Supply Chain Security Risk Manager
Key Skills
Job Description
Introduction 36 hours per week Start: ASAP 1-year assignment with the possibility of extension Hybrid way of work ZZP is allowed Relocation is not allowed Job description What does your working day look like? - The team works according to the DevOps & Agile methodology. - You are working on improving the Supply Chain Security services, based on user stories. - Occasionally there are incidents that occur that you are going to look into. - For your work you often engage with various stakeholders such as other IT departments, business colleagues and software suppliers. Key responsibilities in your work contain: - Govern and manage IT vendor relationships in terms of performance regarding the security aspects of the underlying contractual obligations; - Execute Vendor Security Risk Assessments and perform follow up actions. Focus on the risks that matter, translate them into the business context and help your stakeholders to address security challenges; - Ensure that information security risks are identified and managed effectively throughout all the stages of the relationship with external vendors; - Review the applicability and the quality level of assurance reports issued by the third parties; - Ensure continuous improvements are achieved both in the quality of reporting and service provided by the third party; - Manage the IT security related part of a contract with the third party provider. Work together with 2nd line functions such as legal, compliance, procurement and other internal parties on contractual changes; - Help solving security-related questions, take initiative and escalate in time if needed; - Signal improvements related to the way of working inside the team and contribute to improving the excellence of our service offering; - Stay up-to-date with emerging cyber security trends and the latest developments in the field of technology, information risk and threats, actively share this knowledge with your colleagues and help to determine if/when to integrate them into the assessment program. With the following results (SMART) Key part: Signal improvements related to the way of working inside the team and contribute to improving the excellence of our service offering; which are based upon our expected DORA impact Requirements - HBO or University degree - Knowledge and experience with setting up projects & deliverables within supply chain security / TPSRM - Experience in executing information security risk assessments; - Knowledgeable on one or more areas such as security processes, technology architectures, network security, application security and vulnerability management; - Excellent in stakeholder management. - Hands-on, self-organised, willing to finish and deliver (execution power) - A strong ability to translate technical risks into business risks and vice versa; - Service oriented professional, you enjoy taking on an internal consultancy role - Experience with the ServiceNow TPRM module is a huge pré.
Core Responsibilities
The manager will govern IT vendor relationships, execute security risk assessments, and ensure information security risks are effectively managed throughout the vendor lifecycle. They will also collaborate with internal stakeholders to address security challenges and drive continuous improvements in service quality.
Requirements
Candidates must hold an HBO or University degree and possess significant experience in supply chain security and information risk assessments. Strong stakeholder management skills and the ability to translate technical risks into business contexts are essential for this role.
About A2Z-CM N.V.
Industry: Business Consulting and Services
Company size: 51-200 employees
A2Z-CM is an independent private company founded in 2012 with offices in Amsterdam and United Kingdom. A2Z-CM is a vendor-neutral, fully-compliant company offering consultancy services, contract management and international brokering to suppliers and agencies in the Netherlands and other countries according to the principle of think global, act local. The A2Z-CM team assist clients by analysing their organisational issues and implementing realistic and cost-effective development plans. Think global, act local. At A2Z-CM, our specialists offer a combination of IT and technical experience, plus a thorough knowledge of compliance and risk mitigation. Our thorough grasp of both fields means that you get solutions tailored to meet your specific needs - solutions that are fully compliant. A2Z-CM provides Clients and contractors with clear, friendly and professional advice on all aspects of the local fiscal and legal regulations. It's our job to deliver a comprehensive range of services, leaving you free to focus on your core business or project.