Risk Manager
32–40 hours | Amersfoort / Hybrid | Energy Market | Applications accepted until Aug. 4 at 9:00 a.m.
Start Date: Sept. 1, 2026 | Duration: 6 months initially | Secondment | Interviews: Aug. 12–13
⚡Would you like to contribute to the energy transition through risk management?
We are looking for twoproactive First-Line Risk Managerswho will help an entire value stream make and keep risks manageable. This is not a traditional compliance role, but a position in which you will facilitate, coach, and support teams as they enhance their maturity in the areas of risk management, security, privacy, and assurance.
You’ll collaborate with DevOps teams, Product Owners, Security Officers, and auditors to deliver reliable and future-proof IT services that make a significant contribution to the ongoing digitization of the energy sector and the energy transition. In doing so, you’ll help teams conduct comprehensive risk assessments, implement appropriate control measures, and demonstrate that they are in control.
We strongly believe in the principle:
Demonstrate → Do Together → Do It Yourself
You are not merely a conduit for policies, procedures, or audit requests, but a trusted advisor who helps teams make better decisions and take independent ownership of risks.
✅ Experience with risk management, IT controls, or internal controls
✅ Affinity for Agile/DevOps and complex IT environments
✅ Strong in stakeholder management and bringing people together
✅ A coaching, pragmatic, and results-oriented approach
✅ Enthusiasm for making an active contribution to the energy transition
Would you like to make an impact on the reliability, safety, and continuity of critical energy services—and at the same time help build the energy supply of the future? If so, we’d love to hear from you.
#jobopening #riskmanagement #firstlineofdefense #itrisk #governance #compliance #assurance #security #privacy #agile #devops #energytрансition #sustainability #riskmanager #workingintheenergy sector
-----------------------------------------
Job Opening: Front-Office Risk ManagerAre you an analytical professional who views risks not as obstacles, but as opportunities to improve processes, teams, and service delivery? Do you thrive on collaborating with DevOps teams, Product Owners, auditors, and security specialists? If so, we’re looking for you.
If
Primary Care Risk Manager You play a key role in managing risks within a dynamic IT and data-driven environment. You ensure that new and existing applications not only function properly but also demonstrably meet the requirements for risk management, security, privacy, and assurance.
You will support teams in setting up and maintaining control frameworks, facilitate risk assessments and audits, and help the organization demonstrate that it is—and remains—in control.
Who are we looking for?We’re not looking for a risk administrator who just checks boxes or works through checklists. We’re looking for a
Proactive Front-Line Risk Manager who takes ownership of risk management across the entire value stream and who, driven by intrinsic motivation, helps teams improve systematically.
You have a broad, holistic perspective and understand that effective risk management is much more than just meeting audit or compliance requirements. You look at the entire landscape of processes, people, technology, data, security, privacy, and governance, and know how to connect these disciplines. You understand the objectives of the value stream, contribute to risk assessments, and help teams make decisions that are not only compliant but, above all, contribute to reliable, secure, and future-proof service delivery.
In addition, we believe that sustainable risk management only works when knowledge, ownership, and responsibility are embedded within the teams themselves as much as possible. That is why we are looking for a risk manager who not only advises but, above all, facilitates, coaches, and develops. You will help DevOps teams, Product Owners, Epic Owners, and other stakeholders increase their knowledge and maturity in the areas of risk management, internal controls, security, and assurance. In doing so, we operate according to the principle:
Demonstrate → Do Together → Do It Yourself. You help teams understand the rationale behind risks and risk management measures, so that they not only understand
what Things need to be done, but above all
why That’s what matters. You guide them step by step toward greater independence and ownership, so that risk management becomes a natural part of their daily work.
You are visible within the organization, actively seek collaboration with Product Owners, Epic Owners, architects, DevOps teams, Security Officers, and Privacy Officers, and aren’t afraid to ask critical questions when necessary. At the same time, you are a pragmatic sparring partner who knows how to translate complex risk and assurance issues into workable solutions that truly help teams move forward.
We are therefore looking for someone who:
- Assess risks in their full context, rather than solely based on individual controls;
- In addition, it monitors audit and compliance obligations and actively contributes to continuous improvement;
- Teams inspires, facilitates, and coaches rather than controls;
- Shares knowledge and actively works to increase risk awareness within the organization;
- Can translate complex issues into practical and understandable solutions;
- It draws energy from bringing together different disciplines and stakeholders;
- Teams helps people take responsibility for risks and risk management measures;
- He is a natural point of contact for both management and technical specialists.
As a First-Line Risk Manager, you are not merely a conduit for policies, procedures, audit requests, or control frameworks. You add demonstrable value by helping teams make better decisions, identify risks in a timely manner, and implement appropriate risk management measures. You not only help manage risks, but—more importantly—ensure that the organization and its teams continuously improve their ability to manage risks on their own.
In short: We are looking for a trusted advisor, coach, and facilitator who can help an entire value stream demonstrate that it is—and remains—in control.
What will you do?As a First-Line Risk Manager, you serve as the link between operations, risk management, security, privacy, and external auditors. You support teams in identifying, assessing, and managing risks, and help them demonstrate that they are in control.
Your duties include:
- Designing and implementing new Control Frameworks (CFWs) for new applications and services based on risk analyses;
- Demonstrating the design and existence of controls prior to the go-live of new functionalities and applications;
- Assessing the impact of changes on existing applications, risks, and control frameworks;
- Periodically testing and verifying the effectiveness of controls after going live;
- Facilitating external audits by organizing interviews, answering questions, and reviewing supporting documentation;
- Coordinating with stakeholders such as second-line risk management, auditors, Epic Owners, Security Officers, Privacy Officers, and the CFW Expert Group;
- Facilitating data migration risk assessments and ensuring that they are carefully documented and followed up on;
- Guiding teams in resolving audit findings and areas for improvement;
- Providing advice on complex ad hoc issues related to risk, privacy, security, and internal controls;
- Further professionalizing and operationalizing risk management within EDSN.
What do you bring?You are a strong communicator who can explain risks in a way that is understandable to both management and technical teams. You aren’t afraid to ask critical questions, but at the same time, you know how to engage and convince people.
In addition:
- Do you have at least 5 years of verifiable experience in risk management, internal controls, or IT controls?;
- Do you understand the Three Lines Model and the role of the first line within it;
- Do you have experience in a complex IT and/or change management environment, preferably within Agile and DevOps organizations;
- Are you skilled at bringing stakeholders together and can you switch seamlessly between operations, management, and governance;
- Can you translate risks into concrete and actionable measures;
- Do you work proactively and independently, but also function exceptionally well as part of a team?;
- Do you have excellent communication skills;
- Do you preferably have an RE degree (preferred)?
Why this position?Because here, you have a direct impact on the reliability, security, and continuity of business-critical services. You’ll work at the intersection of technology, governance, and risk management, and have the opportunity to help build new applications, processes, and workflows.
You’ll be working in an environment where collaboration, professionalism, and continuous improvement are key. No two days are the same: one day you might be facilitating a risk assessment for a new application, and the next you might be brainstorming with an auditor, Security Officer, or Epic Owner about the risks of an upcoming go-live.