Cyber Risk Manager
About the assignment
A leading organisation needs a Cyber Risk Manager to own the identification, quantification, and mitigation of cyber risks across all business units and systems.
You report directly to senior leadership and present risk assessments to the board. You bridge technology, compliance, and business strategy—translating complex threats into executive-friendly language and actionable risk responses.
Your impact is direct: you influence vendor selection, security investments, incident response priorities, and regulatory compliance programs. You work with CISO, GRC teams, and business stakeholders to embed risk management into daily operations.
Your responsibilities
- Conduct cyber risk assessments across infrastructure, applications, and third-party dependencies using structured frameworks
- Develop and maintain a risk register that tracks emerging threats, vulnerabilities, and mitigation progress
- Present quarterly risk reports to the executive board, including risk appetite alignment and financial impact models
- Lead risk response planning: prioritise remediation efforts, define SLAs, and track closure against KPIs
- Manage third-party risk assessments and vendor security evaluations
- Align cyber risk strategy with regulatory requirements (ISO 27001, NIS2, DORA, or sector-specific mandates)
- Collaborate with incident response teams during active incidents to assess impact and escalate appropriately
- Design and implement cyber risk metrics and dashboards for continuous board-level visibility
Tech Stack & Tools
Platforms & Tooling
Frameworks & Standards
Cloud & Infrastructure
Methodologies
Certifications (preferred)
Must-haves
- 8+ years in cybersecurity with at least 4 years in risk management or GRC roles
- Proven experience presenting cyber risk to boards and C-suite executives
- Strong knowledge of ISO 27001, NIST CSF, and enterprise risk frameworks
- Proficiency with risk management platforms (ServiceNow GRC, Archer, or equivalent)
- Fluent in Dutch and English; able to communicate complex risk clearly to non-technical stakeholders
Nice-to-haves
- Experience with regulatory frameworks: NIS2, DORA, or industry-specific mandates
- Background in third-party risk management and vendor security assessments
- Certification: CISM, CRISC, or CISA
What we offer
- Shape security strategy at executive level with real board influence
- Work with a cross-functional leadership team across technology and business
- Competitive salary and comprehensive pension scheme
- Professional development budget for certifications and conferences
- Flexible working arrangements and home office options
- Personal guidance from a dedicated MVPeople consultant who knows your niche
The process
Introduction
Phone call with your MVPeople consultant (within 24 hours)
Match & Brief
We discuss the assignment in detail and prepare you
Client meeting
Introduction to the client
Start
Contracting and onboarding
Details
Type
Freelance / ZZP (MVPeople)
Location
Eindhoven
Work model
Hybrid
Level
Senior
Industry
bankwezen
Rate
€110 per hour
Posted
14 September 2026
Job ID
57979
Contact
MVPeople Group
jobs@mvpeoplegroup.com