Technology Risk Consultant

Il y a 2 jours

Brussel Hoofdstad, Belgique Asenium Consulting Temps plein 90 000 € - 120 000 €/an

Asenium is looking for a senior TPTRM expert to assess and manage supplier-related IT, cybersecurity, and operational risks in a large financial services environment.

Responsibilities:

  • Conduct IT and cyber risk assessments of intragroup and external suppliers during due diligence.
  • Assess cloud services for security, data protection, and resilience; review vulnerability and penetration testing reports.
  • Review, challenge, and negotiate supplier IT and cybersecurity clauses with procurement, legal, and business teams.
  • Coordinate external on-site audits, validate findings, track remediation, and elevate critical risks.
  • Monitor supplier security posture through periodic reviews, incident responses, and compliance attestations.
  • Lead ICT risk and cyber committees; prepare dashboards and concise risk reports for senior management.
  • Collaborate with cyber defense, security architecture, continuity, and data protection specialists.
  • Improve TPTRM methodologies, assessment templates, audit guidelines, and reporting standards.

Must-have requirements:

  • 10+ years of experience in information security and IT/cyber risk management, with strong third-party assessment and cloud security expertise.
  • Experience assessing SaaS, IaaS, and PaaS environments, application security, vulnerabilities, penetration testing, and audit findings.
  • Proficiency in ISO 27001, SOC/SOC 2, NIST, and OWASP frameworks and methodologies.
  • Financial services experience within large corporate environments.
  • Experience reviewing and amending third-party IT and cybersecurity contractual clauses.
  • Strong process design and business analysis skills, plus experience delivering stakeholder presentations and training.
  • Strong analytical, communication, negotiation, and stakeholder management skills; ability to work autonomously, manage competing priorities, and coach others.
  • Master’s degree in IT, Cybersecurity, or Risk Management, or equivalent experience.
  • Fluent French and English, spoken and written.