Our client is looking for a Supply Chain Security Specialist to strengthen the security posture of their external vendors. In this role, the successful candidate will work in a DevOps & Agile environment and contribute to the continuous improvement of Supply Chain Security services through user stories, risk assessments, and close collaboration with internal and external stakeholders.
The role sits within the Supply Chain Security (SCS) team, part of the Corporate Information Security Office (CISO) and the Cyber Defense grid. The team is responsible for providing continuous visibility into the security posture of third-party vendors and ensuring that information security risks are managed effectively throughout the vendor lifecycle.
What does a typical working day look like?
The role offers a varied working day, which typically includes:
- Working on user stories to improve Supply Chain Security services in line with DevOps & Agile principles
- Executing Vendor Security Risk Assessments, focusing on the risks that matter and translating them into clear business impact
- Following up on identified risks and supporting stakeholders in addressing security challenges
- Investigating security-related incidents involving third parties when they occur
- Engaging with a wide range of stakeholders, including IT teams, business colleagues, legal, compliance, procurement, and software suppliers
- Reviewing the applicability and quality of assurance reports issued by third parties
- Proactively identifying and suggesting improvements to processes, reporting quality, and service delivery
- Staying up to date with emerging cybersecurity trends, threats, and technological developments, and sharing this knowledge within the team
Key responsibilities
- Govern and manage IT vendor relationships with regard to security performance and contractual obligations
- Execute Vendor Security Risk Assessments and drive follow-up actions
- Ensure information security risks are identified and managed throughout all stages of third-party relationships
- Review and assess third-party assurance reports
- Drive continuous improvement in the quality of third-party reporting and services
- Manage the IT security aspects of contracts in collaboration with 2nd line functions such as legal, compliance, and procurement
- Act as a trusted internal advisor on security-related topics, taking initiative and escalating when necessary
- Signal and implement improvements in the team’s way of working, contributing to service excellence
- Contribute to results aligned with SMART objectives and expected DORA impact
Candidate profile
- HBO or University degree
- Experience with Supply Chain Security / Third Party Security Risk Management (TPSRM) projects and deliverables
- Proven experience in executing information security risk assessments
- Knowledge of one or more of the following areas:
- Security processes
- Technology architectures
- Network security
- Application security
- Vulnerability management
- Hands-on, self-organised, and delivery-oriented with strong execution power
- Strong ability to translate technical risks into business risks and vice versa
- Service-oriented professional who enjoys working in an internal consultancy role
- Experience with the ServiceNow TPRM module is a strong plus