- Location
- AME (Amsterdam - Maple), Netherlands
- Type
- Full-time
- Department
- Operations
- Source
- Workday
Description
The WB CISO Supply Chain Security Expert is a senior Wholesale Banking subject matter expert for supply chain cyber resilience and third-party cyber risk. The role contributes to the WB-wide direction for supplier cyber resilience through hands-on remediation leadership, end-to-end oversight of third-party cyber risk and trusted advisory on complex supplier security, resilience, contractual and regulatory matters.
The role combines strong cybersecurity and IT risk management with business partnership and cross-functional collaboration. It ensures that third parties meet ING security, resilience, contractual and regulatory requirements, while translating complex cybersecurity expectations into practical, risk-based solutions that support Wholesale Banking strategy. Additionally, the role views supply chains holistically by extending the expertise to effectively address WB client-initiated security demand towards ING. By strengthening client confidence in ING's cyber resilience capabilities, the role supports the positioning of WB CISO as a trusted business enabler and credible external representative on supply chain cyber resilience matters.
The team
The WB CISO Supply Chain Security Expert works closely with the WB CISO Supply Chain Security Lead on achieving sustainable maturity improvement of TIPM, TPCRM and client-initiated security management processes across all WB entities worldwide, and with local WB CISO representatives in WB entities to ensure consistent execution in a scalable and harmonized way.
Roles and responsibilities
1. Advance supply chain cyber resilience strategy and governance
- Advance the WB supply chain cyber resilience strategy in alignment with the evolving cyber threat landscape, risk appetite, regulatory requirements and business objectives.
- Lead strategic initiatives that strengthen supply chain resilience, enhance third-party risk governance, improve regulatory readiness and reinforce client confidence in ING's cyber resilience capabilities.
- Drive the evolution of third-party cyber resilience policies and standards, translating emerging cyber threats and risks, regulatory developments and industry practices into practical, risk-based security outcomes.
2. Strengthen TIPM foundation as a prerequisite for effective supply chain security
- Enable contract owners to achieve TIPM compliance via expert advisory, practical implementation guidance, remediation support and hands-on assistance where appropriate.
- Oversee TIPM reporting quality and timeliness, coordinating stakeholders and driving the resolution of non-compliance and structural process issues to closure.
- Steer the evolution of TIPM towards compliance by design, establishing a robust foundation for third-party cyber contract compliance, ongoing supplier monitoring and effective supply chain cyber resilience oversight.
3. Improve third-party cyber contract compliance
- Define, maintain and embed cyber security and resilience requirements, contract clauses and assurance obligations in third-party agreements, ensuring alignment with ING standards and regulatory requirements.
- Provide expert guidance on supplier cyber security requirements, contractual negotiations, risk assessments and exceptions to support informed risk-based decision making.
- Identify and drive remediation of contractual cyber security and resilience gaps, strengthening third-party compliance and reducing supply chain risk exposure.
4. Improve third-party cyber monitoring
- Manage the end-to-end execution of third-party cyber monitoring activities, including stakeholder coordination and service provider performance oversight.
- Facilitate the communication of monitoring results to contract owners and suppliers, driving timely risk remediation and informed risk management decisions.
- Drive the evolution of third-party cyber monitoring towards a threat-informed model, leveraging threat intelligence, emerging risk insights and data-driven analysis to improve risk detection and resilience outcomes.
5. Enhance client-facing cyber security assurance
- Coordinate responses to client cyber security and resilience assessments, questionnaires and due diligence requests, ensuring timely, accurate and consistent engagement across stakeholders.
- Provide expert guidance to relationship managers, sales teams and subject matter experts on client cyber security requirements, supporting effective client engagements and risk-based decision making.
- Improve client-facing cyber security assurance by identifying recurring client concerns, evolving industry expectations and opportunities to strengthen ING's security posture, evidence base and resilience capabilities.
How to succeed
We hire smart people like you for your potential. Our biggest expectation is that you’ll stay curious. Keep learning. Take on responsibility. In return, we’ll back you to develop into an even more awesome version of yourself.
- Demonstrated proficiency in cybersecurity and/or IT risk management areas, ranging from Attack Surface Management, Security Detection & Response, Cyber Threat Management and Identity & Access Management.
- Strong analytical and problem-solving skills to translate complex cybersecurity and/or IT risk management requirements into tangible solutions and actions in a third-party risk management context, and to strengthen TIPM foundation as a prerequisite for effective management of cyber and IT security third party risk.
- Proven ability to partner with third party contract owners, client account managers, product management, Procurement, Legal, ODCR, data management and other non-CISO stakeholders to instate effective third-party oversight and to enable WB business by addressing WB client-initiated security demand towards ING.
- Excellent communication and interpersonal skills, including the ability to convey complex cybersecurity, IT risk management and other TIPM concepts to non-technical stakeholders.
- Holds the ING Orange Code in high regard and applies a variety of Orange behaviours to deliver tangible results.
No one matches every requirement perfectly. If this role feels like the right next step for you, we encourage you to apply.
We'd love to learn more about your leadership experience, the impact you've made and what you'd bring to the team.
Rewards and benefits
We want to make sure that it’s possible for you to strike the right balance between your career and your private life. Find out more about our employment conditions.
The benefits of working with us at ING include:
- 25-28 vacation days depending on contract
- Pension scheme
- 13th month salary
- 8% Holiday payment
- Hybrid working
- Personal growth and challenging work with endless possibilities
- An informal working environment with innovative colleagues
About us
Curious about how ING empowers people and businesses to move forward?
Discover what we do and what we can offer you.
Questions?
Please visit our Frequently Asked Questions section to find some answers on questions you might have.
Contact the recruiter attached to the advertisement. Want to apply directly? Please upload your CV and motivation letter by clicking the ‘Apply’ button.