IT & Cyber Third Party Risk Assessor

Context

The Governance, Risk and Compliance team is responsible for ensuring robust IT and Cyber Risk Management across a large financial services organization, with a strong focus on Third-Party Technology Risk Management (TPTRM). As an IT & Cyber Third Party Risk Assessor, you will assess, mitigate and monitor cybersecurity and operational risks associated with intragroup and external suppliers, particularly cloud-based solutions, while ensuring compliance with internal IT and Information Security policies.

Responsibilities

  • Conduct comprehensive IT and Cyber risk assessments of intragroup and external third-party suppliers during due diligence.
  • Evaluate suppliers’ cybersecurity posture, IT controls and compliance with regulatory and contractual requirements.
  • Assess cloud-based solutions, including SaaS, hosting services and AWS environments, with a focus on security, data protection and resilience.
  • Review vulnerability assessments and penetration testing reports.
  • Review, challenge and negotiate IT and cybersecurity clauses in supplier contracts.
  • Collaborate with Procurement, Legal and Business teams to integrate appropriate risk mitigation measures into contracts.
  • Coordinate IT and Cyber onsite audits performed by external auditors.
  • Review audit reports, validate findings and monitor supplier remediation plans.
  • Escalate critical IT and Cyber risks and support their timely resolution.
  • Perform continuous monitoring of third-party IT and security posture.
  • Review security reports, incident responses and compliance attestations such as ISO 27001, SOC and NIST.
  • Lead ICT Risk and Cyber Committees with internal stakeholders and supplier security teams.
  • Develop ICT risk dashboards and management reports highlighting risks, trends and recommendations.
  • Collaborate with Cyber Defense, Security Architecture, Business Continuity, Data Protection, Procurement and Legal teams.
  • Contribute to the continuous improvement of TPTRM frameworks, tools and methodologies.
  • Develop and refine ICT risk assessment templates, audit guidelines and reporting standards for expert and non-expert audiences.

Technical skills

Must have

  • 10+ years of professional experience in Information Security and IT & Cyber Risk Management.
  • Strong experience in third-party IT and security risk assessments.
  • Strong experience with cloud security across SaaS, IaaS and PaaS environments.
  • Experience with application security, vulnerability management and penetration testing.
  • Proficiency with Information Security and Risk Management frameworks, including ISO 27001, SOC, NIST and OWASP.
  • Experience in IT risk management and audit methodologies.
  • Professional experience within Financial Services and large corporate environments.
  • Experience reviewing and amending IT and Cyber third-party contractual clauses.
  • Experience in process design and business analysis related to IT and security risk management.
  • Experience delivering presentations and training to stakeholders.
  • Strong IT background with exposure to operational and security risk management.
  • Master’s degree in IT, Cybersecurity, Risk Management, or equivalent professional experience.
  • Fluent French.
  • Fluent English.
  • Strong analytical and synthesis capabilities.
  • Excellent communication and influencing skills.
  • Ability to work autonomously and manage multiple priorities.
  • Strong negotiation and conflict-resolution capabilities.
  • Ability to engage effectively with technical, business and supplier stakeholders.

Should have

  • Fluent Dutch.
  • Strong knowledge of control frameworks and audit methodologies.
  • Ability to mentor and coach colleagues.
  • Ability to operate effectively in a dynamic and multicultural environment.
  • Ability to adapt to stakeholder expectations while respecting established processes.

Nice to have

  • CISSP, CISM, CIPP, CCSK or similar security certification.
  • Familiarity with ServiceNow GRC.

Who we are

Community Consulting goes beyond traditional consulting; it’s all about fostering connections in an atmosphere of trust and confidence.

Transparency & Honesty : We say things as they are. Clear communication for seamless collaboration.

#COMMUNITEAM : Work independently, but never alone. Collective intelligence drives us further, faster.

Total Commitment : Always present, always engaged. We find solutions and make sure everyone moves forward together.

Guaranteed Efficiency : No fluff, just results. We act fast, keep our promises, and deliver top quality.

This is our DNA. This is how we make a difference.

Type

Permanent or Freelance

Contract

Full-time

Location

Brussels

Homeworking

2 days per week

Sector

Bank

Keywords

You Career Advisor

Alex Cuypers
Junior Talent Management Officer
a.cuypers@communityconsulting.be

Are you interested in this job offer ?