Cyber Risk Manager

Noord-Brabant · Technische Universiteit Eindhoven · OverheidZZP

Inzet
32 uur per week
Looptijd
5 maanden (exclusief verlenging)
Locatie
Noord-Brabant
Opdrachtgever
Technische Universiteit Eindhoven
Via
OverheidZZP
Sluitingsdatum
25 september 2026

Omschrijving

In het kort: Je gaat een integraal cyberrisicobeheerproces opzetten en uitvoeren, risico’s en business impact analyseren, registers, rapportages en dashboards ontwikkelen, en zo ISO27001- en NIS2-compliance en continuïteit binnen de organisatie versterken.

De TU Eindhoven is op zoek naar de tijdelijke invulling voor de rol Cyber Risk Manager.

1.2 Aanleiding en doelstelling van de opdracht De TU/e is op zoek naar een Cyber Risk Manager. Onderstaande algemene omschrijving en gevraagde competenties zijn in het Engels geschreven, omdat de voertaal Engels is.

General The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. This requires a solid cyber risk management process that is integrated in the overall risk management capability. At this point in time the (cyber) risk management capacity is very limited. The transformation required for NIS2 & ISO27001 requires more capacity & expertise in be ready before July 2028.

TU/e consists of various departments, where education and research are conducted, and a number of support services. You will be part of the GRC team within Library and Information Services (LIS) organization. This team will play a prominent role in implementation of cyber risk management, ISO27001 certification & NIS2 readiness. You report to the GRC manager.

1.3 Functieprofiel en kernvaardigheden

Brief description of the work

1. Improved Cyber Risk Assessment Methodology

  • A documented and practical risk assessment methodology aligned with ISO 27001, ISO 27005, NIS2, and the TU/e risk management framework.
  • Standard templates, scoring criteria, risk categories, impact scales, and guidance for assessing inherent and residual risk.
  • Clear criteria for risk acceptance, escalation, treatment, and management approval.

1. Completed Risk Assessments

  • Risk assessments for agreed critical services, systems, projects, suppliers, research environments, and organisational units.
  • Clear documentation of assets, threats, vulnerabilities, existing controls, risk scenarios, likelihood, impact, and residual risk.
  • Prioritised findings and recommendations that can be translated into concrete improvement actions.
  • Formal identification of risk owners and action owners.

1. Business Impact Analyses

  • Completed BIAs for critical education, research, operational, and supporting processes.
  • Identification of critical activities, supporting systems, data, suppliers, facilities, people, and other dependencies.
  • Documented impact assessments covering operational, financial, legal, regulatory, reputational, safety, and information-security consequences.
  • Defined Maximum Tolerable Periods of Disruption, recovery priorities, Recovery Time Objectives, and Recovery Point Objectives.

1. Risk Register and Treatment Plans

  • An up-to-date and structured cyber and IT risk register.
  • Documented risk treatment plans, including actions, priorities, responsible owners, deadlines, and target risk levels.
  • Formal records of accepted, transferred, avoided, or mitigated risks.
  • Monitoring of overdue actions, unresolved risks, and risks exceeding the approved risk appetite.

1. Management Reporting and Dashboards

  • Periodic management reports on the overall cyber-risk exposure of LIS and TU/e.
  • Dashboards showing risk levels, trends, critical risks, treatment progress, overdue actions, and risk acceptance decisions.
  • Clear escalation reports for risks requiring management or executive decision-making.
  • Reporting that supports ISO 27001 management reviews and NIS2 governance responsibilities.

1. Integration into the Risk PDCA Cycle

… lees de volledige omschrijving bij OverheidZZP.

Reageer op deze opdracht via OverheidZZP

Je wordt doorgestuurd naar de website van OverheidZZP. ZZPdock is geen tussenpartij.