Manager Third-Party
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Belgian banks, insurers and financial market infrastructures are subject to a continuous, supervised obligation to understand the services delivered by their ICT providers, the criticality of each arrangement, and the consequences of provider failure. The Digital Operational Resilience Act has shifted oversight of ICT third-party arrangements from a periodic compliance exercise to an ongoing control that supervisors actively assess.
In practice, many institutions continue to manage this through manual processes and registers that are maintained infrequently and inconsistently.
KPMG supports these institutions both through advisory engagements and through a managed service in which we operate defined elements of the third-party risk lifecycle on the client's behalf. We are seeking a Manager to lead delivery of this work and to contribute to the further development of the managed service within our cyber practice.
What will you do
- Lead TPRM engagements for institutions supervised by the NBB and the FSMA, covering target operating model design, register of information development and remediation, criticality and materiality assessments, contractual gap analysis, exit strategies, and concentration and subcontracting risk.
- Assume responsibility for delivery quality within the TPRM managed service, including provider due diligence, continuous monitoring, assurance reviews and reporting to client risk committees. You will also contribute to the industrialisation of the service through the development of playbooks, tooling, delivery models, quality gates and commercial structure.
- Support the growth of the service in collaboration with the partner group. This includes shaping the proposition, developing proposals and pricing, and building pipeline within existing client relationships. Commercial support will be provided, and an active contribution to business development is expected.
- Translate supervisory requirements into operational processes. This includes DORA Chapter V and the associated RTS and ITS, the EBA outsourcing guidelines, EIOPA guidance and applicable NBB circulars, converted into arrangements that a second line function can realistically operate.
- Coach and develop a team of consultants and senior consultants, and act as escalation point for technical and regulatory judgement.
- Contribute to the practice's market presence through client roundtables, webinars, publications and engagement with the wider regulatory dialogue.
What do you need
Required
- Approximately six or more years of experience in third-party and outsourcing risk, ICT risk or cyber risk, obtained within financial services, either in a first or second line function or in a consulting environment. Sector depth is valued above cross-sector breadth.
- Demonstrable experience of DORA implementation. Candidates should be able to evidence concrete deliverables, such as a register of information that has withstood supervisory review, a criticality assessment methodology, or a contractual remediation programme, rather than theoretical familiarity with the regulation.
- A substantive information security foundation, including the ability to assess a provider's information security management system, critically review SOC 2 Type II and ISAE 3402 reports, and distinguish between control deficiencies and documentation deficiencies.
- Sound knowledge of IT risk management, covering ICT risk taxonomies, control frameworks (ISO/IEC 27001 and 27002, NIST CSF, CIS), risk appetite, key risk indicator design and board-level reporting.
- Experience of leading repeatable service or team delivery, in addition to discrete project work.
- Professional proficiency in Dutch or French, combined with fluent English. Knowledge of the second national language is a significant advantage in this client base.
Advantageous
- Experience with TPRM platforms such as OneTrust, ProcessUnity, Prevalent, ServiceNow or Archer, together with a considered view of their practical value.
- CISSP, CISM, CRISC, CISA or an equivalent certification.
- Exposure to NIS2 and CyFun, ISO 22301 and wider operational resilience work.
- Familiarity with cloud provider assurance, including hyperscaler shared responsibility models and provider-specific control sets.
- Experience of ICT contracting and procurement, and the ability to work effectively alongside legal counsel.
What can you expect
As a certified Top Employer we offe