IT and Cyber Third Party Risk Assessor

Il y a 9 heures

Arrondissement de BruxellesCapitale, Bruxelles, Belgique Adjugo Temps plein

IT and Cyber Third Party Risk Assessor (Expert) - BNP Paribas Fortis

Dates: 2026-10-01 — 2027-09-30

The Governance, Risk and Compliance team supports robust IT and Cyber Risk Management across BNP Paribas Fortis, with a strong focus on Third-Party Technology Risk Management. The expert assesses risks associated with intragroup and external suppliers and checks alignment with the bank’s IT and Information Security policies. A major focus is cloud-based services and the security, data-protection and resilience risks they create. The work spans supplier due diligence, contractual controls and ongoing risk oversight.

The role conducts comprehensive supplier assessments, reviews vulnerability and penetration-testing reports, and challenges IT and cybersecurity clauses in contracts. It also coordinates onsite audits, validates audit findings and follows remediation plans with suppliers. Critical IT and Cyber risks are escalated and followed through to timely resolution with internal stakeholders. Continuous monitoring includes security reports, incident responses and compliance attestations such as ISO 27001, SOC and NIST.

The expert leads ICT Risk and Cyber Committees and produces dashboards and synthetic reports for senior management. Collaboration is extensive, covering Cyber Defense, Security Architecture, Business and IT Continuity, Data Protection, Procurement and Legal teams. The assignment also contributes to evolving TPTRM frameworks, tools and methodologies in line with group standards, industry practice and regulatory changes. The expert develops assessment templates, audit guidelines and reporting standards for expert and non-expert audiences.

Top Reasons to Apply

  • Strategic cyber risk
  • Cloud security exposure
  • Cross-functional collaboration

Responsibilities

  • Assess cloud security solutions
  • Review vulnerability testing reports
  • Negotiate cybersecurity contract clauses
  • Collaborate on contractual mitigations

Must Have

  • 10+ years security experience
  • Third-party risk assessments
  • Cloud security expertise
  • Supplier security assessments
  • Application security experience
  • Vulnerability management experience
  • Penetration testing experience

Nice to Have

  • Dutch fluent proficiency
  • Security certifications preferred
  • Control frameworks knowledge
  • Audit methodologies knowledge
  • ServiceNow GRC familiarity

Additional Responsibilities

  • Escalate critical cyber risks
  • Monitor third-party security posture
  • Develop ICT risk dashboards
  • Align cyber threat intelligence
  • Assess technical security controls
  • Ensure supplier continuity resilience
  • Validate privacy regulation compliance
  • Master degree in IT, Cybersecurity, Risk Management, or equivalent by experience.
  • 10+ years of professional experience in information security.
  • Professional experience in Financial Services, particularly in large corporate environments.
  • Experience in reviewing and amending IT and Cyber Third-Party clauses in contracts.
  • Experience in process design and business analysis, particularly in IT and security risk management.
  • Experience delivering presentations and training to stakeholders on risk-related topics.
  • French: fluent and mandatory.
  • English: fluent and mandatory.
  • Dutch: fluent; the vacancy does not explicitly mark it mandatory.
  • Strong analytical and synthesis skills, with the ability to distill complex technical risks into clear, actionable management insights.
  • Excellent communication and influencing skills with technical experts, business stakeholders, and external suppliers.
  • Autonomous, proactive, and results-driven working style.
  • Structured and methodical approach.
  • Ability to manage multiple priorities in a dynamic, multicultural environment.
  • Negotiation and conflict-resolution skills for contractual and risk mitigation discussions.
  • Ability to capture and adapt to stakeholder expectations while respecting processes in place.
  • Ability to mentor and coach people.
  • Security certifications such as CISSP, CISM, CIPP, or CCSK are optional.

Technical skills

  • 10+ years of professional experience in IT & Cyber Risk Management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS).
  • Experience conducting third-party IT and security assessments, including risk evaluations for suppliers and vendors.
  • Experience with application security.
  • Experience with vulnerability management.
  • Experience with penetration testing.
  • Experience with audit methodologies and