Cyber Risk Manager in Eindhoven, Noord-Brabant | Opdracht

18 september 2026
Reageer direct
Reageren tot:

Job Description

Opdracht in het kort

OpdrachtgeverTechnische Universiteit Eindhoven
RegioEindhoven, Noord-Brabant
Deadline Verse Opdrachten22 september 2026, 11:00
Urenvanaf 32
Looptijd6 maanden

Reageren kan ook via info@verseopdrachten.nl.

Voor onze opdrachtgever zoeken wij een Cyber Risk Manager in Eindhoven, Noord-Brabant | Opdracht. Voldoe jij aan de eisen en wensen? Lijkt de opdracht jou leuk om te doen? Dan ben jij wellicht de kandidaat voor deze opdracht. Reageer en wij helpen je aan tafel.

Eisen

  • • A documented and practical risk assessment methodology aligned with ISO 27001, ISO 27005, NIS2, and the TU/e risk management framework.
  • • Standard templates, scoring criteria, risk categories, impact scales, and guidance for assessing inherent and residual risk.
  • • Clear criteria for risk acceptance, escalation, treatment, and management approval.
  • • Risk assessments for agreed critical services, systems, projects, suppliers, research environments, and organisational units.
  • • Clear documentation of assets, threats, vulnerabilities, existing controls, risk scenarios, likelihood, impact, and residual risk.

Opdrachtomschrijving

General De Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. This requires a solid cyber risk management process that is integrated in the overall risk management capability. At this point in time the (cyber) risk management capacity is very limited. The transformation required for NIS2 & ISO27001 requires more capacity & expertise in be ready before July 2028. TU/e consists of various departments, where education and research are conducted, and a number of support services. You will be part of the GRC team within Library and Information Services (LIS) organization. This team will play a prominent role in implementation of cyber risk management, ISO27001 certification & NIS2 readiness. You report to the GRC manager. Brief description of the work • Improved Cyber Risk Assessment Methodology and the TU/e risk management framework: inherent and residual risk. • Completed Risk Assessments and organisational units: impact, and residual risk. Formal identification of risk owners and action owners. • Formal identification of risk owners and action owners. • Business Impact Analyses: Identification of critical activities, supporting systems, data, suppliers, facilities, people, and other dependencies. Safety, and information-security consequences. Recovery Time Objectives and Recovery Point Objectives. • Identification of critical activities, supporting systems, data, suppliers, facilities, people, and other dependencies. • Safety, and information-security consequences. • Recovery Time Objectives and Recovery Point Objectives. • Risk Register and Treatment Plans: Documented risk treatment plans, including actions, priorities, responsible owners, deadlines, and target risk levels. Monitoring of overdue actions, unresolved risks, and risks exceeding the approved risk appetite. • Documented risk treatment plans, including actions, priorities, responsible owners, deadlines, and target risk levels. • Monitoring of overdue actions, unresolved risks, and risks exceeding the approved risk appetite. • Management Reporting and Dashboards: Dashboards showing risk levels, trends, critical risks, treatment progress, overdue actions, and risk acceptance decisions. Reporting that supports ISO 27001 management reviews and NIS2 governance responsibilities. • Dashboards showing risk levels, trends, critical risks, treatment progress, overdue actions, and risk acceptance decisions. • Reporting that supports ISO 27001 management reviews and NIS2 governance responsibilities. • Integration into the Risk PDCA Cycle: Review, and improvement. Consideration of new threats, projects, or supplier changes. Recommendations for improving the maturity and consistency of risk management across TU/e. • Review, and improvement. • Consideration of new threats, projects, or supplier changes. • Recommendations for improving the maturity and consistency of risk management across TU/e. • Business Continuity and Resilience Requirements: Prioritised recommendations for business continuity, disaster recovery, crisis management, backup, redundancy, and cyber resilience. Input for continuity plans, disaster-recovery plans, crisis exercises, and resilience testing. • Prioritised recommendations for business continuity, disaster recovery, crisis management, backup, redundancy, and cyber resilience. • Input for continuity plans, disaster-recovery plans, crisis exercises, and resilience testing. • Compliance and Audit Evidence: Audit-ready documentation supporting internal audits, external certification, regulatory supervision, and management accountability. Evidence monitored, and reviewed. • Audit-ready documentation supporting internal audits, external certification, regulatory supervision, and management accountability. • Evidence monitored, and reviewed. • Knowledge Transfer and Stakeholder Enablement: Enablement of service owners, researchers, and technical teams. Transfer of knowledge to the internal Risk Manager and GRC team. • Enablement of service owners, researchers, and technical teams. • Transfer of knowledge to the internal Risk Manager and GRC team. Key End Products • An approved cyber-risk assessment methodology. • A prioritised portfolio of completed risk assessments and BIAs. • Approved risk treatment and risk acceptance records. • A documented risk PDCA process. • An improvement roadmap for remaining ISO 27001 and NIS2 risk-management gaps. Core Competencies for a Cyber Risk Manager For the Cyber Risk Manager role at TU/e, the following competencies are particularly important. They align with the requested role, which focuses on the risk management PDCA cycle, stakeholder collaboration, risk treatment, reporting, and translating technical risks into impacts on research, education, and business operations. • Cyber Risk Assessment Experience assessing likelihood, impact, inherent risk, and residual risk using a consistent methodology and establishing clear ownership. • Experience assessing likelihood, impact, inherent risk, and residual risk using a consistent methodology and establishing clear ownership. • Business Impact Analysis Experience assessing the operational, financial, legal, reputational, safety, and information-security impact of disruption. Experience defining Recovery Time Objectives and Recovery Point Objectives and related requirements. • Experience assessing the operational, financial, legal, reputational, safety, and information-security impact of disruption. • Experience defining Recovery Time Objectives and Recovery Point Objectives and related requirements. • Knowledge of ISO 27001 and NIS2 Understanding of NIS2 requirements relating to risk management, incident handling, business continuity, supply-chain security, governance, and management accountability. Experience supporting auditability, evidence collection, risk reporting, and continuous improvement. • Understanding of NIS2 requirements relating to risk management, incident handling, business continuity, supply-chain security, governance, and management accountability. • Experience supporting auditability, evidence collection, risk reporting, and continuous improvement. • Analytical and Structured Working Strong analytical skills and attention to the quality and consistency of risk and BIA data. Experience with risk registers, dashboards, reporting, and GRC tooling. • Strong analytical skills and attention to the quality and consistency of risk and BIA data. • Experience with risk registers, dashboards, reporting, and GRC tooling. • Stakeholder Management and Facilitation Ability to engage effectively with service owners, researchers, architects, engineers, project managers, and management. Strong communication skills and the ability to explain cyber risks in clear business language. • Ability to engage effectively with service owners, researchers, architects, engineers, project managers, and management. • Strong communication skills and the ability to explain cyber risks in clear business language. • Pragmatic Implementation Focus on proportionality, avoiding unnecessary complexity and administrative burden, while ensuring effective risk management. • Focus on proportionality, avoiding unnecessary complexity and administrative burden, while ensuring effective risk management. • TU/e-Specific Organisational Awareness Understanding of the specific needs of scientific research, education, laboratories, research infrastructure, and operational technology. Ability to balance security, compliance, resilience, usability, and research objectives. • Understanding of the specific needs of scientific research, education, laboratories, research infrastructure, and operational technology. • Ability to balance security, compliance, resilience, usability, and research objectives. Let op: • 1. Gezien de aard van onderhavige opdracht is het niet mogelijk om hiervoor als zzp’er zelfstandig in te schrijven. Indien een Opdrachtnemer ervoor kiest om een ZZP’er bij de TU/e te plaatsen, omdat dit in zijn of haar optiek mogelijk is, komen alle verplichtingen, ook die krachtens de belasting-, zorgverzekerings- en socialeverzekeringswetgeving met betrekking tot Personeel van Opdrachtnemer, ten laste van Opdrachtnemer. Opdrachtnemer vrijwaart Opdrachtgever tegen elke aansprakelijkheid die daarmee verband houdt waaronder mede begrepen aanspraken van het Personeel van Opdrachtnemer gebaseerd op het beweerdelijk bestaan van een arbeidsovereenkomst met Opdrachtgever, alsmede aanspraken van derden (zoals de Belastingdienst) in dit verband. Zie ook artikel 13 van de Overeenkomst. • 2. De Inschrijver dient – door middel van het overleggen van een uittreksel uit het Handelsregister – aan te tonen dat hij personeel uit mag lenen en voldoet aan de voorwaarden vanuit de Wet Allocatie Arbeidskrachten door Intermediairs (Waadi).

Zo vergroot je je kans op deze opdracht

Bij veel opdrachtgevers wordt je cv eerst beoordeeld op de afzonderlijke eisen en wensen. Alleen noemen dat je ergens ervaring mee hebt, is daarom vaak niet voldoende.

Onderbouw in je cv zo concreet mogelijk waar, wanneer en in welke rol je de gevraagde ervaring hebt opgedaan. Benoem relevante opdrachten, organisaties, perioden, werkzaamheden en resultaten. Hoe eenvoudiger de beoordelaar jouw ervaring kan herleiden naar de eisen en wensen, hoe sterker je voorstel.

Wanneer je via Verse Opdrachten reageert, helpen wij je om je voorstel zo duidelijk mogelijk te maken voordat het wordt ingediend.

Voorstellen via Verse Opdrachten

Door op deze opdracht te reageren geef je Verse Opdrachten toestemming om jouw aangeleverde cv, toelichting en gegevens te gebruiken om je voor deze concrete opdracht voor te stellen. We stellen je alleen voor wanneer jij daarvoor akkoord hebt gegeven.

Waarom via Verse Opdrachten?

Wij willen dat zoveel mogelijk van het beschikbare tarief bij jou terechtkomt. Daarom werken we met lage en vooraf transparante fees. Onze fee bedraagt 7,5% tot 9%.

Wij helpen je actief om aan tafel te komen. We stoppen veel werk in de kwaliteit van jouw voorstel en in de aansluiting tussen je cv en de eisen en wensen van de opdrachtgever. Onze aanpak is gericht op een hoge succesratio.

We hebben voor vrijwel iedere situatie een passende route: ZZP Detachering, directe inhuur of traditionele projectdetachering. We zoeken een betrouwbare en zo gunstig mogelijke oplossing voor jou, ingericht in lijn met de geldende regels rond de Wet DBA. Je hoeft dus niet zelf verder te zoeken naar een passende inhuurconstructie.

Ook als je nog niet direct op een opdracht wilt reageren, zoeken we gratis en vrijblijvend met je mee. We stellen je alleen voor als jij dat wilt.

Vrijheid staat voorop. Geen onnodig beperkende contractafspraken. En besluit je na een gesprek dat de opdracht toch niet bij je past? Dan is afhaken geen probleem.

Interesse?

Reageer en wij helpen je aan tafel. Zorg dat je reactie ruim vóór de Verse Opdrachten-deadline bij ons binnen is, zodat we tijd hebben om je voorstel te controleren en te verbeteren.

Lukt reageren via de site niet? Mail dan naar info@verseopdrachten.nl.