Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Audit
Compliance
Mentoring @ 3
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Managing Third Party Risk and Supply Chain Risk is becoming increasingly important due to growing cyber threats and regulatory expectations. As a Supplier Contract Risk Manager IT within ABN AMRO’s Corporate Information Security Office, you will help shape the Supplier Contract Risk Management department and ensure that supplier contracts meet high standards of risk management and compliance.
The Platform & Technologies domain includes critical hybrid IT services delivered to ABN AMRO, requiring continuous monitoring of operational resilience, cybersecurity, supply chain security, and data privacy.
Responsibilities
- Advise and support business units and Procurement in selecting, contracting, and managing suppliers, ensuring Third Party Risk Management (TPRM) processes and best practices are applied.
- Identify, assess, monitor, and mitigate supplier and contract risks throughout the full contract lifecycle.
- Maintain oversight of the supplier portfolio and associated risk profiles, identifying risks, bottlenecks, and improvement opportunities.
- Perform and support analyses of aggregation and concentration risks, translating outcomes into clear stakeholder insights.
- Coordinate risk governance by communicating, escalating, and following up on supplier risks with Contract Owners, Procurement, Security, Risk, and Audit.
- Ensure risk controls are implemented and monitored effectively, with evidence available for audits and regulatory reviews.
- Improve TPRM processes, tools, and reporting to strengthen risk management capabilities and digital resilience.
- Raise awareness of supplier risk management practices.
- Coordinate the implementation of relevant regulatory changes, including DORA and Third Party Risk Management requirements.
- Depending on experience and seniority, support junior colleagues through training, mentoring, and coaching.
Working Environment
You will join the Supplier Contract Risk Management department within the Corporate Information Security Office (CISO). The department works across IT and non-IT domains and branches, collaborating with Contract Owners and stakeholders in Technology, Cyber Security, Procurement, Legal, Compliance, Finance, and Risk.
The role operates at the intersection of risk, regulation, and technology, covering higher-risk IT supplier engagements and topics such as DORA, cybersecurity, and digital resilience.
Requirements
- 2–5 years of relevant experience in risk management and/or contract management.
- Experience in one or more specialised risk domains, such as information security, data privacy, business continuity, financial or credit risk, or Third Party Risk Management, including DORA.
- Experience in or knowledge of the banking and financial sector, including IT-related environments.
- Strong analytical capabilities and a structured, results-driven approach.
- Ability to work independently and take ownership of improvements.
- Proven stakeholder-management experience across business, procurement, and risk functions.
- Ability to translate regulatory requirements into practical processes and controls.
- Familiarity with contract management methodologies is preferred, such as CATS CM.
- A process-oriented approach and analytical skills.
Benefits
- Gross monthly salary of €6,066–€8,666 based on a 36-hour work week, including holiday allowance and a flexible benefits budget.
- Excellent pension scheme.
- Hybrid working, with home working possible in consultation with the team and an ergonomic home-office setup provided.
- Five weeks of vacation, two mandatory days off, and the option to purchase up to four additional weeks annually.
- Five additional “Banking for better days” leave days.
- Annual development budget of €1,000, which can accumulate up to €3,000.
- Annual public transport pass providing free public transportation throughout the Netherlands for business and private use.