Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Audit
Compliance
Mentoring @ 3
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Managing Third Party Risk and Supply Chain Risk is becoming increasingly important due to rising cyber threats and growing regulatory expectations. ABN AMRO is strengthening and centralising its approach through the Supplier Contract Risk Management department within the Corporate Information Security Office. The role focuses on ensuring supplier contracts meet high standards of risk management and compliance, contributing to the bank’s digital resilience.
Responsibilities
- Advise and support business units and Procurement in selecting, contracting, and managing suppliers, ensuring Third Party Risk Management (TPRM) processes and best practices are applied consistently.
- Identify, assess, monitor, and mitigate supplier and contract risks throughout the full contract lifecycle.
- Maintain oversight of the supplier portfolio and associated risk profiles, proactively identifying risks, bottlenecks, and improvement opportunities.
- Perform and support analyses of aggregation and concentration risks, translating outcomes into clear insights for stakeholders.
- Coordinate risk governance by communicating, escalating, and following up on supplier risks with Contract Owners, Procurement, Security, Risk, and Audit.
- Ensure risk controls are effectively implemented and monitored, and that evidence is available for audits and regulatory reviews.
- Contribute to improving TPRM processes, tools, and reporting to strengthen risk management capabilities and digital resilience.
- Raise awareness of supplier risk management practices and support stakeholders.
- Coordinate the implementation of relevant regulatory changes, including DORA and Third Party Risk Management requirements.
- Depending on experience and seniority, support junior colleagues through training, mentoring, and coaching.
Working Environment
You will join the Supplier Contract Risk Management department within the Corporate Information Security Office, working with Contract Owners and stakeholders across Technology, Cyber Security, Procurement, Legal, Compliance, Finance, and Risk. The role covers higher-risk IT supplier engagements and operates at the intersection of risk, regulation, and technology, including DORA, cybersecurity, and digital resilience.
Requirements
- Two to five years of relevant experience in risk management and/or contract management.
- A clear understanding of risk as an integral part of decision-making.
- Experience in one or more specialised risk domains, such as information security, data privacy, business continuity, financial or credit risk, or Third Party Risk Management, including DORA.
- Experience in or knowledge of the banking and financial sector, including IT-related environments.
- Strong analytical capabilities and a structured, results-driven approach.
- Ability to work independently and take ownership of improvements.
- Proven stakeholder-management experience across business, procurement, and risk functions.
- Ability to translate regulatory requirements into practical processes and controls.
- Familiarity with contract-management methodologies, such as CATS CM, is preferred.
- A process-oriented approach.
- Analytical skills.
Benefits
- Gross monthly salary of €5,304–€7,577 based on a 36-hour work week, including holiday allowance and a flexible benefits budget.
- Excellent pension scheme.
- Hybrid working, with working from home possible in consultation with the team; an ergonomic home-office setup is provided.
- Five weeks of vacation per year, two mandatory days off, and the option to purchase up to four additional weeks of vacation annually.
- Five “Banking for better days” for personal development or volunteer work.
- Annual development budget of €1,000, which can accumulate up to €3,000.
- Annual public transport pass providing free public transportation throughout the Netherlands for business and private use.