For Technische Universiteit Eindhoven (TU/e), we are looking for a Project Manager Secure Modern Workplace (Digital Safety).

Note: In the context of the Dutch DBA Act (Wet DBA), this assignment can only be performed on a secondment/payroll basis. ICQ Groep offers various employment options for this purpose, including an attractive salary and excellent employment conditions. Interested in learning more about these opportunities? Visit:
https://www.icq-groep.nl/over-icq/nieuws/actueel/update-wet-dba-wij-zijn-er-klaar-voor-jij-ook

Assignment:
The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. The TU/e has identified four strategic focus areas within its Digital Safety Program. The Digital Safety Program aims to significantly strengthen the university’s cyber resilience, governance, identity & data security, endpoint security and overall control framework, while maintaining the open and collaborative nature of an academic institution. To support this transformation, TU/e is looking for a highly experienced project manager to execute the Secure Modern Workplace initiative within the scope of the Digital Safety Program.

Secure Modern Workplace
The Secure Modern Workplace project will define, design and implement a future-ready workplace model for TU/e. The project must balance strong central security standards with the specific needs of faculties, researchers, local IT teams and specialized academic environments. A key objective is to co-create new workplace types with the faculties, including the standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace. The project also includes the roll-out of Mobile Device Management and the use of Microsoft capabilities such as Intune, Autopilot, Company Portal, Entra ID, Conditional Access, device compliance and Microsoft Defender for Endpoint.

As Project Manager you are responsible for delivering the Secure Modern Workplace initiative within the Digital Safety Program. The objective is to establish a controlled, automated and service-oriented workplace model that reduces unmanaged risk, improves user experience and lowers operational support effort. You will coordinate co-creation with faculties and local IT, translate functional and technical requirements into service building blocks, and steer the design, pilot and rollout of the agreed workplace concepts and MDM capabilities.

Key responsibilities include:
• Develop and maintain the project plan, roadmap, milestones, dependencies, risks and budget.
• Organize and facilitate faculty co-creation workshops and stakeholder alignment sessions.
• Coordinate the definition of workplace types: standard secure, research, Linux, macOS and BYOD.
• Translate workplace requirements into service building blocks, operating model choices and support boundaries.
• Coordinate the MDM rollout and Microsoft endpoint management design, including Intune and related Microsoft products.
• Ensure alignment with security baselines, identity, conditional access, application packaging and support processes.
• Set up governance, escalation, exception handling, acceptance criteria and operational handover.
• Coach, involve and train an internal project manager to support knowledge transfer and future ownership.

The department and organization
TU/e consists of various departments and faculties where education and research are conducted, supported by several central services. The candidate will work as project manager within the Digital Safety Program, primarily with LIS workplace management, end-user services, architecture, security operations and service management teams. A substantial part of the assignment is to work directly with faculty stakeholders, researchers and local IT teams to create buy-in, validate requirements, define workable service options and ensure a smooth transition into the new Secure Modern Workplace support model.

You report to the Program Manager Digital Safety.

Description of the work and Key Deliverables:
• Approved Project Approach: A clear project plan covering scope, phases, milestones, dependencies, risks, resources, decision points and budget control.
• Faculty Co-Creation and Adoption Approach: A structured approach for involving faculty leadership, researchers, local IT and workplace specialists through workshops, taskforces and decision preparation.
• Workplace Type Definition: A validated definition of the main workplace types: standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace, including eligibility and support boundaries.
• Secure Standard Workplace Design: A design for the standard secure workplace, including device management, security baseline, user experience, application access and operational support model.
• Research Workplace Model: A model for research environments that preserves required flexibility while defining security controls, 7support limitations, recovery-to-baseline principles and exception handling.
• Linux and macOS Workplace Model: A practical design for managing Linux and macOS workplaces, including management tooling, ownership, patching, security baseline, support model and operational feasibility.
• BYOD Workplace and MDM Model: A design for BYOD access, mobile device management, device compliance, enrolment, remote wipe, application access and privacy-sensitive operating principles.
• Microsoft Endpoint Management Roadmap: A detailed roadmap for using Intune, Autopilot, Company Portal, Entra ID, Conditional Access, compliance policies and Microsoft Defender for Endpoint in the target workplace model.
• MDM Roll-out and Migration Plan: A phased rollout plan for MDM adoption, including pilots, migration waves, communication, readiness criteria, user impact and operational dependencies.
• Application Packaging and Light Rationalisation Approach: An approach for application packaging, scripting, Company Portal publication and light rationalisation of the application landscape.
• Security Baseline and Compliance Model: A minimum management and security baseline covering device compliance, local admin approach, patching, endpoint protection, vulnerability visibility, logging and monitoring.
• IAM and Conditional Access Alignment: Alignment with IAM, identity lifecycle, device identity, user identity, RBAC/ABAC principles, conditional access and privileged access requirements.
• Exception and Risk Acceptance Process: A formal process for justified exceptions, including ownership, compensating measures, approval, expiry dates and review cycles.
• Service Building Blocks and Operating Model: Translation of the workplace concepts into service building blocks, service catalogue descriptions, responsibilities, support levels, handover and BAU operating model.
• Pilot Implementation and Evaluation: A completed pilot with selected faculties or user groups, including lessons learned, refined processes, confirmed service definitions and recommendations for wider rollout.
• Knowledge Transfer and Internal Project Manager Coaching: Active involvement, coaching and training of an internal project manager, including shadowing, documentation, decision logic and practical handover of project management routines.

The ideal candidate has extensive experience leading complex modern workplace, endpoint management, cybersecurity and service design projects in decentralized organizations. The role requires strong stakeholder management, the ability to balance security with academic freedom, and the credibility to work with faculty leadership, researchers, local IT, LIS, architects, security specialists and senior management.

Requirements:
• You are not a student or employee of TU/e.
• Fluent in English mandatory.
• Dutch required language for speaking.
• Work location is Eindhoven (minimal 3 days).

Key Competencies:
• Project Management: Able to structure and deliver a complex, multi-phase workplace transformation with clear milestones, dependencies, risks, governance and measurable outcomes.
• Stakeholder Management and Co-Creation: Strong ability to engage faculty leadership, researchers, local IT, LIS, Security Operations, architecture and service management teams with different interests and maturity levels.
• Modern Workplace and Endpoint Management Expertise: Extensive experience with workplace transformation, endpoint management, device lifecycle, automation, deployment, remote management and support model redesign.
• Microsoft Technology Knowledge: Strong working knowledge of Microsoft endpoint and security products, including Intune, Autopilot, Company Portal, Entra ID, Conditional Access, compliance policies and Microsoft Defender for Endpoint.
• MDM and BYOD Understanding: Understands MDM/MAM concepts, device compliance, enrolment, remote wipe, privacy considerations and the balance between secure access and user flexibility.
• Service Design and Service Building Blocks: Able to translate technical and functional requirements into reusable service building blocks, service catalogue elements, responsibilities, support boundaries and operating model choices.
• Organizational Sensitivity: Understands how to operate effectively in a decentralized and autonomous academic environment, where influence, trust and credibility are often more important than formal authority.
• Change and Adoption Management: Able to position the initiative as a service and user-experience improvement rather than only a technology rollout, and to build acceptance for new standards, controls and responsibilities.
• Cybersecurity and Risk-Based Thinking: Understands endpoint security, hardening, local admin reduction, vulnerability management, monitoring, data protection touchpoints and risk-based prioritization.
• Facilitation and Decision-Making: Skilled in facilitating workshops, resolving conflicting views, clarifying ownership and preparing decisions for architecture, program and steering governance.
• Coaching and Knowledge Transfer: Comfortable taking an internal project manager along, providing coaching, practical training and structured knowledge transfer during the assignment.
• Pragmatism and Delivery Focus: Balances security, architecture and service objectives with operational feasibility, capacity constraints and the realities of research and faculty environments.
• Communication Skills: Communicates complex workplace, security and service management topics in clear, accessible language for both technical and non-technical audiences.

General Information:
Location: Eindhoven
Start date: 12-10-2026
End date: 12-04-2027
Duration: 6 months
Extension option: Yes
Workload: 32 hours per week
Rate: Competitive
Application deadline: 28-09-2026
Closing time: 13:00
Interview: 08-10-2026 (09:00-13:00)

Additional Information:
How to Make Your Application Stand Out:
CV in top form: Submit your CV in Word format, written in the language of the assignment, and presented in a professional and easy-to-read layout. Please keep your CV to a maximum of 7 pages. Attention to detail is highly valued.
Availability, clearly state: Your earliest availability date; The number of hours per week you are available to work; Any planned holidays or periods of absence;
Rate or Monthly Salary: Please specify your hourly rate (excluding VAT) or monthly salary for this assignment, including travel expenses and any accommodation costs, if applicable.

Keywords: Project Manager Secure Modern Workplace (Digital Safety)



EMPLOYER:

Company:
ICQ Groep
contact person:
Erik Mensinga
type:
contracting, temp job
status:
open
location:
Eindhoven
region:
Noord-Brabant
hourly rate:
Marktconform
start date:
12-10-2026
reference:
ITC
duration:
6 months
prolongation:
Yes
hours per week:
32 hours
posted:
09-16-2026 16:12:29