Third Party Risk Consultant
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
IT & Cyber Third-Party Risk Expert – Job Description
Role overview
A major financial services organisation in Belgium is hiring a senior IT & Cyber Third-Party Risk Expert. The role is hybrid, with 50% on site.
The Governance, Risk and Compliance team ensures robust IT and cyber risk management across the organisation. It has a strong focus on third-party technology risk. The team helps IT and business functions assess, mitigate and monitor the risks from internal and external suppliers, in line with internal IT and information security policies.
You will evaluate and manage the cyber and operational risks of third-party services, particularly cloud solutions. You will work with cyber defence, security architecture, business continuity, data protection and procurement teams.
Key responsibilities
Third-party risk assessment and due diligence- Run IT and cyber risk assessments of internal and external suppliers during due diligence, covering cyber posture, IT controls, and regulatory and contractual compliance
- Assess cloud solutions (SaaS, hosted services, AWS and similar) with a deep focus on security, data protection and resilience
- Review vulnerability and penetration testing reports against security best practice and regulatory requirements
- Review, challenge and negotiate IT and cyber clauses in supplier contracts so they meet risk appetite and compliance standards
- Work with Procurement, Legal and the business to build risk mitigation into contracts
- Steer IT and cyber onsite audits performed by external auditors, including scope and execution
- Review audit reports, validate findings and track supplier remediation plans
- Escalate critical IT and cyber risks and drive them to timely resolution
- Monitor supplier security posture through periodic reviews of security reports, incident responses and attestations (ISO 27001, SOC, NIST)
- Lead ICT risk and cyber committees with business representatives and supplier security teams
- Build and maintain ICT risk dashboards and summary reports for senior management
- Cyber defence teams, on threat intelligence and incident response
- Security architects, on technical controls and cloud security frameworks
- Business and IT continuity experts, on supplier resilience and disaster recovery
- Data protection officers, on GDPR and privacy compliance
- Procurement and Legal, on supplier selection and contract lifecycle
- Evolve third-party risk frameworks, tools and methods in line with group standards, best practice and regulation
- Develop ICT risk assessment templates, audit guidelines and reporting standards for expert and non-expert audiences
Required experience and skills
Mandatory- 10+ years in information security and IT & cyber risk management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS)
- Hands-on third-party IT and security assessments and supplier risk evaluations
- Application security, vulnerability management, penetration testing and audit methodologies (ISO 27001, SOC 2, NIST, OWASP)
- Financial services experience in a large corporate environment
- Reviewing and amending IT and cyber clauses in supplier contracts
- Process design and business analysis in IT and security risk management
- Delivering presentations and training on risk topics
- Strong IT background with exposure to operational and security risk
- Knowledge of control frameworks and audit methodologies
- Familiarity with GRC tooling (ServiceNow)
- Strong analysis and synthesis: turning complex technical risk into clear, actionable insight for management
- Clear communication and influence with technical experts, business stakeholders and suppliers
- Autonomous, proactive and structured, able to juggle priorities in a multicultural environment
- Negotiation and conflict-resolution skills for contract and remediation discussions
- Able to adapt to stakeholder expectations while respecting established processes
- Able to mentor and coach others
Languages, education and setup
- French – Fluent (mandatory)
- English – Fluent (mandatory)
- Dutch – Fluent (strong plus)
- Education – Master's in IT, cybersecurity or risk management, or equivalent experience
- Certifications – Optional: CISSP, CISM, CIPP, CCSK
- Location – Belgium, hybrid: 50% on site, 50% remot