Introduction
- 36 hours per week
- Start: 01-09-2026
- End: 31-08-2027
- Extension is possible
- ZZP is allowed
- Hybrid working 1-2 day per week in office
Function
We are looking for a senior security expert to act as process owner for Issue Management from a security scope, maturing the end-to-end process with primarily focus on the Issue-to-Risk process. In this role, you will provide deep subject-matter expertise and direction to improve how security-relevant issues are identified, assessed, prioritised, escalated, governed and translated into risk insight.
Issue Management team aims to ensure that significant deviations are formally recorded and escalated to higher management, while also providing Risk Management with insight into potential risks through the Issue-to-Risk procedure. The team mission is to ensure that every issue is timely remediated, minimising the impact of issues in the bank risk appetite.
You will take ownership of the security scope of Issue Management, guide the team, align stakeholders across first and second line, and drive the transition toward a more risk-based, management attention driven process. You will work closely with three main departments: CISO (Corporate Information Security Office), Platform & Technology, CRO IT & Cyber (Cyber Risk Office) and with the following roles: security experts, security process owners, BISOs (Business Information Security Officers), SDMs (Service Delivery Managers) and Risk Managers to ensure that the right issues receive the right attention at the right level.
Your mission is to make Issue Management a stronger security and risk management control: improving prioritisation, clarifying responsibilities, strengthening governance, and ensuring that the Issue-to-Risk process focuses on material exposure and resilience outcomes.
With the following results (SMART)
Own and improve the security scope of the Issue Management process.
Lead and implement the maturation of Issue-to-Risk, including scope, process design, governance, SLA, KPI and reporting.
Standardise issue review assessment for first and second line, including guidance, training and automation opportunities.
Ensure alignment and measurable outcomes between Issue Management, Risk Management and Resilience.
Guide the team and stakeholders in consistent, risk-aware issue handling.
Improve reporting, dashboards and KPIs to monitor inflow, outflow, backlog ageing, acceptance, severity, Issue-to-Risk handoff and remediation progress.
Support the Issue Management roadmap, including task/issue/risk framework formalisation, review rules, exception workflows, data quality and process performance improvements.
Team backlog management.
Strategic sparring partner alongside the manager able to provide quarterly strategic insights and proposals that influence managerial decisions
In short: You will deliver a clear and functioning security Issue Management operating model, a matured Issue-to-Risk process, a risk-based backlog approach, improved severity and review guidance, stronger governance reporting, and an embedded way of working that helps ABN AMRO focus management attention on the security issues that matter most.
Requirements
Senior experience in IT security, risk management, operational risk, process governance or control frameworks
Ability to operate as trusted advisor to senior stakeholders and as process owner for complex cross-domain topics.
Strong understanding of Issue Management, Issue-to-Risk, 3-lines-of-defence, governance escalation and management reporting
Strong analytical skills and the ability to translate issue data into risk-based priorities and concrete actions.
Excellent stakeholder management and communication skills.
Preferred ABN AMRO experience
Professional proficiency in English
Information
Sean Verhoef +31(0)20-3337629
Application
Sean Verhoef +31(0)20-3337629