Car allowance
Bonus

Job summary

WestPoint Search has been retained to appoint an Information Security Risk Manager for an international organisation operating across IT and OT environments. Working directly with the CISO, this newly created role will shape how risk is identified, assessed and communicated across the business.

You will develop the risk management framework, perform BIAs, introduce quantitative methods such as FAIR, and produce executive reporting to inform risk-based investment decisions.

Qualifications

  • Significant experience in Information Security or Cyber Risk Management.
  • Experience developing or owning security risk frameworks, methodologies and risk registers.
  • Strong knowledge of ISO 27001 and risk-based security governance.
  • Experience with Business Impact Assessments and translating cyber scenarios into tangible business impact.
  • Ability to engage and influence senior business, technology and security stakeholders.
  • Experience producing executive or board-level risk reporting.
  • Professional Dutch speaking and written skills.

Responsibilities

  • Develop and mature the risk management framework and enterprise risk register.
  • Strengthen BIAs across critical services and operations.
  • Introduce quantitative cyber risk approaches, including FAIR where appropriate.
  • Translate cyber risks into operational, commercial and financial impact.
  • Develop executive and board-level risk reporting for decisions.
  • Strengthen third-party security risk management and ISO 27001/NIS2 alignment.

Skills

Security risk management
ISMS ISO 27001
Executive reporting
Stakeholder influence
Business impact assessment
Quantitative risk

Tools

GRC platforms
FAIR methodology

Job description

Shape how cyber security risk is understood, quantified and managed across a complex international organisation.

WestPoint Search has been exclusively retained to appoint an Information Security Risk Manager for an international organisation operating across both IT and Operational Technology environments.

Working directly with the CISO, this newly created position offers the opportunity to develop and mature how security risk is identified, assessed and communicated across the organisation.

The ambition is to move beyond traditional risk scoring towards a clearer understanding of business impact, financial exposure and risk-based decision making.

This isn't a role for someone looking to simply maintain an established risk framework. It's an opportunity to help build and shape one.

Why This Opportunity?

As the organisation's first dedicated Information Security Risk Manager, you'll have the autonomy to develop a more structured and business-focused approach to cyber security risk.

You’ll:

  • Develop and mature the Information Security Risk Management Framework and enterprise risk register.
  • Strengthen Business Impact Assessments across critical services and operations.
  • Introduce quantitative approaches to cyber risk, including FAIR where appropriate.
  • Translate technical cyber risks into clear operational, commercial and financial impact.
  • Develop executive and board-level reporting to support risk and investment decisions.
  • Strengthen third-party security risk management and support wider ISO 27001 and NIS2 objectives.

The objective isn’t simply better risk documentation. It’s helping business and technology leaders understand their security risks, make informed decisions and take ownership of them.

What We're Looking For

We're looking for an experienced Information Security Risk professional who combines strong risk expertise with the ability to influence across a complex organisation.

You’ll bring:

  • Significant experience within Information Security or Cyber Risk Management.
  • Experience developing or owning security risk frameworks, methodologies and risk registers.
  • Strong knowledge of ISO 27001 and risk-based security governance.
  • Experience with Business Impact Assessments and translating cyber scenarios into tangible business impact.
  • The ability to engage and influence senior business, technology and security stakeholders.
  • Experience producing executive or board-level risk reporting.
  • Professional Dutch speaking and written skills.

Experience with FAIR or other quantitative risk methodologies, third-party risk, NIS2, GRC platforms or industrial/OT environments would be advantageous.

You’ll work directly with the CISO, have the autonomy to shape this capability and play a key role in how cyber risk is understood, prioritised and managed across the organisation.

  • An attractive package is available, including a competitive salary, car allowance and bonus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Strategic Information Security Risk Manager
Strategic Information Security Risk Manager

WestPoint Search • Utrecht

On-site
EUR 90,000 - 140,000
Car allowance
Bonus
Information Security Consultant
Information Security Consultant

ITSync • Netherlands

On-site
EUR 73,000 - 92,000
Hybrid working
Home-office flexibility
Competitive salary
Information Security Manager
Information Security Manager

Barclay Simpson • Amsterdam

On-site
EUR 70,000 - 110,000
Cyber Security Operations Manager (ID: 3783)
Cyber Security Operations Manager (ID: 3783)

Stafide • Netherlands

On-site
EUR 90,000 - 120,000
Collaborative work environment
Opportunities for operational transformation
Information Security Engineer
Information Security Engineer

Doghouse Recruitment • Amsterdam

On-site
EUR 84,000 - 90,000
Pension without contributions
Travel allowance
Internet allowance
+3
IT Risk Manager
IT Risk Manager

Selby Jennings • Amsterdam

On-site
EUR 100,000 - 140,000
Information Security Officer
Information Security Officer

Doghouse Recruitment • Amsterdam

On-site
EUR 88,000 - 95,000
Up to 95000 EUR OTE per year
Non-contributory pension
Working from home allowance €2.40 per day
+2
IT Risk Program Manager
IT Risk Program Manager

Levy Professionals • Amsterdam

On-site
EUR 80,000 - 100,000
Security Risk Manager
Security Risk Manager

Trinamics • Noord-Brabant

On-site
EUR 90,000 - 130,000
Cyber Risk Officer
Cyber Risk Officer

Vanderlande • Veghel

On-site
40 vacation days including flexible budget
Flexible working hours
Health & Wellbeing budget
+3