Build your career on Magnet.me
Create a profile and receive smart job recommendations based on your liked jobs.
Job description
We are looking for a motivated researcher interested in collecting and analyzing various types of data from within partner organizations—such as interviews, surveys, ticketing systems, and incident logs—to understand the organizational and technical practices around patching security in organizations.
We are in an age of regular news stories about vulnerabilities in organization IT being exploited, for theft of customer data or injection of malware and ransomware. The costs seem to be rising, yet organizations still do not appear to be patching their IT systems and keeping software up-to-date.
The reality is that organizations face a painful dilemma: patch too soon and incur potential downtime and failures; patch too late and get compromised by attacks. As a result, organizations take a long time to patch even critical security vulnerabilities. The way to get out of this catch-22 is to radically change the risk governance of patching. That is the objective of the NWO-funded THESEUS project.
In this project, we work with real-world partner organizations, such as KLM-AirFrance, Rijkswaterstaat, City of Amsterdam, City of The Hague, KPN, and the National Cyber Security Center. We engage with risk management and patch management professionals to understand the challenges they face. We also engage with organizational decision-makers and the wider workforce to rationalize their perspective on the benefits and disruptions of keeping systems patched in a timely manner. This work complements efforts at partner universities to explore automatic vulnerability and patch triaging, risk profiling, and legal instruments such as incentive mechanisms.
Your PhD, degree(s) and experiences could be from social science or an interdisciplinary program, but also from information systems, telecommunications or computer science. You could have a background in social and organizational research and be willing to learn about the technical factors at play. Or vice versa: you could be a technically trained person with an interest in the social aspects. You would work in close collaboration with researchers from computer science and social science disciplines.
The researcher will be part of an interdisciplinary team of over 20 scientists who jointly research cybersecurity issues. The team consists of people from different disciplines, countries, and backgrounds. The project also offers the opportunity to collaborate with real-world companies in government, healthcare, and various other sectors, working closely with security managers and IT management teams. We also work with government organizations and leading solutions providers who are developing policies and practices for organizations. The candidate will have the opportunity to present their work at international conferences, to conduct research abroad and to collaborate with leading researchers working towards a secure digital future.
Job requirements
TU Delft (Delft University of Technology)
TU Delft is a top international university combining science, engineering and design. It delivers world-class results in education, research and innovation to address challenges in the areas of energy, climate, mobility, health and digital society.
Faculty Technology, Policy and Management
The Faculty of TPM contributes to solving complex technical-social issues, such as energy transition, mobility, digitalisation, water management and (cyber) security. TPM combines insights from engineering, social sciences and the humanities, is internationally oriented and has an extensive network of knowledge institutions, companies, social organisations and governments.
Conditions of employment
As part of knowledge security, TU Delft conducts a risk assessment during the recruitment of personnel. This is done, among other things, to prevent the unwanted transfer of sensitive knowledge and technology. The assessment is based on information provided by candidates themselves, such as their motivation letter and CV, and takes place at the final stages of the selection process. When the outcome of the assessment is negative, the candidate will be informed. The processing of personal data in the context of the risk assessment is carried out on the legal basis of the GDPR: performing a public task in the public interest.
De fascinatie voor science, design en engineering is wat ruim 13000 bachelor & masterstudenten en 5000 medewerkers van de TU Delft drijft. De Technische Universiteit Delft is niet alleen de oudste, maar ook de grootste technische universiteit van Nederland: een universiteit die continu op zoek is naar jou als (inter)nationaal talent om het onderzoek en onderwijs van deze unieke instelling…
De fascinatie voor science, design en engineering is wat ruim 13000 bachelor & masterstudenten en 5000 medewerkers van de TU Delft drijft. De Technische Universiteit Delft is niet alleen de oudste, maar ook de grootste technische universiteit van Nederland: een universiteit die continu op zoek is naar jou als (inter)nationaal talent om het onderzoek en onderwijs van deze unieke instelling op topniveau te houden. Met ongeveer 5.000 medewerkers is de Technische Universiteit Delft de grootste werkgever in Delft. De acht faculteiten, de unieke laboratoria, onderzoeksinstituten, onderzoeksscholen en de ondersteunende universiteitsdienst bieden de meest uiteenlopende functies en werkplekken aan. De diversiteit bij de TU Delft biedt voor iedereen mogelijkheden. Van Hoogleraar tot Promovendus. Van Beleidsmedewerker tot ICT'er.
View what's on offer:
Change language to: Dutch
This page is optimised for people from the Netherlands. View the version optimised for people from the UK.