Supply Chain Security Risk Manager
- Plaats
- Amstelveen, Noord-Holland
- Werkplek
- Hybride
- Opdrachtgever
- niet vermeld
Via wie reageer je
A2Z-CM
- Wie betaalt de fee
- niet vastgesteld
- Tarief bij deze opdracht
- geen tarief
- Beoordelingen
- nog geen
Omschrijving
Introduction 36 hours per week Start: ASAP 1-year assignment with the possibility of extension Hybrid way of work ZZP is allowed Relocation is not allowed Function What does your working day look like? – The team works according to the DevOps & Agile methodology. – You are working on improving the Supply Chain Security services, based on user stories. – Occasionally there are incidents that occur that you are going to look into. – For your work you often engage with various stakeholders such as other IT departments, business colleagues and software suppliers. Key responsibilities in your work contain: – Govern and manage IT vendor relationships in terms of performance regarding the security aspects of the underlying contractual obligations; – Execute Vendor Security Risk Assessments and perform follow up actions.
Focus on the risks that matter, translate them into the business context and help your stakeholders to address security challenges; – Ensure that information security risks are identified and managed effectively throughout all the stages of the relationship with external vendors; – Review the applicability and the quality level of assurance reports issued by the third parties; – Ensure continuous improvements are achieved both in the quality of reporting and service provided by the third party; – Manage the IT security related part of a contract with the third party provider. Work together with 2nd line functions such as legal, compliance, procurement and other internal parties on contractual changes; – Help solving security-related questions, take initiative and escalate in time if needed; – Signal improvements related to the way of working inside the team and contribute to improving the excellence of our service offering; – Stay up-to-date with emerging cyber security trends and the latest developments in the field of technology, information risk and threats, actively