Senior Cyber Security Third Party Risk Manager

Apply
Good to know: you can easily save this vacancy using the print button at the top of the page. After the closing date, this vacancy will be removed from our website.
  • Real programme ownership at a critical moment

    NIS2 and DORA are live. Eneco operates critical energy infrastructure with a broad supplier ecosystem. You are not maintaining a mature programme - you are shaping what it becomes at exactly the moment it matters most.

     

  • Influence that goes beyond security

    This role puts you at the table with Procurement, Legal, Compliance, and the business. TPRM at Eneco is not a back-office function - it is a business-critical capability with executive visibility.

     

  • A mission that means something

    Eneco's goal is climate neutrality by 2035. The infrastructure and supplier ecosystem you protect underpins that ambition. The work is serious, the stakes are real, and the organisation is committed.

Why choose Eneco?

Eneco is one of Europe's leading sustainable energy companies, working toward climate neutrality by 2035 through our One Planet strategy. Our Digital & Tech and Security organisation is a critical enabler of that mission - and the TPRM programme you lead sits at the heart of how we manage risk across our supplier ecosystem.

What you’ll do

  • Own the TPRM framework end-to-end - policies, standards, procedures, risk registers, and playbooks
  • Lead governance forums and steer risk-based decision-making and risk acceptance processes
  • Define and track KPIs, KRIs, and executive dashboards that give management real visibility of supplier risk
  • Drive continuous improvement across the full third-party lifecycle - from onboarding through to offboarding

 

Supplier Assessments and Risk Management

  • Perform and oversee security assessments of new and existing suppliers - reviewing ISO 27001, SOC reports, pen test results, BCDR plans, and security controls
  • Evaluate supplier cyber maturity, provide risk ratings, and define remediation requirements
  • Maintain risk registers, manage exceptions, and oversee remediation tracking
  • Implement continuous monitoring for critical suppliers and manage periodic reassessments
  • Support supplier breach response activities alongside the incident management team

 

Procurement and Regulatory Integration

  • Embed mandatory security review gates into procurement - high-risk vendors do not get onboarded without assessment and approval
  • Support contract reviews and security clause integration alongside Legal and Procurement
  • Align TPRM practices with NIS2, DORA, ISO 27001, NIST, and GDPR requirements
  • Prepare evidence and reporting for internal and external audits and regulatory examinations

 

Platform and Automation

  • Own and optimise the TPRM/GRC platform - driving automation of vendor onboarding, risk tiering, workflows, and reporting
  • Identify opportunities to reduce manual effort and increase assessment coverage through tooling
  • Define reporting capabilities that translate supplier risk data into actionable management insight

Is this about you?

You are a senior TPRM professional who has built or significantly matured a third-party risk programme in a complex enterprise environment. You know how to assess a supplier, but more importantly you know how to design a programme that scales, earns organisational trust, and keeps pace with a shifting regulatory landscape. You are comfortable in a room with senior stakeholders, confident presenting risk data to the board, and able to push back constructively when a high-risk vendor is being fast-tracked without proper scrutiny.

 

Experience

  • 5+ years hands-on experience in Third Party Risk Management
  • 7+ years in Cyber Security, IT Risk, Information Security, or GRC
  • Proven track record leading or maturing a TPRM programme in a large enterprise
  • Experience influencing senior stakeholders and embedding security controls into procurement and supplier governance processes
  • Familiarity with critical infrastructure or regulated sector environments is a strong plus

 

Knowledge and Expertise

  • Deep understanding of TPRM frameworks - vendor risk assessments, risk tiering, continuous monitoring, fourth-party risk, supply chain security, and exception management
  • Strong knowledge of relevant regulations and standards - NIS2, DORA, ISO 27001, NIST CSF, GDPR
  • Hands-on experience with at least one GRC/TPRM platform - ServiceNow GRC, OneTrust, Archer, ProcessUnity or similar
  • Solid grounding in information security domains - cloud security, identity and access management, incident management, and BCDR

 

Skills and Competencies

  • Ownership mindset - you take accountability for the programme, not just the tasks
  • Executive presence - you communicate risk clearly to senior stakeholders and translate complexity into decisions
  • Analytical and data-driven - you use risk data to drive prioritisation, not just report status
  • Automation mindset - you look for ways to increase coverage and reduce manual effort through tooling and process design
  • Collaborative - you influence across Legal, Procurement, Risk, IT, and Business without formal authority

 

Certifications (preferred)

  • CISSP, CISM, or CRISC
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified Third Party Risk Professional (CTPRP) is a strong plus

 

You’ll be responsible for

Eneco operates critical energy infrastructure and depends on a broad ecosystem of technology suppliers and service partners. As that ecosystem grows in complexity, so does the risk it carries - and regulators are paying close attention. NIS2 and DORA are not future considerations here. They are operational realities.

As TPRM Lead you own the end-to-end Third Party Risk Management programme - from framework and governance through to supplier assessments, continuous monitoring, and procurement integration. This is not an assessment execution role. You are here to mature the programme, increase its organisational reach, and make third-party cyber risk visible and manageable at every level of the business.

You will work from within the CISO Office, partnering with Procurement, Legal, Compliance, Risk, Data Privacy, and IT. You will need to influence without formal authority - and you will have the mandate to do it.

This is where you’ll work

You will be part of the CISO Office at Eneco, working within a security organisation that sits at the intersection of a major energy transition and a rapidly evolving regulatory environment. Your stakeholders span Procurement, Legal, Compliance, Enterprise Risk, Data Privacy, IT, and the wider business - giving you broad organisational reach from day one.

Eneco operates critical infrastructure and is directly in scope for NIS2 and DORA. That gives the TPRM programme real weight - and gives you a genuine mandate to drive change. We work hybrid, combining focused days from home with collaboration at Eneco's Rotterdam HQ.

What we have to offer

alt

Gross annual salary between €72,000 and €90,100

Including FlexBudget, 8% holiday allowance, and depending on your role a bonus or collective profit sharing.
alt

FlexBudget

Have it paid out, use it to buy extra holiday days or save it up for something nice, it's up to you.
alt

Personal and professional growth

Eneco is fully committed to help you in your personal and professional development.
alt

Hybrid working: home, office or abroad

Work 40% at the office, 40% from home, and 20% flexibly. With manager approval, you may work abroad (within approved countries) up to 3 weeks/year, max 2 consecutively.

Want more information about our terms of employment?

Work Where Everyone Matters

When you choose a career at Eneco, you choose ambition, growth, and opportunity in an environment where everyone matters. You’re given the space to develop yourself and to do your work in a way that suits you. We believe that different perspectives, nationalities, and backgrounds make us stronger, which is why we foster an open, safe and inclusive culture. Naturally, we also prioritize a healthy work-life balance, flexible working hours, and the option to work from home when your role allows it. If you have a physical or sensory disability, we will work with you to find the right adjustments so you can perform your job well.
This is how you build your own future and a sustainable future at the same time. Together with 4,000 colleagues, each with their own talents and ideas, you work on our shared mission: speeding up the energy transition. We help customers become more sustainable faster, create innovative solutions, and seize new opportunities. Will you join us?

The phases of our application procedure

Application procedure, 1 applying, 2 introduction interview, 3 online assessment, 4 follo-up interview, 5 offer time and 6 congratulations with your new job

Want to know more about this job function?

Please apply directly via the Eneco Careers Portal. Applications submitted by email will not be processed.

Third Party Disclaimer

Eneco manages recruitment through selected channels and preferred partners. Unsolicited acquisition, candidate submissions, or commercial outreach in relation to this vacancy are not appreciated.

Questions about the application procedure

Feel free to contact our recruiter:

Donja Huidar

Recruiter

Would you like to receive our newest job vacancies?

With this job vacancy, we aim to recruit a new colleague for Eneco. Therefore, this is not a solicitation for acquisition.