(Senior) Information Security Risk Manager

Care Professionals

Amsterdam, Utrecht

On-site

EUR 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Care Professionals in Amsterdam seeks an operational owner of the ICT Risk Management Framework within the second line of defence. You will oversee day-to-day ICT risk activities, monitoring, and reporting in line with DORA, ISO 27001, and PCI DSS.

You will maintain the ICT risk register, run the RCSA cycle for ICT domains, and manage key controls and KRIs. You will lead ISMS policy governance and coordinate security monitoring from a 2LoD perspective, shaping risk signals.

Qualifications

  • Experience leading ICT risk programs in a regulated environment.
  • Knowledge of ISO 27001, DORA and PCI DSS requirements.
  • Strong governance, controls monitoring and reporting skills.

Responsibilities

  • Own the ICT risk management framework and 2LoD activities.
  • Maintain risk registers, run RCSA cycles, monitor KRIs.
  • Oversee ISMS policy suite and 2LoD security monitoring.
  • Coordinate PCI DSS governance and QSA interactions.
  • Manage Eramba GRC platform and audit support.
  • Liaise with EY IT audit and annual risk reporting.

Skills

ICT risk management
2LoD governance
ISO 27001
DORA compliance
PCI DSS
GRC tooling
Stakeholder liaison
Audit coordination

Tools

Eramba GRC

Job description

In this role you will become the primary operational owner of the ICT Risk Management Framework within the second line of defence. In this role, you will be responsible for the day-to-day execution, monitoring, and reporting of ICT risk and information security activities in line with DORA, ISO 27001, and PCI DSS requirements.

Furthermore you will become responsible for:

  • Maintaining and developing the ICT risk register, executing the RCSA cycle for ICT risk domains, and monitoring key ICT controls including KRI dashboard management
  • Owning the ISMS policy suite in line with ISO 27001, DORA, and document standards, and coordinating security monitoring oversight from a 2LoD perspective
  • Supporting DORA Chapter II obligations including ICT incident classification and major incident reporting, and monitoring the external threat landscape to translate developments into 2LoD risk signals
  • Leading PCI DSS 2LoD governance as primary owner of PCI DSS v4.0 compliance oversight, coordinating PCI-3DS as a separate project stream, and acting as primary contact for QSA and internal stakeholders
  • Owning the Eramba GRC platform including data structure, user access, and module configuration, and driving its rollout to new modules and processes as the ICT risk framework matures
  • Providing second line of defence oversight of ICT third-party risk, acting as primary liaison for the annual EY IT audit, and supporting the annual Group IT risk reporting cycle.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior ICT Risk & Compliance Lead (2LoD, ISO27001, PCI DSS)
Senior ICT Risk & Compliance Lead (2LoD, ISO27001, PCI DSS)

Care Professionals • Amsterdam, Utrecht

On-site
EUR 90,000 - 130,000
Risk Officer (Security)
Risk Officer (Security)

Levy Professionals • Amstelveen

On-site
EUR 80,000 - 110,000
Information Security Manager
Information Security Manager

Stake Logic • Eindhoven

Hybrid
EUR 90,000 - 130,000
Security Risk Manager @ ASML
Security Risk Manager @ ASML

Sterksen • Veldhoven

On-site
EUR 95,000 - 135,000
Information Security Officer
Information Security Officer

Planon • Nijmegen

On-site
EUR 70,000 - 120,000
Security Governance & Risk Lead - ISO 27001, AI
Security Governance & Risk Lead - ISO 27001, AI

PwC South Africa • Amsterdam

Hybrid
Confidential
Competitive salary
Annual bonus
Permanent contract
+6
Security & Compliance Leader: ISO, GDPR, NIS2 & Risk
Security & Compliance Leader: ISO, GDPR, NIS2 & Risk

S[&]T • Delft

On-site
EUR 70,000 - 100,000
PCI Internal Security Assessor (ISA) - Caribbean
PCI Internal Security Assessor (ISA) - Caribbean

Visa Hunt • Netherlands

On-site
EUR 70,000 - 100,000
Security Governance & Risk Leader (Hybrid)
Security Governance & Risk Leader (Hybrid)

PwC Nederland • Amsterdam

Hybrid
EUR 110,000 - 140,000
Competitive salary
Permanent contract
Training programs
+5
Sr Security Governance Analyst - NIS2
Sr Security Governance Analyst - NIS2

ADM • Amsterdam

On-site
EUR 80,000 - 100,000