IT Risk Manager
About the assignment
A major organisation is strengthening its risk management function. You'll build and execute the IT risk strategy, translating regulatory requirements and business objectives into actionable controls.
You assess infrastructure, applications, and third-party vendors for vulnerabilities and compliance gaps. You'll prioritize remediation efforts, track metrics, and communicate risk posture to the board and executive teams.
This role bridges security, compliance, and business operations. You'll influence security investments, drive risk awareness across departments, and ensure the organisation meets evolving regulatory standards.
Your responsibilities
- Identify, assess, and quantify IT and security risks across the enterprise using frameworks like NIST, ISO 27001, and industry-specific standards
- Design and implement risk mitigation strategies, including controls architecture and remediation roadmaps
- Monitor risk metrics and KPIs; produce quarterly/annual risk reports for executive and board-level stakeholders
- Conduct risk assessments for new projects, system implementations, and third-party integrations
- Manage relationships with external auditors, regulators, and compliance teams to validate control effectiveness
- Lead risk awareness and training programmes across business units
- Define and maintain the organisation's risk appetite and tolerance thresholds
- Advise security and IT teams on control design and risk treatment priorities
Tech Stack & Tools
Platforms & Tooling
Frameworks & Standards
Cloud & Infrastructure
Methodologies
Certifications (preferred)
Must-haves
- 8+ years in IT risk management, GRC, or enterprise security roles
- Proven expertise in risk frameworks (NIST, ISO 27001, COBIT, COSO)
- Experience with GRC platforms (ServiceNow, Archer, or equivalent)
- Strong understanding of enterprise IT infrastructure, cloud security, and regulatory compliance
- Excellent stakeholder management and ability to communicate risk to non-technical audiences
Nice-to-haves
- CISM or CRISC certification
- Experience in financial services, healthcare, or other highly regulated sectors
- Background in vulnerability management or security assessment
What we offer
- Strategic influence: shape security and risk strategy at board level
- Competitive salary and performance bonus
- Professional development budget for certifications and training
- Flexible working arrangements and modern office environment
- Health insurance and pension contributions
- Personal guidance from a dedicated MVPeople consultant who knows your niche
The process
Introduction
Phone call with your MVPeople consultant (within 24 hours)
Match & Brief
We discuss the assignment in detail and prepare you
Client meeting
Introduction to the client
Start
Contracting and onboarding
Details
Type
Freelance / ZZP (MVPeople)
Location
Provincie Utrecht
Work model
Hybrid
Level
Senior
Industry
overige
Rate
€100 per hour
Posted
28 July 2026
Job ID
56920
Contact
MVPeople Group
jobs@mvpeoplegroup.com