Business Analyst – 3rd Party Software Supply Chain Security

Salt Digital Recruitment

Brussel

Sur place

EUR 92 000 - 148 000

Plein temps

14 jours+
Générateur de candidature

Obtenez une réponse de ce recruteur — un CV et une lettre de motivation adaptés exactement à ce qu’on recherche pour ce poste.

Passez les filtres ATS

Résumé du poste

Salt Digital Recruitment seeks a Business Analyst to help design and implement governance, processes and data models for software supply chain security under DORA. You will collaborate with Cybersecurity, IT Risk, Supply Chain and IT Operations to ensure secure development, maintenance and monitoring of supplier software.

The role emphasizes creating a practical framework for third-party risk, establishing accountability, dashboards and KPIs, and enabling effective incident response with

Qualifications

  • Experience with BPMN process design and improvement.
  • Designing IT governance frameworks (RACI, TO, ITIL, COBIT).
  • Knowledge of security governance and risk management (CISM, ISO 27001).
  • Strong stakeholder management, coordination and communication skills.
  • Experience in regulated environments, ideally financial services or critical infrastructure.

Responsabilités

  • Contribute to the design of the 3rd Party Software Supply Chain Security framework (Q4 2025) and support its deployment during 2026.
  • Define governance and operating structures (RACI, committees, reporting lines) for supplier software security management.
  • Design and document processes for supplier and subcontractor risk management, aligned with DORA and internal security requirements.
  • Develop and validate the data model for mapping suppliers, software, and open-source components.
  • Coordinate stakeholders across divisions to align on scope, priorities, and execution.
  • Define monitoring and reporting requirements, including dashboards and KPIs.
  • Support incident response procedures involving third-party security events.
  • Ensure integration of new processes into existing supplier governance and review structures.

Connaissances

BPMN process design
IT governance
Security governance
Stakeholder management
Regulatory compliance
Cross-functional collaboration

Description du poste

Business Analyst - 3rd Party Software Supply Chain Security, DORA,RISK, Security

Duration: 12 months, with potential for extension.

Rate: 500-800 per day.

Eligibility: Candidates must be based in a country where the organisation has offices - Belgium, France, Netherlands, or the UK. Important: UK-based candidates will only be considered if engaged via an accredited umbrella company.

On-site requirement: Minimum 8 days per month on site, including 8-10 days per year in Brussels for project workshops and key governance meetings.

About the Project

This project aims to strengthen the organisation's software supply chain security and ensure that all third-party providers - both on-premise and SaaS - comply with the organisation's security standards and regulatory obligations under the Digital Operational Resilience Act (DORA). The initiative will deliver new capabilities to manage and monitor security risks linked to external software suppliers, focusing on:

  • Ensuring supplier-developed or maintained software follows secure development practices.
  • Building and maintaining an inventory of software components and open-source libraries.
  • Identifying and managing vulnerabilities within supplier-delivered software.
  • Defining and coordinating incident response procedures when third parties are involved.
  • Establishing governance, reporting, and monitoring for supplier and subcontractor security.
Role Purpose

As a Business Analyst, you will contribute to the design and implementation of new governance, processes, and data models that enable the operational management of software supply chain security. You will collaborate across Cybersecurity, IT Risk, Supply Chain, and IT Operations to design practical, sustainable processes that ensure supplier software is securely developed, maintained, and monitored.

Key Responsibilities
  • Contribute to the design of the 3rd Party Software Supply Chain Security framework (Q4 2025) and support its deployment during 2026.
  • Define governance and operating structures (RACI, committees, reporting lines) for supplier software security management.
  • Design and document processes for supplier and subcontractor risk management, aligned with DORA and internal security requirements.
  • Develop and validate the supporting data model for mapping suppliers, software, and open-source components.
  • Coordinate stakeholders across multiple divisions to align on scope, priorities, and execution.
  • Define monitoring and reporting requirements, including dashboards, KPIs, and operational follow-up mechanisms.
  • Support the design of incident response procedures involving third-party security events.
  • Ensure integration of new processes into existing supplier governance and review structures.
Required Skills & Experience Essential
  • Strong experience in process design, documentation, and improvement using methodologies such as BPMN.
  • Proven experience designing IT governance frameworks (RACI, Target Operating Model, ITIL, COBIT).
  • Knowledge of security governance and risk management frameworks (CISM, ISO 27001, or equivalent).
  • Strong stakeholder management, coordination, and communication skills.
  • Ability to balance security, operational efficiency, and regulatory compliance in process design.
  • Experience within a regulated environment, ideally in financial services or critical infrastructure.
Desirable
  • Understanding of software supply chain security, including SBOMs, vulnerability scanning, and dependency management.
  • Experience working on DORA compliance or similar regulatory frameworks.
  • Prior involvement in cross-functional cybersecurity or IT risk transformation projects.

*Rates depend on experience and client requirements

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Business Analyst, 3rd-Party Software Supply Chain (DORA)
Business Analyst, 3rd-Party Software Supply Chain (DORA)

Salt Digital Recruitment • Brussel

Sur place
EUR 92 000 - 148 000
Business Analyst DORA
Business Analyst DORA

Taleo Consulting • Brussel Hoofdstad

Sur place
EUR 55 000 - 75 000
Security Analyst
Security Analyst

Next Ventures • Brussel

Sur place
EUR 90 000 - 150 000
Service Management Specialist
Service Management Specialist

Montash • Brussel

Sur place
EUR 111 000 - 185 000
Data Business Analyst Consultant
Data Business Analyst Consultant

keystone-solutions • Brussel Hoofdstad

Sur place
EUR 50 000 - 70 000
Business Analyst DORA
Business Analyst DORA

Capco • Brussel

Hybride
EUR 55 000 - 75 000
Meal vouchers
Insurances
Car or mobility budget
+2
Business Analyst — Data Source Discovery and Governance for NATO with security clearance
Business Analyst — Data Source Discovery and Governance for NATO with security clearance

Wlgroup • Eigenbrakel

Sur place
EUR 65 000 - 90 000
CISO Officer (TPRM)
CISO Officer (TPRM)

act digital • Brussel

Hybride
EUR 65 000 - 85 000
Business Analyst – Process Optimization & Data Management
Business Analyst – Process Optimization & Data Management

Pauwels Consulting • Anderlecht

Sur place
EUR 55 000 - 75 000
Strategic Demand Analyst
Strategic Demand Analyst

keystone-solutions • Brussel Hoofdstad

Sur place
EUR 50 000 - 80 000