
The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. This requires a solid cyber risk management process that is integrated in the overall risk management capability. At this point in time the (cyber) risk management capacity is very limited. The transformation required for NIS2 & ISO27001 requires more capacity & expertise in be ready before July 2028.
You will be part of the GRC team within Library and Information Services (LIS) organization. This team will play a prominent role in implementation of cyber risk management, ISO27001 certification & NIS2 readiness. You report to the GRC manager.
A documented and practical risk assessment methodology aligned with ISO 27001, ISO 27005, NIS2, and the TU/e risk management framework. Standard templates, scoring criteria, risk categories, impact scales, and guidance for assessing inherent and residual risk. Clear criteria for risk acceptance, escalation, treatment, and management approval.
Risk assessments for agreed critical services, systems, projects, suppliers, research environments, and organisational units. Clear documentation of assets, threats, vulnerabilities, existing controls, risk scenarios, likelihood, impact, and residual risk. Prioritised findings and recommendations that can be translated into concrete improvement actions. Formal identification of risk owners and action owners.
Completed BIAs for critical education, research, operational, and supporting processes. Identification of critical activities, supporting systems, data, suppliers, facilities, people, and other dependencies. Documented impact assessments covering operational, financial, legal, regulatory, reputational, safety, and information-security consequences. Defined Maximum Tolerable Periods of Disruption, recovery priorities, Recovery Time Objectives, and Recovery Point Objectives.
An up-to-date and structured cyber and IT risk register. Documented risk treatment plans, including actions, priorities, responsible owners, deadlines, and target risk levels. Formal records of accepted, transferred, avoided, or mitigated risks. Monitoring of overdue actions, unresolved risks, and risks exceeding the approved risk appetite.
Periodic management reports on the overall cyber-risk exposure of LIS and TU/e. Dashboards showing risk levels, trends, critical risks, treatment progress, overdue actions, and risk acceptance decisions. Clear escalation reports for risks requiring management or executive decision-making. Reporting that supports ISO 27001 management reviews and NIS2 governance responsibilities.
A functioning risk management cycle covering identification, assessment, treatment, monitoring, review, and improvement. Defined review frequencies and triggers for reassessment, such as major changes, incidents, new threats, projects, or supplier changes. Evidence that risk assessments and BIAs are periodically reviewed and kept current. Recommendations for improving the maturity and consistency of risk management across TU/e.
Recovery and continuity requirements based on BIA outcomes. Prioritised recommendations for business continuity, disaster recovery, crisis management, backup, redundancy, and cyber resilience. Identification of gaps between required and actual recovery capabilities. Input for continuity plans, disaster-recovery plans, crisis exercises, and resilience testing.
Documented evidence demonstrating that cyber risks are systematically identified, assessed, treated, monitored, and reviewed. Traceability between risks, ISO 27001 controls, NIS2 obligations, policies, and improvement actions. Audit-ready documentation supporting internal audits, external certification, regulatory supervision, and management accountability. Support for the preparation and follow-up of ISO 27001 and NIS2 assessments.
Workshops, guidance, and practical training for service owners, risk owners, project managers, researchers, and technical teams. Clear instructions explaining roles, responsibilities, assessment methods, and expected evidence. Transfer of knowledge to the internal Risk Manager and GRC team. Increased stakeholder capability to independently identify, assess, and manage cyber risks.
Meer weten over deze organisatie? Lees wie ze zijn en welke opdrachten ze momenteel aanbieden.
Bij een geschikte match stelt TenTalent je graag voor! We lezen graag hoe jouw CV aansluit bij deze opdracht.
Onze marge voor de dienstverlening is €2,50 van het afgesproken uurtarief.
Als ervaren recruitment partner nemen wij het volledige selectie- en administratieve proces voor onze rekening. Jij kunt je volledig concentreren op je vakgebied, terwijl wij zorgen voor optimale matchmaking en professionele begeleiding gedurende de hele opdracht.
Blijf automatisch op de hoogte van relevante opdrachten door onze gerichte e-mail notificaties. Onze slimme matching zorgt ervoor dat je alleen opdrachten ontvangt die aansluiten bij jouw expertise, ervaring en voorkeuren.
Bedankt voor je inschrijving!
We hebben je gegevens en CV ontvangen. Bij een geschikte match nemen we spoedig contact met je op.
Verzenden mislukt. Probeer het later opnieuw.