Manager Third-Party
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Position description
Job title
Manager Third-Party & ICT Risk (TPRM / DORA)
Function
Advisory - Manager
Roles & Responsibilities
Belgian banks, insurers and financial market infrastructures are subject to a continuous, supervised obligation to understand the services delivered by their ICT providers, the criticality of each arrangement, and the consequences of provider failure. The Digital Operational Resilience Act has shifted oversight of ICT third-party arrangements from a periodic compliance exercise to an ongoing control that supervisors actively assess.
In practice, many institutions continue to manage this through manual processes and registers that are maintained infrequently and inconsistently.
KPMG supports these institutions both through advisory engagements and through a managed service in which we operate defined elements of the third-party risk lifecycle on the client's behalf. We are seeking a Manager to lead delivery of this work and to contribute to the further development of the managed service within our cyber practice.
Location
Zaventem HQ
Skills & Qualifications
Required
Approximately six or more years of experience in third-party and outsourcing risk, ICT risk or cyber risk, obtained within financial services, either in a first or second line function or in a consulting environment. Sector depth is valued above cross-sector breadth.Demonstrable experience of DORA implementation. Candidates should be able to evidence concrete deliverables, such as a register of information that has withstood supervisory review, a criticality assessment methodology, or a contractual remediation programme, rather than theoretical familiarity with the regulation.A substantive information security foundation, including the ability to assess a provider's information security management system, critically review SOC 2 Type II and ISAE 3402 reports, and distinguish between control deficiencies and documentation deficiencies.Sound knowledge of IT risk management, covering ICT risk taxonomies, control frameworks (ISO/IEC 27001 and 27002, NIST CSF, CIS), risk appetite, key risk indicator design and board-level reporting.Experience of leading repeatable service or team delivery, in addition to discrete project work.Professional proficiency in Dutch or French, combined with fluent English. Knowledge of the second national language is a significant advantage in this client base.
#LI-DNI
We offer
As a certified Top Employer we offer:
An attractive remuneration package with a great number of extra-legal benefits (premium electric company car + charging card, net daily and monthly allowances, bonus, smartphone and many other benefits tailored through our cafeteria plan).Flexible work arrangements to ensure a healthy work-life balance (picking up kids from school, doctor’s appointment, working from home,…) and the possibility to work from anywhere 20 days per year.Comprehensive insurance package including group insurance with full KPMG contributions, hospitalization insurance and optional outpatient options (dental & eye care, medical consultations and registered medication).Ca