Third Party Cyber Risk Officer

Il y a 4 heures

Brussels, Brussels, Belgique Technology & Risk Recruitment Temps plein

Third Party Cyber Risk Officer

Location: Brussels, Belgium

Working Model: Hybrid – minimum 2 days per week on-site

Contract: Long-term contract until August 2027

Start Date: ASAP

Languages: French, Dutch & English



Is your CV ready If so, and you are confident this is the role for you, make sure to apply asap.

The Role

We are looking for an experienced Third Party Cyber Risk Officer to support the management of cybersecurity risks across suppliers, partners, vendors and service providers.


The role will focus on Third Party Risk Management (TPRM), supplier security assurance and the integration of cybersecurity requirements into procurement and tendering processes.


You will work closely with stakeholders across Cybersecurity, CISO, IT, Legal and Procurement to ensure third-party security risks and commitments are appropriately assessed, documented, controlled and monitored throughout the supplier lifecycle.


Key Responsibilities

  • Assess cybersecurity risks associated with third parties, suppliers and service providers.
  • Review security questionnaires, certifications, policies, audit reports and supporting security documentation.
  • Assess proposed IT and security architectures from a cyber risk perspective.
  • Define and document risk mitigation measures, acceptance conditions and remediation plans.
  • Support and continuously improve the Third Party Risk Management framework.
  • Review cybersecurity requirements within RFI, RFC, RFQ and RFP processes.
  • Evaluate supplier responses from a cybersecurity, compliance and risk perspective.
  • Work with Procurement, Legal, IT and CISO stakeholders on security requirements and contractual commitments.
  • Monitor third-party cybersecurity risks and associated remediation actions.
  • Produce structured risk assessments, reports and management-level documentation.
  • Support continuous improvement of cybersecurity risk and supplier assurance processes.


Essential Requirements

Applicants must be able to demonstrate the following experience and qualifications clearly within their CV:

  • 5+ years' experience within Third Party Risk Management, Security Assurance, Cybersecurity GRC/Compliance, Audit or Security Assessment.
  • Proven experience reviewing RFI, RFQ, RFP or similar procurement/tender documentation from a cybersecurity perspective.
  • Strong experience with recognised cybersecurity frameworks and security controls.
  • Experience assessing IT and/or security architectures.
  • Strong risk analysis, compliance, audit and reporting capabilities.
  • Experience working with multiple stakeholders including CISO, IT, Legal and Procurement.
  • Master's degree in IT, Law, Risk Management, Information Security or a closely related field.
  • At least one active certification from: CISSP, CCSP, CISA, CRISC, CISM, CDPSE or CGEIT.
  • French or Dutch at C1 level, with the other language at minimum B2.
  • English at C1 level or above.
  • Able to work on-site in Brussels at least 2 days per week.


Ideal Profile

You will be comfortable working independently and making risk-based decisions in a complex enterprise environment. You should be able to translate technical cybersecurity findings into clear risk assessments and structured reporting for both technical and senior stakeholders. xirbnpk


Previous experience combining Third Party Risk Management, cybersecurity assurance and procurement/tender processes will be particularly valuable.