As Information Security Officer (Third-Party Risk Management) you are responsible for managing and strengthening PostNL's security posture across suppliers and customer-facing partnerships. You combine cybersecurity expertise with stakeholder management skills, ensuring that third-party risks are identified, assessed and mitigated in a structured and pragmatic way.
Why you choose PostNL as a Information Security Officer - Team Suppliers & Customers voor PostNL
Strategic impact: Third-party risk is high on the board agenda. Your work directly contributes to resilience and compliance.
Complex stakeholder landscape: You operate at the intersection of IT, business, legal and suppliers.
Maturity growth: You contribute to further professionalizing TRPM within a large, regulated organization.
Visibility: You interact with senior management and external strategic partners.
Development: Opportunity to deepen expertise in regulatory frameworks (NIS2, DORA-like principles, supply chain security).
Your role
As an Information Security Officer (ISO) focused on Third-Party Risk Management (TPRM), you will be part of our Cyber Security Office (CSO) within the Suppliers & Customers domain. This domain is responsible for managing cyber risks related to suppliers, customers, and strategic partners. In this role, you help ensure that our external partnerships meet security requirements while supporting business continuity and operational goals. You understand that security should enable the business. You will perform third-party security risk assessments, including due diligence, onboarding, and periodic reassessments. Also you evaluate supplier compliance against ISO 27001, NIST Cyber Security Framework (CSF), and our internal security policies.You define, coordinate, and monitor mitigation plans together with business owners and suppliers. Also you support audits and evidence-gathering activities related to supplier security and compliance.
You balance risk mitigation, regulatory compliance, and operational feasibility. By building strong relationships with internal and external stakeholders, you help create a secure and resilient supplier ecosystem that supports our business ambitions. You contribute to the further development and improvement of our Third-Party Risk Management framework, processes, and tooling.
The Senior Information Security Officer position is typically positioned within salary scale 11. However, for candidates who can demonstrate relevant team-lead experience and capabilities, the role may be expanded to include team lead responsibilities and be evaluated at salary scale 12.
Your Team
You are part of the Suppliers & Customers domain, collaborating closely with:
- DevOps teams across business units
- Cloud platform teams
- Enterprise and solution architects
- Business Information Security Officers
- Privacy and Data Governance teams
You play a key role in increasing the information security maturity of suppliers, collaborate with customers, and manage third-party risks across the supply chain.
What we deliver you
A job full of innovation and impact. At PostNL, we want to become the e-commerce logistics platform of the future. Every day, we work on smarter, faster, and better ways to deliver special moments. Your ambition and our challenge come together here. In return, you can count on an attractive package of employment benefits.
These are the top benefits of this role:
- A gross monthly salary between €4,589 and €6,499 based on a 37-hour work week but 32 hours is possible too!
- The opportunity to work in a hybrid way and organise your working hours flexibly. If you work from home two or more days per week, you will receive a net home office allowance of €45 per month.
- An laptop (Mac or Windows) and a smartphone.
- 8% holiday allowance and 25 vacation days based on full-time employment.
- Travel expense reimbursement for commuting.
- An excellent pension scheme through the PostNL pension fund.
- Plenty of learning and development opportunities through the PostNL Academy.
- Discounts on holidays, events, and various products.
What you bring
You combine strong analytical skills with a pragmatic and business-oriented mindset. You know how to translate security requirements into practical solutions and can confidently engage with a wide range of stakeholders, from suppliers to senior management. Thanks to your communication and negotiation skills, you build trust and drive risk mitigation initiatives effectively.
You also have see your self in the following:
- A Bachelor's or Master's thiking levels and preferably a degree in IT, Cybersecurity, Risk Management, or Business Administration.
- 3 to 6+ years of experience in Information Security, Third-Party Risk Management, or a related field.
- Experience conducting supplier risk assessments and managing vendor security governance processes.
- Strong knowledge of ISO 27001, NIST Cybersecurity Framework (CSF), CIS Controls, and audit practices.
- Understanding of NIS2, GDPR, and supply chain security risk requirements.
- Relevant certifications such as CISSP, CISM, CRISC, or CISA are considered an advantage.
- The ability to work independently at a medior or senior professional level.
- Excellent stakeholder management and negotiation skills.
The final letters
We do a background check during the application. We hereby ask you for a Certificate of Good Conduct (VOG).
We will also check your references and may conduct a tailor-made investigation.
We are looking for new colleagues who want to work with us to build the PostNL of the future. We therefore return mail from recruitment agencies.
As part of the recruitment process, candidates undergo an assessment designed to evaluate their competencies and skills relevant to the position. 59.460