(Senior) Information Security Risk Manager

Opdrachtgever: (Leading) payment service provider
Type: Vast
Standplaats: Amsterdam
Regio Noord-Holland, Zuid-Holland, Utrecht, ..
Indicatie: 90-100k
Aantal uren per week: 40
Andere arbeidsvoorwaarden: klik hier
Sector: Financieel: Banken, Card-...
Laatste update: 11 september 2026
Officer IT Risk

  • 5-8 years of experience in ICT risk management, information security, or a related discipline within a highly regulated financial institution
  • Demonstrable experience with DORA (ICT risk management chapter), ISO/IEC 27001, and PCI DSS v4.0
  • Hands-on experience with a GRC platform such as Eramba or equivalent, including RCSA execution, control monitoring, and KRI reporting
  • Bachelor's or Master's degree in Information Security, Computer Science, Risk Management, or an equivalent field
  • Strong ability to translate complex technical risks into clear reporting for non-technical stakeholders, with a structured, process-oriented working style
  • Ability to constructively challenge first line of defence stakeholders on ICT risk and security topics
  • Strong written and verbal communication skills in English.

SPECIFIEKE SKILLS

My client is a leading, fast-growing and innovative payment service provider offering advanced payment solutions to businesses across Europe.

In this role you will become the primary operational owner of the ICT Risk Management Framework within the second line of defence. In this role, you will be responsible for the day-to-day execution, monitoring, and reporting of ICT risk and information security activities in line with DORA, ISO 27001, and PCI DSS requirements.

Furthermore you will become responsible for:

  • Maintaining and developing the ICT risk register, executing the RCSA cycle for ICT risk domains, and monitoring key ICT controls including KRI dashboard management
  • Owning the ISMS policy suite in line with ISO 27001, DORA, and document standards, and coordinating security monitoring oversight from a 2LoD perspective
  • Supporting DORA Chapter II obligations including ICT incident classification and major incident reporting, and monitoring the external threat landscape to translate developments into 2LoD risk signals
  • Leading PCI DSS 2LoD governance as primary owner of PCI DSS v4.0 compliance oversight, coordinating PCI-3DS as a separate project stream, and acting as primary contact for QSA and internal stakeholders
  • Owning the Eramba GRC platform including data structure, user access, and module configuration, and driving its rollout to new modules and processes as the ICT risk framework matures
  • Providing second line of defence oversight of ICT third-party risk, acting as primary liaison for the annual EY IT audit, and supporting the annual Group IT risk reporting cycle.
Copyright © 2026 Care Professionals