IT and Cyber Third Party Risk Assessor Consultant
Il y a 9 heures
Brussels, Brussels-Capital, Belgique
Keystone Solutions
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Mission Overview:
The IT and Cyber Third Party Risk Assessor role is a consultancy mission at the client site, representing Keystone Solutions. As a Keystone Solutions consultant, you will be hired to deliver expert services on client projects, focusing on robust IT and Cyber Risk Management with a strong emphasis on Third-Party Technology Risk Management.
Responsibilities:
• Conduct comprehensive IT and Cyber risk assessments of third-party suppliers (intragroup and external) during the due diligence phase, evaluating their cybersecurity posture, IT controls, and compliance with regulatory and contractual obligations.
• Assess cloud-based solutions (SaaS, HSP, AWS, etc.) with a deep focus on security, data protection, and resilience.
• Review vulnerability and penetration testing reports, ensuring alignment with security best practices and regulatory requirements.
• Review, challenge, and negotiate IT and cybersecurity clauses in supplier contracts, ensuring they meet risk appetite and compliance standards.
• Collaborate with procurement, legal, and business teams to integrate risk mitigation measures into contractual agreements.
• Pilot IT and Cyber onsite audits conducted by external auditors, ensuring proper scope, execution, and alignment with TPTRM objectives.
• Review IT audit reports, validate findings, and track remediation plans with third-party suppliers.
• Escalate critical IT and Cyber risks and ensure timely resolution in collaboration with internal stakeholders.
• Monitor third-party IT and Security posture through periodic reviews of security reports, incident responses, and compliance attestations (ISO 27001, SOC, NIST, etc.).
• Lead ICT Risk & Cyber Committees involving internal business representatives and supplier security teams to assess ongoing risks, track mitigation progress, and enforce accountability.
• Develop and maintain ICT risk dashboards and synthetic reports for senior management, highlighting key risks, trends, and recommendations.
• Work closely with Cyber Defense Teams, Security Architects, Business & IT Continuity Experts, Data Protection Officers, Procurement & Legal Teams to align third-party risk management with threat intelligence, technical controls, resilience, privacy regulations, and contract lifecycle management.
• Contribute to the evolution of TPTRM frameworks, tools, and methodologies, ensuring alignment with group standards, industry best practices, and regulatory changes.
• Develop and refine ICT risk assessment templates, audit guidelines, and reporting standards for both expert and non-expert audiences.
Requirements:
• Master degree in IT, Cybersecurity, Risk Management or equivalent by experience.
• Security certifications like CISSP, CISM, CIPP, CCSK are optional.
• Fluent in French (mandatory), Dutch, and English (mandatory).
• Professional experience in information security (10+ years).
• Experience in process design and business analysis.
• Experience in third-party IT and security assessments.
• Experience in IT risk management.
• Experience in delivering presentations and training.
• 10+ years of professional experience in IT & Cyber Risk Management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS).
• Experience with application security, vulnerability management, penetration testing, and audit methodologies (ISO 27001, SOC 2, NIST, OWASP).
• Knowledge of control frameworks and audit methodologies.
• Familiarity with GRC tools (ServiceNow).
• Proficiency in Information Security and Risk Management frameworks (e.g., ISO 27001, SOC, NIST, OWASP).
• Professional experience in Financial Services, particularly in large corporate environments.
• Experience in reviewing and amending IT and Cyber Third-Party clauses in contracts.
• Process design and business analysis, particularly in IT and security risk management.
• Delivery of presentations and training to stakeholders on risk-related topics.
• Strong IT background, with exposure to operational and security risk management.
• Strong analytical and synthesis skills – ability to distill complex technical risks into clear, actionable insights for management.
• Excellent communication and influencing skills – capable of engaging with technical experts, business stakeholders, and external suppliers.
• Autonomous, proactive, and results-driven with a structured and methodical approach.
• Ability to manage multiple priorities in a dynamic, multicultural environment.
• Negotiation and conflict-resolution skills for contractual and risk mitigation discussions.
• Ability to capture and adapt to stakeholder expectations while respecting processes in place.
• Ability to mentor/coach people. Consultancy Advantages at Keystone Solutions:
• As a consultant, you will work on-site at the client, bringing Keystone Solutions’ expertise and values to every engagement.
• Experience a wide variety of dynamic projects and challenges across diverse client environments.
• Accelerate your professional development with turbo-charged learning and broad exposure to industry best practices.
• Grow your career ambitions within a framework that supports your progression and recognizes your achievements.
• Being a “K-Stone” means embodying core values and delivering excellence in every mission. Work
Location:
Brussels (50% on site & 50% homeworking expected) Travel: Frequency and location or N/A If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.
Responsibilities:
• Conduct comprehensive IT and Cyber risk assessments of third-party suppliers (intragroup and external) during the due diligence phase, evaluating their cybersecurity posture, IT controls, and compliance with regulatory and contractual obligations.
• Assess cloud-based solutions (SaaS, HSP, AWS, etc.) with a deep focus on security, data protection, and resilience.
• Review vulnerability and penetration testing reports, ensuring alignment with security best practices and regulatory requirements.
• Review, challenge, and negotiate IT and cybersecurity clauses in supplier contracts, ensuring they meet risk appetite and compliance standards.
• Collaborate with procurement, legal, and business teams to integrate risk mitigation measures into contractual agreements.
• Pilot IT and Cyber onsite audits conducted by external auditors, ensuring proper scope, execution, and alignment with TPTRM objectives.
• Review IT audit reports, validate findings, and track remediation plans with third-party suppliers.
• Escalate critical IT and Cyber risks and ensure timely resolution in collaboration with internal stakeholders.
• Monitor third-party IT and Security posture through periodic reviews of security reports, incident responses, and compliance attestations (ISO 27001, SOC, NIST, etc.).
• Lead ICT Risk & Cyber Committees involving internal business representatives and supplier security teams to assess ongoing risks, track mitigation progress, and enforce accountability.
• Develop and maintain ICT risk dashboards and synthetic reports for senior management, highlighting key risks, trends, and recommendations.
• Work closely with Cyber Defense Teams, Security Architects, Business & IT Continuity Experts, Data Protection Officers, Procurement & Legal Teams to align third-party risk management with threat intelligence, technical controls, resilience, privacy regulations, and contract lifecycle management.
• Contribute to the evolution of TPTRM frameworks, tools, and methodologies, ensuring alignment with group standards, industry best practices, and regulatory changes.
• Develop and refine ICT risk assessment templates, audit guidelines, and reporting standards for both expert and non-expert audiences.
Requirements:
• Master degree in IT, Cybersecurity, Risk Management or equivalent by experience.
• Security certifications like CISSP, CISM, CIPP, CCSK are optional.
• Fluent in French (mandatory), Dutch, and English (mandatory).
• Professional experience in information security (10+ years).
• Experience in process design and business analysis.
• Experience in third-party IT and security assessments.
• Experience in IT risk management.
• Experience in delivering presentations and training.
• 10+ years of professional experience in IT & Cyber Risk Management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS).
• Experience with application security, vulnerability management, penetration testing, and audit methodologies (ISO 27001, SOC 2, NIST, OWASP).
• Knowledge of control frameworks and audit methodologies.
• Familiarity with GRC tools (ServiceNow).
• Proficiency in Information Security and Risk Management frameworks (e.g., ISO 27001, SOC, NIST, OWASP).
• Professional experience in Financial Services, particularly in large corporate environments.
• Experience in reviewing and amending IT and Cyber Third-Party clauses in contracts.
• Process design and business analysis, particularly in IT and security risk management.
• Delivery of presentations and training to stakeholders on risk-related topics.
• Strong IT background, with exposure to operational and security risk management.
• Strong analytical and synthesis skills – ability to distill complex technical risks into clear, actionable insights for management.
• Excellent communication and influencing skills – capable of engaging with technical experts, business stakeholders, and external suppliers.
• Autonomous, proactive, and results-driven with a structured and methodical approach.
• Ability to manage multiple priorities in a dynamic, multicultural environment.
• Negotiation and conflict-resolution skills for contractual and risk mitigation discussions.
• Ability to capture and adapt to stakeholder expectations while respecting processes in place.
• Ability to mentor/coach people. Consultancy Advantages at Keystone Solutions:
• As a consultant, you will work on-site at the client, bringing Keystone Solutions’ expertise and values to every engagement.
• Experience a wide variety of dynamic projects and challenges across diverse client environments.
• Accelerate your professional development with turbo-charged learning and broad exposure to industry best practices.
• Grow your career ambitions within a framework that supports your progression and recognizes your achievements.
• Being a “K-Stone” means embodying core values and delivering excellence in every mission. Work
Location:
Brussels (50% on site & 50% homeworking expected) Travel: Frequency and location or N/A If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.