Technology Risk Consultant
Il y a 2 jours
Brussel Hoofdstad, Belgique
Asenium Consulting
Temps plein
90 000 € - 120 000 €/an
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Asenium is looking for a senior TPTRM expert to assess and manage supplier-related IT, cybersecurity, and operational risks in a large financial services environment.
Responsibilities:
- Conduct IT and cyber risk assessments of intragroup and external suppliers during due diligence.
- Assess cloud services for security, data protection, and resilience; review vulnerability and penetration testing reports.
- Review, challenge, and negotiate supplier IT and cybersecurity clauses with procurement, legal, and business teams.
- Coordinate external on-site audits, validate findings, track remediation, and elevate critical risks.
- Monitor supplier security posture through periodic reviews, incident responses, and compliance attestations.
- Lead ICT risk and cyber committees; prepare dashboards and concise risk reports for senior management.
- Collaborate with cyber defense, security architecture, continuity, and data protection specialists.
- Improve TPTRM methodologies, assessment templates, audit guidelines, and reporting standards.
Must-have requirements:
- 10+ years of experience in information security and IT/cyber risk management, with strong third-party assessment and cloud security expertise.
- Experience assessing SaaS, IaaS, and PaaS environments, application security, vulnerabilities, penetration testing, and audit findings.
- Proficiency in ISO 27001, SOC/SOC 2, NIST, and OWASP frameworks and methodologies.
- Financial services experience within large corporate environments.
- Experience reviewing and amending third-party IT and cybersecurity contractual clauses.
- Strong process design and business analysis skills, plus experience delivering stakeholder presentations and training.
- Strong analytical, communication, negotiation, and stakeholder management skills; ability to work autonomously, manage competing priorities, and coach others.
- Master’s degree in IT, Cybersecurity, or Risk Management, or equivalent experience.
- Fluent French and English, spoken and written.