Job Description
Vulnerability Management Road Manager / IT Risk Manager
260604-OF-003
Location
Utrecht, Netherlands (Hybrid)
Contract Duration
Until December 2026
Start Date
ASAP
Hours
40 Hours per Week
Education Required
HBO / University Level (WO Thinking and Working Level Preferred)
Experience Required
7+ Years
We are seeking an experienced Vulnerability Management Road Manager to lead and coordinate enterprise-wide vulnerability management initiatives within a complex financial services environment. This role is responsible for creating structure, visibility, and momentum across security improvement programs, ensuring vulnerabilities are effectively managed, risks are reduced, and remediation efforts remain on track.
Working closely with security, infrastructure, platform, application, and leadership teams, you will drive strategic initiatives that strengthen organizational resilience and improve security posture across the enterprise.
Key Responsibilities
Vulnerability Management Leadership
Drive the organization-wide Vulnerability Management roadmap and improvement initiatives.
Create transparency, governance, and accountability across remediation programs.
Coordinate efforts to improve patch management, vulnerability remediation, and security controls.
Support the implementation of automated patching and vulnerability remediation processes.
Ensure timely follow-up and closure of critical and high-risk vulnerabilities.
Program & Project Management
Translate security objectives into structured project plans with clear milestones and deliverables.
Define project scope, timelines, ownership, dependencies, and success metrics.
Coordinate cross-functional teams to ensure alignment and effective execution.
Track progress, identify blockers, and manage project risks.
Escalate issues and drive resolution to maintain project momentum.
Risk Management & Security Governance
Identify security risks and vulnerabilities impacting the organization.
Provide recommendations on risk mitigation strategies and prioritization.
Support the implementation of preventive and corrective security measures.
Ensure security initiatives align with organizational risk management frameworks.
Contribute to long-term security planning and resilience improvement.
Stakeholder Management
Collaborate with:
Security teams
Infrastructure teams
Platform teams
Application owners
IT leadership
Business stakeholders
Build consensus and drive alignment across multiple domains.
Advise senior leadership and management on security priorities and remediation strategies.
Facilitate decision-making and governance discussions.
Reporting & Performance Monitoring
Develop executive-level reports and dashboards.
Monitor key vulnerability management metrics and remediation performance.
Provide regular updates on:
Progress against objectives
Security risks
Improvement initiatives
Dependencies and blockers
Present findings and recommendations to senior stakeholders and leadership teams.
Required Skills & Experience
Must-Have
Minimum 7 years of experience in Information Security, IT Risk Management, or Cybersecurity Program Management.
Strong expertise in Vulnerability Management processes and best practices.
Demonstrated experience managing large-scale security improvement initiatives.
Proven project and program management experience.
Experience working within complex enterprise or international environments.
Strong understanding of:
Vulnerability Assessment
Patch Management
Risk Management
Security Governance
Security Operations
Experience managing and influencing senior stakeholders and executive leadership.
Strong analytical and problem-solving skills.
Excellent communication and presentation skills.
Fluent in Dutch and English.
Preferred Skills
Experience within banking, financial services, or highly regulated industries.
Knowledge of security frameworks and industry standards.
Familiarity with enterprise vulnerability management tools and reporting platforms.
Experience with security transformation programs.
Understanding of enterprise infrastructure, cloud platforms, and application security.
Key Competencies
Vulnerability Management
Information Security
IT Risk Management
Security Governance
Cyber Risk Management
Program Management
Project Management
Stakeholder Management
Executive Reporting
Security Operations
Change Management
Strategic Planning
Leadership & Coordination