Third Party Risk Consultant

Stott and May Inc.

Brussel Hoofdstad

Hybride

EUR 90 000 - 130 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV et une lettre de motivation personnalisés en environ une minute.

Passez les filtres ATS

Résumé du poste

A major financial services organisation in Belgium is seeking a Senior IT & Cyber Third-Party Risk Expert to join its Governance, Risk and Compliance team. The role is hybrid, with 50% on-site and 50% remote, focusing on evaluating and mitigating IT and cyber risks of third-party services, including cloud solutions.

You will work with cyber defence, security architecture, business continuity, data protection and procurement to ensure risk is assessed, mitigated and monitored across the supplier

Qualifications

  • 10+ years in information security and IT & cyber risk management.
  • Extensive experience with third-party risk assessments and cloud security.
  • Knowledge of ISO 27001, SOC 2, NIST, OWASP.
  • Financial services experience in a large corporate environment.
  • Ability to review and negotiate IT and cyber clauses in supplier contracts.
  • Strong process design and business analysis skills.
  • Experience delivering risk topic presentations and training.

Responsabilités

  • Conduct third-party IT and cyber risk assessments during due diligence.
  • Assess cloud solutions with focus on security, data protection and resilience.
  • Review vulnerability and penetration testing reports against security best practice and regulatory requirements.
  • Review and negotiate IT and cyber clauses in supplier contracts.
  • Coordinate onsite audits and track remediation.
  • Monitor supplier security posture and governance via reports.
  • Lead ICT risk and cyber committees with business representatives and supplier security teams.
  • Build and maintain ICT risk dashboards and summary reports for senior management.
  • Collaborate with cyber defence, security architects, data protection officers, procurement and legal.

Connaissances

Info security
Third-party risk
Cloud security
Regulatory compliance
Audit methodologies
Financial services experience
Contract clauses
Business analysis
Presentations
Training delivery

Formation

Master's degree in IT/cybersecurity or risk management

Outils

ServiceNow

Description du poste

IT & Cyber Third-Party Risk Expert – Job Description
Role overview

A major financial services organisation in Belgium is hiring a senior IT & Cyber Third-Party Risk Expert. The role is hybrid, with 50% on site.

The Governance, Risk and Compliance team ensures robust IT and cyber risk management across the organisation. It has a strong focus on third-party technology risk. The team helps IT and business functions assess, mitigate and monitor the risks from internal and external suppliers, in line with internal IT and information security policies.

You will evaluate and manage the cyber and operational risks of third-party services, particularly cloud solutions. You will work with cyber defence, security architecture, business continuity, data protection and procurement teams.

Key responsibilities
Third-party risk assessment and due diligence
  • Run IT and cyber risk assessments of internal and external suppliers during due diligence, covering cyber posture, IT controls, and regulatory and contractual compliance
  • Assess cloud solutions (SaaS, hosted services, AWS and similar) with a deep focus on security, data protection and resilience
  • Review vulnerability and penetration testing reports against security best practice and regulatory requirements
Contract and negotiation support
  • Review, challenge and negotiate IT and cyber clauses in supplier contracts so they meet risk appetite and compliance standards
  • Work with Procurement, Legal and the business to build risk mitigation into contracts
Onsite audit coordination and follow-up
  • Steer IT and cyber onsite audits performed by external auditors, including scope and execution
  • Review audit reports, validate findings and track supplier remediation plans
  • Escalate critical IT and cyber risks and drive them to timely resolution
Continuous monitoring and governance
  • Monitor supplier security posture through periodic reviews of security reports, incident responses and attestations (ISO 27001, SOC, NIST)
  • Lead ICT risk and cyber committees with business representatives and supplier security teams
  • Build and maintain ICT risk dashboards and summary reports for senior management
Cross-functional collaboration
  • Cyber defence teams, on threat intelligence and incident response
  • Security architects, on technical controls and cloud security frameworks
  • Business and IT continuity experts, on supplier resilience and disaster recovery
  • Data protection officers, on GDPR and privacy compliance
  • Procurement and Legal, on supplier selection and contract lifecycle
Process and methodology
  • Evolve third-party risk frameworks, tools and methods in line with group standards, best practice and regulation
  • Develop ICT risk assessment templates, audit guidelines and reporting standards for expert and non-expert audiences
Required experience and skills
Mandatory
  • 10+ years in information security and IT & cyber risk management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS)
  • Hands-on third-party IT and security assessments and supplier risk evaluations
  • Application security, vulnerability management, penetration testing and audit methodologies (ISO 27001, SOC 2, NIST, OWASP)
  • Financial services experience in a large corporate environment
  • Reviewing and amending IT and cyber clauses in supplier contracts
  • Process design and business analysis in IT and security risk management
  • Delivering presentations and training on risk topics
  • Strong IT background with exposure to operational and security risk
Preferred
  • Knowledge of control frameworks and audit methodologies
  • Familiarity with GRC tooling (ServiceNow)
Soft skills
  • Strong analysis and synthesis: turning complex technical risk into clear, actionable insight for management
  • Clear communication and influence with technical experts, business stakeholders and suppliers
  • Autonomous, proactive and structured, able to juggle priorities in a multicultural environment
  • Negotiation and conflict-resolution skills for contract and remediation discussions
  • Able to adapt to stakeholder expectations while respecting established processes
  • Able to mentor and coach others
Languages, education and setup
  • French – Fluent (mandatory)
  • English – Fluent (mandatory)
  • Dutch – Fluent (strong plus)
  • Education – Master's in IT, cybersecurity or risk management, or equivalent experience
  • Certifications – Optional: CISSP, CISM, CIPP, CCSK
  • Location – Belgium, hybrid: 50% on site, 50% remote
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

IT & Cyber Third Party Risk Assessor
IT & Cyber Third Party Risk Assessor

Huxley • Brussel

Hybride
EUR 60 000 - 90 000
IT and Cyber Third Party Risk Assessor (Expert) - BNP Paribas Fortis
IT and Cyber Third Party Risk Assessor (Expert) - BNP Paribas Fortis

Adjugo • Brussel Hoofdstad

Hybride
EUR 95 000 - 130 000
Senior Third-Party Risk & Cloud Security Expert
Senior Third-Party Risk & Cloud Security Expert

Stott and May Inc. • Brussel Hoofdstad

Hybride
EUR 90 000 - 130 000
IT and Cyber Third Party Risk Assessor
IT and Cyber Third Party Risk Assessor

OPTIMUS IT SERVICES • Brussel

Sur place
EUR 90 000 - 130 000
Hybrid IT & Cyber Third-Party Risk Assessor (Remote)
Hybrid IT & Cyber Third-Party Risk Assessor (Remote)

ictjob.be • Belgique

Hybride
EUR 70 000 - 90 000
CISO Officer (TPRM)
CISO Officer (TPRM)

act digital • Brussel

Hybride
EUR 65 000 - 85 000
IT and Cyber Third Party Risk Assessor Consultant
IT and Cyber Third Party Risk Assessor Consultant

Keystone Solutions • Brussel Hoofdstad

Hybride
EUR 90 000 - 130 000
On-site at client
Diverse projects
Professional development
+1
IT And Cyber Third Party Risk Assessor
IT And Cyber Third Party Risk Assessor

Rhox • Brussel

Sur place
EUR 90 000 - 130 000
IT & Cyber Third-Party Risk Assessor (Hybrid)
IT & Cyber Third-Party Risk Assessor (Hybrid)

Keystone Solutions • Brussel Hoofdstad

Hybride
EUR 90 000 - 130 000
On-site at client
Diverse projects
Professional development
+1
IT & Cyber Third Party Risk Management Expert - HQ Brussels
IT & Cyber Third Party Risk Management Expert - HQ Brussels

Editx • Brussel

Sur place
EUR 90 000 - 120 000