Senior Cyber Security Third-Party Risk Manager

at Eneco
EUR 72,000-90,100 per year
SENIOR
✅ Hybrid

🕙 32-40 hours per week

Tech Stack

Compliance GDPR @ 7 Security @ 7 ServiceNow @ 4

Details

Eneco operates critical energy infrastructure and depends on a broad ecosystem of technology suppliers and service partners. As Third-Party Risk Management (TPRM) Lead, you will own and mature the end-to-end TPRM programme from within the CISO Office.

The role involves shaping the TPRM framework, increasing its organisational reach, integrating security into procurement, and making third-party cyber risk visible and manageable across the business. You will work with Procurement, Legal, Compliance, Risk, Data Privacy, IT, and other senior stakeholders.

Responsibilities

  • Own the TPRM framework end-to-end, including policies, standards, procedures, risk registers, and playbooks.
  • Lead governance forums and risk-based decision-making and risk acceptance processes.
  • Define and track KPIs, KRIs, and executive dashboards for supplier risk.
  • Drive continuous improvement across the third-party lifecycle, from onboarding through offboarding.
  • Perform and oversee security assessments of new and existing suppliers.
  • Review ISO 27001 certifications, SOC reports, penetration test results, BCDR plans, and security controls.
  • Evaluate supplier cyber maturity, provide risk ratings, and define remediation requirements.
  • Maintain risk registers, manage exceptions, and oversee remediation tracking.
  • Implement continuous monitoring for critical suppliers and manage periodic reassessments.
  • Support supplier breach response activities with the incident management team.
  • Embed mandatory security review gates into procurement.
  • Support contract reviews and security clause integration with Legal and Procurement.
  • Align TPRM practices with NIS2, DORA, ISO 27001, NIST, and GDPR requirements.
  • Prepare evidence and reporting for internal and external audits and regulatory examinations.
  • Own and optimise the TPRM/GRC platform, including automation of vendor onboarding, risk tiering, workflows, and reporting.
  • Identify opportunities to reduce manual effort and increase assessment coverage through tooling.
  • Define reporting capabilities that translate supplier risk data into actionable management insight.

Requirements

  • At least 5 years of hands-on experience in Third-Party Risk Management.
  • At least 7 years of experience in Cyber Security, IT Risk, Information Security, or GRC.
  • Proven experience leading or maturing a TPRM programme in a large enterprise.
  • Experience influencing senior stakeholders and embedding security controls into procurement and supplier governance processes.
  • Familiarity with critical infrastructure or regulated-sector environments is a strong plus.
  • Deep understanding of vendor risk assessments, risk tiering, continuous monitoring, fourth-party risk, supply chain security, and exception management.
  • Strong knowledge of NIS2, DORA, ISO 27001, NIST CSF, and GDPR.
  • Hands-on experience with at least one GRC/TPRM platform, such as ServiceNow GRC, OneTrust, Archer, ProcessUnity, or a similar platform.
  • Solid grounding in cloud security, identity and access management, incident management, and BCDR.
  • Ability to communicate risk clearly to senior stakeholders and translate complexity into decisions.
  • Analytical and data-driven approach to risk prioritisation.
  • Automation mindset and experience improving coverage through tooling and process design.
  • Ability to collaborate across Legal, Procurement, Risk, IT, and the business without formal authority.

Preferred Certifications

  • CISSP, CISM, or CRISC.
  • ISO 27001 Lead Implementer or Lead Auditor.
  • Certified Third Party Risk Professional (CTPRP).

Benefits

  • Gross annual salary between €72,000 and €90,100, including FlexBudget and 8% holiday allowance.
  • Depending on the role, a bonus or collective profit sharing.
  • Flexible FlexBudget options, including payment, purchasing additional holiday days, or saving it.
  • Personal and professional development opportunities.
  • Hybrid working: 40% at the office, 40% from home, and 20% flexibly.
  • With manager approval, work abroad in approved countries for up to 3 weeks per year, with a maximum of 2 consecutive weeks.
  • Eneco works toward climate neutrality by 2035 through its One Planet strategy.

More jobs at Eneco

Similar jobs