IT- en infrastructuurvacatures in Rotterdam bij werkgevers die een visum kunnen sponsoren

openstaande vacatures
17 openstaande vacatures
werkgevers
12 werkgevers
noemen een salaris
1 noemen een salaris
noemen relocatie
0 noemen relocatie
Taal
Ervaringsniveau
Vakgebied
Meer filters

Nieuwste IT- en infrastructuurvacatures in Rotterdam

Filters openen het volledige overzicht met jouw keuze.

EnecoGeplaatst 2 dagen geleden

Senior Cyber Security Third Party Risk Manager

Rotterdam · Hybride

Wat we weten over deze vacature

  • Eneco staat in het IND-register van erkende referenten
  • De vacature is in het Engels
  • De vacature noemt geen salaris
Solliciteer op de site van Eneco Opent de eigen site van de werkgever.
Erkend referent
Staat in het IND-register
Taal
Engels
Ervaring
Senior
Salaris
Niet vermeld
Relocatie
Niet vermeld
Soort baan
Niet vermeld

Over de functie

Over de functie

Eneco is one of Europe's leading sustainable energy companies, working toward climate neutrality by 2035 through our One Planet strategy. Our Digital & Tech and Security organisation is a critical enabler of that mission - and the TPRM programme you lead sits at the heart of how we manage risk across our supplier ecosystem.

Wat ze zoeken

  • 5+ years hands-on experience in Third Party Risk Management
  • 7+ years in Cyber Security, IT Risk, Information Security, or GRC
  • Proven track record leading or maturing a TPRM programme in a large enterprise
  • Experience influencing senior stakeholders and embedding security controls into procurement and supplier governance processes
  • Familiarity with critical infrastructure or regulated sector environments is a strong plus

Wat ze zoeken

  • Ownership mindset - you take accountability for the programme, not just the tasks
  • Executive presence - you communicate risk clearly to senior stakeholders and translate complexity into decisions
  • Analytical and data-driven - you use risk data to drive prioritisation, not just report status
  • Automation mindset - you look for ways to increase coverage and reduce manual effort through tooling and process design
  • Collaborative - you influence across Legal, Procurement, Risk, IT, and Business without formal authority

Mooi meegenomen

  • CISSP, CISM, or CRISC
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified Third Party Risk Professional (CTPRP) is a strong plus

You will be part of the CISO Office at Eneco, working within a security organisation that sits at the intersection of a major energy transition and a rapidly evolving regulatory environment. Your stakeholders span Procurement, Legal, Compliance, Enterprise Risk, Data Privacy, IT, and the wider business - giving you broad organisational reach from day one.

Eneco operates critical infrastructure and is directly in scope for NIS2 and DORA. That gives the TPRM programme real weight - and gives you a genuine mandate to drive change. We work hybrid, combining focused days from home with collaboration at Eneco's Rotterdam HQ.

Please apply directly via the Eneco Careers Portal. Applications submitted by email will not be processed.

Programme Ownership and Governance

  • Own the TPRM framework end-to-end - policies, standards, procedures, risk registers, and playbooks
  • Lead governance forums and steer risk-based decision-making and risk acceptance processes
  • Define and track KPIs, KRIs, and executive dashboards that give management real visibility of supplier risk
  • Drive continuous improvement across the full third-party lifecycle - from onboarding through to offboarding

Supplier Assessments and Risk Management

  • Perform and oversee security assessments of new and existing suppliers - reviewing ISO 27001, SOC reports, pen test results, BCDR plans, and security controls
  • Evaluate supplier cyber maturity, provide risk ratings, and define remediation requirements
  • Maintain risk registers, manage exceptions, and oversee remediation tracking
  • Implement continuous monitoring for critical suppliers and manage periodic reassessments
  • Support supplier breach response activities alongside the incident management team

Procurement and Regulatory Integration

  • Embed mandatory security review gates into procurement - high-risk vendors do not get onboarded without assessment and approval
  • Support contract reviews and security clause integration alongside Legal and Procurement
  • Align TPRM practices with NIS2, DORA, ISO 27001, NIST, and GDPR requirements
  • Prepare evidence and reporting for internal and external audits and regulatory examinations

Platform and Automation

  • Own and optimise the TPRM/GRC platform - driving automation of vendor onboarding, risk tiering, workflows, and reporting
  • Identify opportunities to reduce manual effort and increase assessment coverage through tooling
  • Define reporting capabilities that translate supplier risk data into actionable management insight

Eneco operates critical energy infrastructure and depends on a broad ecosystem of technology suppliers and service partners. As that ecosystem grows in complexity, so does the risk it carries - and regulators are paying close attention. NIS2 and DORA are not future considerations here. They are operational realities.

As TPRM Lead you own the end-to-end Third Party Risk Management programme - from framework and governance through to supplier assessments, continuous monitoring, and procurement integration. This is not an assessment execution role. You are here to mature the programme, increase its organisational reach, and make third-party cyber risk visible and manageable at every level of the business.

You will work from within the CISO Office, partnering with Procurement, Legal, Compliance, Risk, Data Privacy, and IT. You will need to influence without formal authority - and you will have the mandate to do it.

You are a senior TPRM professional who has built or significantly matured a third-party risk programme in a complex enterprise environment. You know how to assess a supplier, but more importantly you know how to design a programme that scales, earns organisational trust, and keeps pace with a shifting regulatory landscape. You are comfortable in a room with senior stakeholders, confident presenting risk data to the board, and able to push back constructively when a high-risk vendor is being fast-tracked without proper scrutiny.

Knowledge and Expertise

  • Deep understanding of TPRM frameworks - vendor risk assessments, risk tiering, continuous monitoring, fourth-party risk, supply chain security, and exception management
  • Strong knowledge of relevant regulations and standards - NIS2, DORA, ISO 27001, NIST CSF, GDPR
  • Hands-on experience with at least one GRC/TPRM platform - ServiceNow GRC, OneTrust, Archer, ProcessUnity or similar
  • Solid grounding in information security domains - cloud security, identity and access management, incident management, and BCDR

Third Party Disclaimer

Eneco manages recruitment through selected channels and preferred partners. Unsolicited acquisition, candidate submissions, or commercial outreach in relation to this vacancy are not appreciated.

Real programme ownership at a critical moment

NIS2 and DORA are live. Eneco operates critical energy infrastructure with a broad supplier ecosystem. You are not maintaining a mature programme - you are shaping what it becomes at exactly the moment it matters most.

  • Influence that goes beyond security

    This role puts you at the table with Procurement, Legal, Compliance, and the business. TPRM at Eneco is not a back-office function - it is a business-critical capability with executive visibility.

  • A mission that means something

    Eneco's goal is climate neutrality by 2035. The infrastructure and supplier ecosystem you protect underpins that ambition. The work is serious, the stakes are real, and the organisation is committed.

    Lees de rest op de vacaturepagina

    Over deze vacatures

    17 openstaande IT- en infrastructuurvacatures in Rotterdam (in het Engels, zonder Nederlands als eis) bij werkgevers die kunnen sponsoren: 1 noemt een salaris, en geen enkele noemt relocatie- of visumondersteuning. De meeste vacatures staan open bij Nearfield Instruments (4), Dentsu (2) en Eneco (2); er zijn ook 13 vacatures in het Nederlands of met Nederlands als eis voor dezelfde zoekopdracht, die hier niet meetellen. Verwante pagina's: IT- en infrastructuurvacatures in Amsterdam (79), werktuigbouw-, elektro- en procesvacatures in Rotterdam (43) en software engineering vacatures in Rotterdam (25).

    In de lijst staan betekent dat de werkgever kan sponsoren, niet dat elke functie dat doet; het relocatielabel staat bij vacatures die het zelf zeggen. Elke vacature linkt direct naar de werkgever.

    Verder kijken

    Wie zoekt er mensen

    Vragen over IT- en infrastructuurvacatures in Rotterdam

    Hoeveel IT- en infrastructuurvacatures in Rotterdam staan er nu open?

    Op dit moment 17, allemaal van werkgevers in het openbaar register erkende referenten van de IND. Een vacature verdwijnt van deze pagina zodra de werkgever hem offline haalt.

    Mogen deze werkgevers kennismigranten sponsoren?

    Een plek in het register betekent dat een werkgever een verblijfsvergunning als kennismigrant mag sponsoren. Of hij dat voor een bepaalde functie doet, beslist de werkgever.

    Welk salaris heb ik in 2026 nodig als kennismigrant?

    Vanaf 1 januari 2026 vraagt de IND een brutosalaris van €5.942 per maand als je 30 jaar of ouder bent, €4.357 als je jonger bent dan 30, en €3.122 (het verlaagde salariscriterium) als je kort geleden bent afgestudeerd aan een Nederlandse universiteit of een verblijfsvergunning zoekjaar hoogopgeleiden hebt. Vakantiegeld telt niet mee.

    Moet ik Nederlands spreken om in Rotterdam te werken?

    Niet voor de vacatures op deze pagina: standaard zie je Engelstalige vacatures die geen Nederlands vragen. Spreek je Nederlands, dan vind je bij dezelfde werkgevers nog veel meer functies bij de vacatures in het Nederlands of met Nederlands als eis.

    Meer in de gidsen over visumsponsoring in Nederland.