Skip to content
MVPeopleGroup
IT Risk Management

IT Risk Manager

Amersfoort, UTSecondment (MVProfessionals)Hybrid€100 per hourSenioroverheid

About the assignment

A major organisation is strengthening its risk management function. You assess IT vulnerabilities, monitor control effectiveness, and drive remediation across the enterprise. Your work directly impacts board-level decisions and regulatory standing.

You'll balance operational realities with security requirements. You identify gaps in controls, prioritise remediation based on business impact, and communicate risk in terms stakeholders understand.

Your responsibilities

  • Conduct IT risk assessments across infrastructure, applications, and third-party integrations using structured methodologies
  • Monitor control effectiveness through continuous testing and audit coordination
  • Report risk metrics to senior management and the audit committee with clear remediation roadmaps
  • Develop and maintain risk policies, frameworks, and risk appetites aligned with COBIT and ISO 27001
  • Evaluate emerging threats and their potential impact on critical business processes
  • Manage relationships with internal audit, compliance, and security teams to embed risk thinking
  • Track remediation efforts and validate control implementation
  • Support vendor and third-party risk assessments

Tech Stack & Tools

Platforms & Tooling

ServiceNow GRCArcherSplunk or Sentinel for log analysisvulnerability scanning tools (Nessus, Qualys)

Frameworks & Standards

ISO 27001ISO 31000COBIT 2019NIST Cybersecurity FrameworkNIS2DORA

Cloud & Infrastructure

AzureAWScloud security posture management tools

Methodologies

Risk assessment (qualitative and quantitative)Control testing and validationHeat mappingScenario analysis

Certifications (preferred)

CISMCRISCCISACISSP

Must-haves

  • 7+ years in IT risk, GRC, audit, or IT security roles
  • Hands-on experience with risk assessment methodologies and control frameworks (ISO 27001, COBIT, NIST)
  • Proficiency with GRC platforms (ServiceNow, Archer, or similar)
  • Strong analytical skills: you synthesise complex data into actionable risk narratives
  • Ability to communicate risk clearly to both technical and non-technical audiences

Nice-to-haves

  • Experience in regulated industries (banking, energy, government, healthcare)
  • Familiarity with continuous compliance and real-time risk monitoring
  • Background in vulnerability management or threat analysis

What we offer

  • Strategic role: shape enterprise risk strategy and control design
  • Autonomy: lead risk assessments and drive remediation without micromanagement
  • Growth: mentor junior analysts and expand into enterprise risk leadership
  • Modern toolkit: work with leading GRC and security platforms
  • Competitive package including pension, flexible working, and professional development budget
  • Personal guidance from a dedicated MVPeople consultant who knows your niche

The process

1

Introduction

Phone call with your MVPeople consultant (within 24 hours)

2

Match & Brief

We discuss the assignment in detail and prepare you

3

Client meeting

Introduction to the client

4

Start

Contracting and onboarding

Details

Type

Secondment (MVProfessionals)

Location

Amersfoort, UT

Work model

Hybrid

Level

Senior

Industry

overheid

Rate

€100 per hour

Posted

27 July 2026

Job ID

56886



Contact

Apply nowMore information
Apply now