Manager Third-Party & ICT Risk (TPRM / DORA) (Ref. : 2026-1434) - Manager

KPMG
Zaventem, Belgium
about 1 month ago
Apply on be.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Languages
Dutch, English, French
Job source

Tech stack

Cyber Security Information Security Management System

Job description

Belgian banks, insurers and financial market infrastructures are subject to a continuous, supervised obligation to understand the services delivered by their ICT providers, the criticality of each arrangement, and the consequences of provider failure. The Digital Operational Resilience Act has shifted oversight of ICT third-party arrangements from a periodic compliance exercise to an ongoing control that supervisors actively assess.

In practice, many institutions continue to manage this through manual processes and registers that are maintained infrequently and inconsistently.

KPMG supports these institutions both through advisory engagements and through a managed service in which we operate defined elements of the third-party risk lifecycle on the client’s behalf. We are seeking a Manager to lead delivery of this work and to contribute to the further development of the managed service within our cyber practice.

  • Lead TPRM engagements for institutions supervised by the NBB and the FSMA, covering target operating model design, register of information development and remediation, criticality and materiality assessments, contractual gap analysis, exit strategies, and concentration and subcontracting risk.
  • Assume responsibility for delivery quality within the TPRM managed service, including provider due diligence, continuous monitoring, assurance reviews and reporting to client risk committees. You will also contribute to the industrialisation of the service through the development of playbooks, tooling, delivery models, quality gates and commercial structure.
  • Support the growth of the service in collaboration with the partner group. This includes shaping the proposition, developing proposals and pricing, and building pipeline within existing client relationships. Commercial support will be provided, and an active contribution to business development is expected.
  • Translate supervisory requirements into operational processes. This includes DORA Chapter V and the associated RTS and ITS, the EBA outsourcing guidelines, EIOPA guidance and applicable NBB circulars, converted into arrangements that a second line function can realistically operate.
  • Coach and develop a team of consultants and senior consultants, and act as escalation point for technical and regulatory judgement.
  • Contribute to the practice’s market presence through client roundtables, webinars, publications and engagement with the wider regulatory dialogue.

Requirements

Required

  • Approximately six or more years of experience in third-party and outsourcing risk, ICT risk or cyber risk, obtained within financial services, either in a first or second line function or in a consulting environment. Sector depth is valued above cross-sector breadth.
  • Demonstrable experience of DORA implementation. Candidates should be able to evidence concrete deliverables, such as a register of information that has withstood supervisory review, a criticality assessment methodology, or a contractual remediation programme, rather than theoretical familiarity with the regulation.
  • A substantive information security foundation, including the ability to assess a provider’s information security management system, critically review SOC 2 Type II and ISAE 3402 reports, and distinguish between control deficiencies and documentation deficiencies.
  • Sound knowledge of IT risk management, covering ICT risk taxonomies, control frameworks (ISO/IEC 27001 and 27002, NIST CSF, CIS), risk appetite, key risk indicator design and board-level reporting.
  • Experience of leading repeatable service or team delivery, in addition to discrete project work. Professional proficiency in Dutch or French, combined with fluent English. Knowledge of the second national language is a significant advantage in this client base., * Dutch (Very good knowledge)

  • English (Very good knowledge)
  • French (Very good knowledge)

Benefits & conditions

Pulled from the full job description

  • Company phone
  • Company car
  • Hospitalization insurance
  • Work from home
  • Company events, * An attractive remuneration package with a great number of extra-legal benefits (premium electric company car + charging card, net daily and monthly allowances, bonus, smartphone and many other benefits tailored through our cafeteria plan).
  • Flexible work arrangements to ensure a healthy work-life balance (picking up kids from school, doctor’s appointment, working from home,…) and the possibility to work from anywhere 20 days per year.
  • Comprehensive insurance package including group insurance with full KPMG contributions, hospitalization insurance and optional outpatient options (dental & eye care, medical consultations and registered medication).
  • Career development opportunities combined with trainings based on your personal goals and aspirations.
  • An inclusive, international culture where personal growth, mutual trust and lifelong learning is fostered.
  • A buddy and performance manager to support and guide you throughout your career at KPMG.
  • Great team building activities and sport & wellbeing events (Brussels Marathon, Antwerp 10 Miles, 1000 kilometers for KOTK, river clean-ups, plant a tree and many more…) through our Together@KPMG & KPMG Foundation programs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on be.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · World Congress 2021

1:41 min

Overcoming staffing risks in specialized platform environments

Michael Coté Michael Coté · World Congress 2026 Europe

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all