Skip to content
MVPeople Group Logo
MVPeopleGroup
IT Risk Management

IT Risk Project Manager

Arnhem, GEConsultancyHybridSeniorbankwezen

About the assignment

A leading organisation in financial services is scaling its IT risk management function. You'll oversee multi-year risk remediation programmes, bridge technology and governance teams, and report directly to the Chief Risk Officer.

Your focus: reducing residual risk, optimising control effectiveness, and embedding risk awareness across the organisation. You'll manage stakeholders from C-suite to technical teams, balancing competing priorities within strict timelines.

Your responsibilities

  • Define and execute IT risk project roadmaps aligned with enterprise risk appetite
  • Monitor control implementation progress against agreed KPIs and risk metrics
  • Coordinate cross-functional teams (security, infrastructure, compliance, business units)
  • Report risk status, findings, and recommendations to senior leadership and audit committees
  • Identify bottlenecks in risk remediation and propose mitigation strategies
  • Maintain risk registers and track emerging threats affecting project scope
  • Facilitate risk workshops with stakeholders to validate assessments and solutions
  • Ensure compliance with regulatory requirements (ISO 27001, NIS2, DORA)

Tech Stack & Tools

Platforms & Tooling

ServiceNow GRCArcherOneTrust

Frameworks & Standards

ISO 27001COBIT 2019NIST Cybersecurity FrameworkNIS2DORABIO 2.0

Methodologies

Risk assessment (qualitative/quantitative)Agile project managementPRINCE2 / PMI frameworksStakeholder managementChange management

Certifications (preferred)

CISACRISCPMPPRINCE2

Must-haves

  • 7+ years in IT risk management, compliance, or related GRC roles
  • Proven experience managing large-scale IT risk remediation programmes
  • Strong understanding of ISO 27001, NIST frameworks, and regulatory requirements
  • Fluent in Dutch and English (written and spoken)
  • Experience with risk management tools (ServiceNow GRC, Archer, or equivalent)

Nice-to-haves

  • CISA or CRISC certification
  • Background in financial services or heavily regulated industries
  • Experience with board-level risk reporting and executive communication

What we offer

  • Influence enterprise risk strategy at executive level
  • Work with cutting-edge GRC platforms and frameworks
  • Lead cross-functional teams in a regulated, high-impact environment
  • Continuous learning through certifications and industry events
  • Flexible work arrangements with home office options
  • Personal guidance from a dedicated MVPeople consultant who knows your niche

The process

1

Introduction

Phone call with your MVPeople consultant (within 24 hours)

2

Match & Brief

We discuss the assignment in detail and prepare you

3

Client meeting

Introduction to the client

4

Start

Contracting and onboarding

Details

Type

Consultancy

Location

Arnhem, GE

Work model

Hybrid

Level

Senior

Industry

bankwezen

Posted

13 April 2026


Contact

Apply nowMore information
Apply now