Open role
Information Security Officer - Team Suppliers & Customers
PostNL N.V.
About the role
As Information Security Officer (Third-Party Risk Management) you are responsible for managing and strengthening PostNL's security posture across suppliers and customer-facing partnerships. You combine cybersecurity expertise with stakeholder management skills, ensuring that third-party risks are identified, assessed and mitigated in a structured and pragmatic way.
As an Information Security Officer (ISO) focused on Third-Party Risk Management (TPRM), you will be part of our Cyber Security Office (CSO) within the Suppliers & Customers domain. This domain is responsible for managing cyber risks related to suppliers, customers, and strategic partners. In this role, you help ensure that our external partnerships meet security requirements while supporting business continuity and operational goals. You understand that security should enable the business. You will perform third-party security risk assessments, including due diligence, onboarding, and periodic reassessments. Also you evaluate supplier compliance against ISO 27001, NIST Cyber Security Framework (CSF), and our internal security policies.You define, coordinate, and monitor mitigation plans together with business owners and suppliers. Also you support audits and evidence-gathering activities related to supplier security and compliance.
You balance risk mitigation, regulatory compliance, and operational feasibility. By building strong relationships with internal and external stakeholders, you help create a secure and resilient supplier ecosystem that supports our business ambitions. You contribute to the further development and improvement of our Third-Party Risk Management framework, processes, and tooling.
The Senior Information Security Officer position is typically positioned within salary scale 11. However, for candidates who can demonstrate relevant team-lead experience and capabilities, the role may be expanded to include team lead responsibilities and be evaluated at salary scale 12.
What you'll do
Strategic impact: Third-party risk is high on the board agenda. Your work directly contributes to resilience and compliance. Complex stakeholder landscape: You operate at the intersection of IT, business, legal and suppliers. Maturity growth: You contribute to further professionalizing TRPM within a large, regulated organization. Visibility: You interact with senior management and external strategic partners. Development: Opportunity to deepen expertise in regulatory frameworks (NIS2, DORA-like principles, supply chain security).
What you'll bring
Bachelor or Master degree in IT, Cybersecurity, Risk Management or Business Administration.
3–6+ years of relevant experience in Information Security or Third-Party Risk Management.
Experience with supplier risk assessments and vendor security governance.
Strong knowledge of ISO27001, NIST CSF, CIS Controls and audit processes.
Understanding of NIS2, GDPR and supply chain risk requirements.
Strong stakeholder management and negotiation skills.
Ability to operate independently at medior/senior level.
Relevant certifications (CISSP, CISM, CRISC, CISA) are considered a plus.
What's on offer
We support our people with a motivating work environment and enthusiastic colleagues, a commitment to promoting from within and a belief that every employee deserves a productive life outside of work.
This position is on scale 11 (between € 4.588,- and € 6.498,- a month), depending on experience.
Full-time working week of 37 hours.
8% holiday pay and 25 holiday days (full-time).
Flexible working hours to support work/life balance.
Hybrid working model from home and from our head office next to Den Haag – Hollands Spoor station.
NS Business Card for business travel and commuting.
Collective health insurance and pension via the PostNL pension fund.
Strong internal training and development opportunities.
About the company
You are part of the Suppliers & Customers domain, collaborating closely with:
DevOps teams across business units
Cloud platform teams
Enterprise and solution architects
Business Information Security Officers
Privacy and Data Governance teams
You play a key role in increasing the information security maturity of suppliers, collaborate with customers, and manage third-party risks across the supply chain.