Senior Cyber Security Third-Party Risk Manager
at Eneco
EUR 72,000-90,100 per year
🕙 32-40 hours per week
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Compliance
GDPR @ 7
Security @ 7
ServiceNow @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Eneco operates critical energy infrastructure and depends on a broad ecosystem of technology suppliers and service partners. As Third-Party Risk Management (TPRM) Lead, you will own and mature the end-to-end TPRM programme from within the CISO Office.
The role involves shaping the TPRM framework, increasing its organisational reach, integrating security into procurement, and making third-party cyber risk visible and manageable across the business. You will work with Procurement, Legal, Compliance, Risk, Data Privacy, IT, and other senior stakeholders.
Responsibilities
- Own the TPRM framework end-to-end, including policies, standards, procedures, risk registers, and playbooks.
- Lead governance forums and risk-based decision-making and risk acceptance processes.
- Define and track KPIs, KRIs, and executive dashboards for supplier risk.
- Drive continuous improvement across the third-party lifecycle, from onboarding through offboarding.
- Perform and oversee security assessments of new and existing suppliers.
- Review ISO 27001 certifications, SOC reports, penetration test results, BCDR plans, and security controls.
- Evaluate supplier cyber maturity, provide risk ratings, and define remediation requirements.
- Maintain risk registers, manage exceptions, and oversee remediation tracking.
- Implement continuous monitoring for critical suppliers and manage periodic reassessments.
- Support supplier breach response activities with the incident management team.
- Embed mandatory security review gates into procurement.
- Support contract reviews and security clause integration with Legal and Procurement.
- Align TPRM practices with NIS2, DORA, ISO 27001, NIST, and GDPR requirements.
- Prepare evidence and reporting for internal and external audits and regulatory examinations.
- Own and optimise the TPRM/GRC platform, including automation of vendor onboarding, risk tiering, workflows, and reporting.
- Identify opportunities to reduce manual effort and increase assessment coverage through tooling.
- Define reporting capabilities that translate supplier risk data into actionable management insight.
Requirements
- At least 5 years of hands-on experience in Third-Party Risk Management.
- At least 7 years of experience in Cyber Security, IT Risk, Information Security, or GRC.
- Proven experience leading or maturing a TPRM programme in a large enterprise.
- Experience influencing senior stakeholders and embedding security controls into procurement and supplier governance processes.
- Familiarity with critical infrastructure or regulated-sector environments is a strong plus.
- Deep understanding of vendor risk assessments, risk tiering, continuous monitoring, fourth-party risk, supply chain security, and exception management.
- Strong knowledge of NIS2, DORA, ISO 27001, NIST CSF, and GDPR.
- Hands-on experience with at least one GRC/TPRM platform, such as ServiceNow GRC, OneTrust, Archer, ProcessUnity, or a similar platform.
- Solid grounding in cloud security, identity and access management, incident management, and BCDR.
- Ability to communicate risk clearly to senior stakeholders and translate complexity into decisions.
- Analytical and data-driven approach to risk prioritisation.
- Automation mindset and experience improving coverage through tooling and process design.
- Ability to collaborate across Legal, Procurement, Risk, IT, and the business without formal authority.
Preferred Certifications
- CISSP, CISM, or CRISC.
- ISO 27001 Lead Implementer or Lead Auditor.
- Certified Third Party Risk Professional (CTPRP).
Benefits
- Gross annual salary between €72,000 and €90,100, including FlexBudget and 8% holiday allowance.
- Depending on the role, a bonus or collective profit sharing.
- Flexible FlexBudget options, including payment, purchasing additional holiday days, or saving it.
- Personal and professional development opportunities.
- Hybrid working: 40% at the office, 40% from home, and 20% flexibly.
- With manager approval, work abroad in approved countries for up to 3 weeks per year, with a maximum of 2 consecutive weeks.
- Eneco works toward climate neutrality by 2035 through its One Planet strategy.
More jobs at Eneco
Analyst Strategic Portfolio Management
Eneco · Rotterdam, Netherlands
EUR 71,000-100,000 per year
SAP Asset Lifecycle Management Functional Consultants
Eneco · Rotterdam, Netherlands
EUR 60,000-81,000 per year
B2B Data Analytics Internship
Eneco · Rotterdam, Netherlands
EUR 8,100 per year
IoT & DevOps Engineer (TypeScript & Azure)
Eneco · Rotterdam, Netherlands
EUR 79,000-108,000 per year
B2B Integration Engineer (TypeScript & Azure)
Eneco · Rotterdam, Netherlands
EUR 79,000-108,000 per year
Similar jobs
IT Network Security & Compliance Risk Manager
ABN AMRO · Amstelveen, Netherlands
EUR 72,800-104,000 per year
Senior Data Architect
Eneco · Rotterdam, Netherlands
EUR 93,000-150,000 per year
Staff Site Reliability Operations
Nvidia · Hillsboro, United States
USD 144,000-230,000 per year
Product Manager · NordPass
Nord Security · Poland
PLN 18,000-21,300 per year
Product Manager, NordPass
Nord Security · Kaunas, Lithuania, Vilnius, Lithuania
EUR 54,000-78,000 per year
Security Specialist Solutions Architect
ClickHouse · United States
USD 275,000-300,000 per year
Security Technology Deployment Specialist
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 180,000-230,000 per year
Staff Workday Integration Engineer, Tech Foundations
Airbnb · United States
USD 180,000-225,000 per year