IT and Cyber Third Party Risk Assessor Consultant

Il y a 9 heures

Brussels, Brussels-Capital, Belgique Keystone Solutions Temps plein
Mission Overview: The IT and Cyber Third Party Risk Assessor role is a consultancy mission at the client site, representing Keystone Solutions. As a Keystone Solutions consultant, you will be hired to deliver expert services on client projects, focusing on robust IT and Cyber Risk Management with a strong emphasis on Third-Party Technology Risk Management.

Responsibilities:
• Conduct comprehensive IT and Cyber risk assessments of third-party suppliers (intragroup and external) during the due diligence phase, evaluating their cybersecurity posture, IT controls, and compliance with regulatory and contractual obligations.
• Assess cloud-based solutions (SaaS, HSP, AWS, etc.) with a deep focus on security, data protection, and resilience.
• Review vulnerability and penetration testing reports, ensuring alignment with security best practices and regulatory requirements.
• Review, challenge, and negotiate IT and cybersecurity clauses in supplier contracts, ensuring they meet risk appetite and compliance standards.
• Collaborate with procurement, legal, and business teams to integrate risk mitigation measures into contractual agreements.
• Pilot IT and Cyber onsite audits conducted by external auditors, ensuring proper scope, execution, and alignment with TPTRM objectives.
• Review IT audit reports, validate findings, and track remediation plans with third-party suppliers.
• Escalate critical IT and Cyber risks and ensure timely resolution in collaboration with internal stakeholders.
• Monitor third-party IT and Security posture through periodic reviews of security reports, incident responses, and compliance attestations (ISO 27001, SOC, NIST, etc.).
• Lead ICT Risk & Cyber Committees involving internal business representatives and supplier security teams to assess ongoing risks, track mitigation progress, and enforce accountability.
• Develop and maintain ICT risk dashboards and synthetic reports for senior management, highlighting key risks, trends, and recommendations.
• Work closely with Cyber Defense Teams, Security Architects, Business & IT Continuity Experts, Data Protection Officers, Procurement & Legal Teams to align third-party risk management with threat intelligence, technical controls, resilience, privacy regulations, and contract lifecycle management.
• Contribute to the evolution of TPTRM frameworks, tools, and methodologies, ensuring alignment with group standards, industry best practices, and regulatory changes.
• Develop and refine ICT risk assessment templates, audit guidelines, and reporting standards for both expert and non-expert audiences.

Requirements:
• Master degree in IT, Cybersecurity, Risk Management or equivalent by experience.
• Security certifications like CISSP, CISM, CIPP, CCSK are optional.
• Fluent in French (mandatory), Dutch, and English (mandatory).
• Professional experience in information security (10+ years).
• Experience in process design and business analysis.
• Experience in third-party IT and security assessments.
• Experience in IT risk management.
• Experience in delivering presentations and training.
• 10+ years of professional experience in IT & Cyber Risk Management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS).
• Experience with application security, vulnerability management, penetration testing, and audit methodologies (ISO 27001, SOC 2, NIST, OWASP).
• Knowledge of control frameworks and audit methodologies.
• Familiarity with GRC tools (ServiceNow).
• Proficiency in Information Security and Risk Management frameworks (e.g., ISO 27001, SOC, NIST, OWASP).
• Professional experience in Financial Services, particularly in large corporate environments.
• Experience in reviewing and amending IT and Cyber Third-Party clauses in contracts.
• Process design and business analysis, particularly in IT and security risk management.
• Delivery of presentations and training to stakeholders on risk-related topics.
• Strong IT background, with exposure to operational and security risk management.
• Strong analytical and synthesis skills – ability to distill complex technical risks into clear, actionable insights for management.
• Excellent communication and influencing skills – capable of engaging with technical experts, business stakeholders, and external suppliers.
• Autonomous, proactive, and results-driven with a structured and methodical approach.
• Ability to manage multiple priorities in a dynamic, multicultural environment.
• Negotiation and conflict-resolution skills for contractual and risk mitigation discussions.
• Ability to capture and adapt to stakeholder expectations while respecting processes in place.
• Ability to mentor/coach people. Consultancy Advantages at Keystone Solutions:
• As a consultant, you will work on-site at the client, bringing Keystone Solutions’ expertise and values to every engagement.
• Experience a wide variety of dynamic projects and challenges across diverse client environments.
• Accelerate your professional development with turbo-charged learning and broad exposure to industry best practices.
• Grow your career ambitions within a framework that supports your progression and recognizes your achievements.
• Being a “K-Stone” means embodying core values and delivering excellence in every mission. Work

Location:
Brussels (50% on site & 50% homeworking expected) Travel: Frequency and location or N/A If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.