Vendor Security Specialist

IQ Staffing

Amsterdam

On-site

EUR 60,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A security consulting firm is seeking a Supply Chain Security Specialist to enhance external vendor security. In this role, you will improve Supply Chain Security services through user stories, risk assessments, and collaboration with various stakeholders. You will govern IT vendor relationships and execute risk assessments, ensuring effective management of information security risks throughout vendor lifecycles. Ideal candidates possess a relevant degree, experience in Supply Chain Security, and can translate technical risks into business context.

Qualifications

  • Experience with Supply Chain Security / Third Party Security Risk Management projects.
  • Proven experience in executing information security risk assessments.
  • Strong ability to translate technical risks into business risks.

Responsibilities

  • Govern IT vendor relationships regarding security performance.
  • Execute Vendor Security Risk Assessments and follow-up actions.
  • Manage information security risks throughout third-party relationships.
  • Review third-party assurance reports and drive continuous improvement.
  • Act as an internal advisor on security-related topics.

Skills

Supply Chain Security
Third Party Security Risk Management
Risk Assessment
Service-oriented
Technical Translation

Education

HBO or University degree

Tools

ServiceNow TPRM module

Job description

Our client is looking for a Supply Chain Security Specialist to strengthen the security posture of their external vendors. In this role, the successful candidate will work in a DevOps & Agile environment and contribute to the continuous improvement of Supply Chain Security services through user stories, risk assessments, and close collaboration with internal and external stakeholders.

The role sits within the Supply Chain Security (SCS) team, part of the Corporate Information Security Office (CISO) and the Cyber Defense grid. The team is responsible for providing continuous visibility into the security posture of third-party vendors and ensuring that information security risks are managed effectively throughout the vendor lifecycle.

What does a typical working day look like?

The role offers a varied working day, which typically includes:

  • Working on user stories to improve Supply Chain Security services in line with DevOps & Agile principles
  • Executing Vendor Security Risk Assessments, focusing on the risks that matter and translating them into clear business impact
  • Following up on identified risks and supporting stakeholders in addressing security challenges
  • Investigating security-related incidents involving third parties when they occur
  • Engaging with a wide range of stakeholders, including IT teams, business colleagues, legal, compliance, procurement, and software suppliers
  • Reviewing the applicability and quality of assurance reports issued by third parties
  • Proactively identifying and suggesting improvements to processes, reporting quality, and service delivery
  • Staying up to date with emerging cybersecurity trends, threats, and technological developments, and sharing this knowledge within the team
Key responsibilities
  • Govern and manage IT vendor relationships with regard to security performance and contractual obligations
  • Execute Vendor Security Risk Assessments and drive follow-up actions
  • Ensure information security risks are identified and managed throughout all stages of third-party relationships
  • Review and assess third-party assurance reports
  • Drive continuous improvement in the quality of third-party reporting and services
  • Manage the IT security aspects of contracts in collaboration with 2nd line functions such as legal, compliance, and procurement
  • Act as a trusted internal advisor on security-related topics, taking initiative and escalating when necessary
  • Signal and implement improvements in the team’s way of working, contributing to service excellence
  • Contribute to results aligned with SMART objectives and expected DORA impact
Candidate profile
  • HBO or University degree
  • Experience with Supply Chain Security / Third Party Security Risk Management (TPSRM) projects and deliverables
  • Proven experience in executing information security risk assessments
  • Knowledge of one or more of the following areas:
  • Security processes
  • Technology architectures
  • Network security
  • Application security
  • Vulnerability management
  • Hands-on, self-organised, and delivery-oriented with strong execution power
  • Strong ability to translate technical risks into business risks and vice versa
  • Service-oriented professional who enjoys working in an internal consultancy role
  • Experience with the ServiceNow TPRM module is a strong plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Supply Chain Security Third Party Risk Consultant
Supply Chain Security Third Party Risk Consultant

A2Z-CM N.V. • Amstelveen

On-site
EUR 60,000 - 80,000
Vendor Security Risk Consultant - Supply Chain Security
Vendor Security Risk Consultant - Supply Chain Security

A2Z-CM N.V. • Amstelveen

On-site
EUR 60,000 - 80,000
Vendor Security & Standards Manager
Vendor Security & Standards Manager

Jobgether • Netherlands

On-site
EUR 120,000 - 180,000
Competitive compensation
Career growth
International exposure
+2
Third-Party Security Risk Lead
Third-Party Security Risk Lead

IQ Staffing • Amsterdam

On-site
EUR 60,000 - 80,000
Junior Information Security Expert
Junior Information Security Expert

Experis • Netherlands

On-site
EUR 45,000 - 65,000
25 holiday days + 0.5 bonus day for health
Travel allowance 21 cents/km
E-learning portal with various courses
+1
Information Security Expert
Information Security Expert

ABN AMRO Bank N.V. • Amstelveen

Hybrid
EUR 70,000 - 90,000
Attractive salary with flexible benefit budget
Excellent pension scheme
Room for personal development
+2
Information Security Engineer
Information Security Engineer

Marconi Associates • Amsterdam

Hybrid
EUR 65,000 - 100,000
Vendor Security Risk Specialist
Vendor Security Risk Specialist

Experis • Netherlands

On-site
EUR 45,000 - 65,000
25 holiday days + 0.5 bonus day for health
Travel allowance 21 cents/km
E-learning portal with various courses
+1
Senior Product Security & Risk Consulting Manager
Senior Product Security & Risk Consulting Manager

Accenture • Amsterdam

On-site
Security Manager - EU, Netherlands or Slovakia based
Security Manager - EU, Netherlands or Slovakia based

Cello Square by Samsung SDS Europe • Delft

On-site
EUR 90,000 - 120,000