About this role
competenties zijn in het Engels geschreven, omdat de voertaal Engels is. The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. more capacity & expertise in be ready before July 2028. TU/e consists of various departments, where education and research are conducted, and a number of You will be part of the GRC team within Library and Information Services (LIS) organization. This team will play a prominent role in implementation of cyber risk management, ISO27001 certification & Improved Cyber Risk Assessment Methodology and the TU/e risk management framework. Business Impact Analyses • Identification of critical activities, supporting systems, data, suppliers, facilities, people, and other Risk Register and Treatment Plans • Documented risk treatment plans, including actions, priorities, responsible owners, deadlines, and • Monitoring of overdue actions, unresolved risks, and risks exceeding the approved risk appetite. Management Reporting and Dashboards • Dashboards showing risk levels, trends, critical risks, treatment progress, overdue actions, and risk • Reporting that supports ISO 27001 management reviews and NIS2 governance responsibilities. • Recommendations for improving the maturity and consistency of risk management across TU/e. Business Continuity and Resilience Requirements • Prioritised recommendations for business continuity, disaster recovery, crisis management, backup, redundancy, and cyber resilience. • Input for continuity plans, disaster-recovery plans, crisis exercises, and resilience testing. Compliance and Audit Evidence monitored, and reviewed. • Audit-ready documentation supporting internal audits, external certification, regulatory supervision, and management accountability. Key End Products • An approved cyber-risk assessment methodology. • A prioritised portfolio of com...