Manager Third-Party

Il y a 22 heures

Brussel, Belgique KPMG Temps plein

Position description

Job title

Manager Third-Party & ICT Risk (TPRM / DORA)

Function

Advisory - Manager

Roles & Responsibilities

Belgian banks, insurers and financial market infrastructures are subject to a continuous, supervised obligation to understand the services delivered by their ICT providers, the criticality of each arrangement, and the consequences of provider failure. The Digital Operational Resilience Act has shifted oversight of ICT third-party arrangements from a periodic compliance exercise to an ongoing control that supervisors actively assess.

In practice, many institutions continue to manage this through manual processes and registers that are maintained infrequently and inconsistently.

KPMG supports these institutions both through advisory engagements and through a managed service in which we operate defined elements of the third-party risk lifecycle on the client's behalf. We are seeking a Manager to lead delivery of this work and to contribute to the further development of the managed service within our cyber practice.

Lead TPRM engagements for institutions supervised by the NBB and the FSMA, covering target operating model design, register of information development and remediation, criticality and materiality assessments, contractual gap analysis, exit strategies, and concentration and subcontracting risk.Assume responsibility for delivery quality within the TPRM managed service, including provider due diligence, continuous monitoring, assurance reviews and reporting to client risk committees. You will also contribute to the industrialisation of the service through the development of playbooks, tooling, delivery models, quality gates and commercial structure.Support the growth of the service in collaboration with the partner group. This includes shaping the proposition, developing proposals and pricing, and building pipeline within existing client relationships. Commercial support will be provided, and an active contribution to business development is expected.Translate supervisory requirements into operational processes. This includes DORA Chapter V and the associated RTS and ITS, the EBA outsourcing guidelines, EIOPA guidance and applicable NBB circulars, converted into arrangements that a second line function can realistically operate.Coach and develop a team of consultants and senior consultants, and act as escalation point for technical and regulatory judgement.Contribute to the practice's market presence through client roundtables, webinars, publications and engagement with the wider regulatory dialogue.

Location

Zaventem HQ

Skills & Qualifications

Required

Approximately six or more years of experience in third-party and outsourcing risk, ICT risk or cyber risk, obtained within financial services, either in a first or second line function or in a consulting environment. Sector depth is valued above cross-sector breadth.Demonstrable experience of DORA implementation. Candidates should be able to evidence concrete deliverables, such as a register of information that has withstood supervisory review, a criticality assessment methodology, or a contractual remediation programme, rather than theoretical familiarity with the regulation.A substantive information security foundation, including the ability to assess a provider's information security management system, critically review SOC 2 Type II and ISAE 3402 reports, and distinguish between control deficiencies and documentation deficiencies.Sound knowledge of IT risk management, covering ICT risk taxonomies, control frameworks (ISO/IEC 27001 and 27002, NIST CSF, CIS), risk appetite, key risk indicator design and board-level reporting.Experience of leading repeatable service or team delivery, in addition to discrete project work.
Professional proficiency in Dutch or French, combined with fluent English. Knowledge of the second national language is a significant advantage in this client base.

#LI-DNI

We offer

As a certified Top Employer we offer:

An attractive remuneration package with a great number of extra-legal benefits (premium electric company car + charging card, net daily and monthly allowances, bonus, smartphone and many other benefits tailored through our cafeteria plan).Flexible work arrangements to ensure a healthy work-life balance (picking up kids from school, doctor’s appointment, working from home,…) and the possibility to work from anywhere 20 days per year.Comprehensive insurance package including group insurance with full KPMG contributions, hospitalization insurance and optional outpatient options (dental & eye care, medical consultations and registered medication).Ca