Information Security Risk Manager
Location: Utrecht (Hybrid)
Salary: Competitive + Car Allowance + Bonus
About the Opportunity
An international organisation operating across both IT and Operational Technology (OT) environments is investing significantly in the maturity of its cyber security capability and is looking to appoint its first dedicated Information Security Risk Manager.
This is a genuine greenfield opportunity. Rather than inheriting an established framework, you'll build the organisation's security risk capability from the ground up, working directly with the Chief Information Security Officer to shape how cyber risk is identified, assessed and communicated across the business.
You'll become a trusted advisor to the CISO and senior business stakeholders, ensuring cyber risk is understood, prioritised and communicated in a way that enables informed business decisions. Your work will have direct visibility at executive and board level, influencing investment decisions and helping shape the organisation's long-term cyber security strategy.
If you're someone who enjoys creating structure, influencing senior stakeholders and building lasting capability, this is an opportunity to make a genuine impact.
The Role
As Information Security Risk Manager, you'll take ownership of the organisation's security risk management capability, establishing the frameworks, governance and reporting needed to support a modern, risk-led security function.
Your responsibilities will include:
- Designing and maintaining the Information Security Risk Management Framework aligned to ISO 27001.
- Developing security risk methodologies, scoring models and governance processes.
- Owning and maintaining the enterprise security risk register.
- Leading Business Impact Assessments across critical business services.
- Developing quantitative risk analysis capabilities, using FAIR methodologies where appropriate, to support executive and board-level decision making.
- Producing clear, commercially focused reporting that translates technical cyber risks into business and financial impact.
- Establishing third-party security risk processes alongside Procurement and key business stakeholders.
- Supporting NIS2 compliance through effective risk management practices.
- Driving the continual maturity of the organisation's overall security risk capability.
This is not a traditional GRC administration role. We're looking for someone who will challenge stakeholders, influence decision-making and build a capability that enables business and IT leaders to understand, own and manage their security risks effectively.
About You
You'll be someone who enjoys building capability rather than simply maintaining existing processes.
You'll be comfortable operating with a high degree of autonomy, influencing senior stakeholders and bringing structure to an environment where you'll be creating, rather than inheriting, the organisation's security risk function.
We're particularly interested in professionals who can demonstrate:
Essential
- At least six years' experience within Information Security Risk Management.
- Experience designing or owning security risk frameworks and enterprise risk registers.
- Strong understanding of ISO 27001 and risk-based security governance.
- Experience conducting Business Impact Assessments (BIAs).
- The ability to translate technical cyber risks into clear business and financial impact.
- Excellent stakeholder management skills, with experience engaging senior business and IT leaders.
- Experience preparing executive or board-level risk reporting.
- Dutch Speaking is essential for this role
Desirable
- Practical experience applying FAIR or other quantitative risk methodologies.
- Experience within industrial, manufacturing, utilities or other regulated environments.
- Third-party risk management experience.
- Knowledge of NIS2 requirements.
- Experience working with GRC platforms.
Why Join?
This is an opportunity to build something that doesn't already exist.
You'll have the autonomy to define the organisation's security risk capability, work directly alongside the CISO and influence how cyber risk is understood at executive and board level.
In return, you'll join an international organisation that is making significant investment in cyber security and digital transformation, offering the opportunity to shape strategy, influence major investment decisions and build a function that will have a lasting impact across the business.
If you're interested in learning more, please apply or get in touch for a confidential discussion. We'd be happy to share further details about the organisation and the opportunity.