In het kort: Je gaat als projectmanager de Secure Modern Workplace binnen het Digital Safety Program definiëren, ontwerpen en uitrollen, met faculteiten samenwerken, MDM en Microsoft endpoint management implementeren en een veilig, toekomstbestendig werkplekmodel realiseren.
Description for this hiring position
The Eindhoven University of Technology (TU/e) is within scope of the NIS2 directive and has strategically committed to achieving ISO27001 compliance maturity in the coming years. The TU/e has identified four strategic focus areas within its Digital Safety Program.
The Digital Safety Program aims to significantly strengthen the university’s cyber resilience, governance, identity & data security, endpoint security and overall control framework, while maintaining the open and collaborative nature of an academic institution.
To support this transformation, TU/e is looking for a highly experienced project manager to execute the Secure Modern Workplace initiative within the scope of the Digital Safety Program.
Secure Modern Workplace
The Secure Modern Workplace project will define, design and implement a future-ready workplace model for TU/e. The project must balance strong central security standards with the specific needs of faculties, researchers, local IT teams and specialized academic environments.
A key objective is to co-create new workplace types with the faculties, including the standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace.
The project also includes the roll-out of Mobile Device Management and the use of Microsoft capabilities such as Intune, Autopilot, Company Portal, Entra ID, Conditional Access, device compliance and Microsoft Defender for Endpoint.
Role Profile – Workplace Engineer Subject Matter Expert
The Project Manager is responsible for delivering the Secure Modern Workplace initiative within the Digital Safety Program. The objective is to establish a controlled, automated and service-oriented workplace model that reduces unmanaged risk, improves user experience and lowers operational support effort.
The Project Manager will coordinate co-creation with faculties and local IT, translate functional and technical requirements into service building blocks, and steer the design, pilot and rollout of the agreed workplace concepts and MDM capabilities.
Key responsibilities include:
– Develop and maintain the project plan, roadmap, milestones, dependencies, risks and budget.
– Organize and facilitate faculty co-creation workshops and stakeholder alignment sessions.
– Coordinate the definition of workplace types: standard secure, research, Linux, macOS and BYOD.
– Translate workplace requirements into service building blocks, operating model choices and support boundaries.
– Coordinate the MDM rollout and Microsoft endpoint management design, including Intune and related Microsoft products.
– Ensure alignment with security baselines, identity, conditional access, application packaging and support processes.
– Set up governance, escalation, exception handling, acceptance criteria and operational handover.
– Coach, involve and train an internal project manager to support knowledge transfer and future ownership.
The ideal candidate has extensive experience leading complex modern workplace, endpoint management, cybersecurity and service design projects in decentralized organizations. The role requires strong stakeholder management, the ability to balance security with academic freedom, and the credibility to work with faculty leadership, researchers, local IT, LIS, architects, security specialists and senior management.
The department and organization
TU/e consists of various departments and faculties where education and research are conducted, supported by several central services. The candidate will work as project manager within the Digital Safety Program, primarily with LIS workplace management, end-user services, architecture, security operations and service management teams.
A substantial part of the assignment is to work directly with faculty stakeholders, researchers and local IT teams to create buy-in, validate requirements, define workable service options and ensure a smooth transition into the new Secure Modern Workplace support model.
You report to the Program Manager Digital Safety.
Description of the work and Key Deliverables
– Approved Project Approach: A clear project plan covering scope, phases, milestones, dependencies, risks, resources, decision points and budget control.
– Faculty Co-Creation and Adoption Approach: A structured approach for involving faculty leadership, researchers, local IT and workplace specialists through workshops, taskforces and decision preparation.
– Workplace Type Definition: A validated definition of the main workplace types: standard secure workplace, research workplace, Linux workplace, macOS workplace and BYOD workplace, including eligibility and support boundaries.
– Secure Standard Workplace Design: A design for the standard secure workplace, including device management, security baseline, user experience, application access and operational support model.
– Research Workplace Model: A model for research environments that preserves required flexibility while defining security controls, support limitations, recovery-to-baseline principles and exception handling.
– Linux and macOS Workplace Model: A practical design for managing Linux and macOS workplaces, including management tooling, ownership, patching, security baseline, support model and operational feasibility.
– BYOD Workplace and MDM Model: A design for BYOD access, mobile device management, device compliance, enrolment, remote wipe, application access and privacy-sensitive operating principles.
– Microsoft Endpoint Management Roadmap: A detailed roadmap for using Intune, Autopilot, Company Portal, Entra ID, Conditional Access, compliance policies and Microsoft Defender for Endpoint in the target workplace model.
– MDM Roll-out and Migration Plan: A phased rollout plan for MDM adoption, including pilots, migration waves, communication, readiness criteria, user impact and operational dependencies.
– Application Packaging and Light Rationalisation Approach: An approach for application packaging, scripting, Company Portal publication and light rationalisation of the application landscape.
– Security Baseline and Compliance Model: A minimum management and security baseline covering device compliance, local admin approach, patching, endpoint protection, vulnerability visibility, logging and monitoring.
– IAM and Conditional Access Alignment: Alignment with IAM, identity lifecycle, device identity, user identity, RBAC/ABAC principles, conditional access and privileged access requirements.
– Exception and Risk Acceptance Process: A formal process for justified exceptions, including ownership, compensating measures, approval, expiry dates and review cycles.
– Service Building Blocks and Operating Model: Translation of the workplace concepts into service building blocks, service catalogue descriptions, responsibilities, support levels, handover and BAU operating model.
– Pilot Implementation and Evaluation: A completed pilot with selected faculties or user groups, including lessons learned, refined processes, confirmed service definitions and recommendations for wider rollout.
– Knowledge Transfer and Internal Project Manager Coaching: Active involvement, coaching and training of an internal project manager, including shadowing, documentation, decision logic and practical handover of project management routines.