CISO Officer (TPRM)

act digital
Brussel, Belgium
8 days ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
Dutch, English, French
Job source

Tech stack

Cyber Security Information Systems Security Architecture Professional

Job description

Ensure effective management of cybersecurity risks related to third parties (suppliers, partners, service providers, integrators, vendors) as well as the integration and enforcement of cybersecurity requirements within procurement and tendering processes (RFI, RFC, RFQ, RFP, tenders, etc.), in alignment with the CISO strategy, regulatory frameworks, and the organization’s standards.

The role aims to ensure that security commitments made with third parties are consistent, compliant, controlled, and traceable from a technical, regulatory, and contractual perspective throughout the entire lifecycle of the third-party relationship.

MAIN ACTIVITIES

Third Party Risk Management (TPRM)

  • Establish, maintain, and continuously improve the cybersecurity third party risk management framework, in alignment with applicable regulatory and industry standards.

  • Identify, analyse, and assess cybersecurity risks associated with third parties based on security questionnaires, supporting documentation (certifications, policies, audit reports), and reviews of proposed architectures or solutions.

  • Define, monitor, and document risk mitigation measures, acceptance conditions, and related action plans.

Procurement Processes and Tender Documentation

  • Review and secure cybersecurity requirements within procurement processes (RFI, RFC, RFQ, RFP, etc.) and tender documentation, ensuring compliance with applicable reference frameworks.

  • Assess suppliers’ responses and proposals from a security, compliance, and risk management perspective.

  • Contribute to drafting security-related responses and identify associated risks, conditions, and commitments, in collaboration with relevant stakeholders.

Reporting and Continuous Improvement

  • Ensure reporting and monitoring of third-party risks and reviewed RFPs.

  • Provide consolidated visibility to the CISO and management, and propose continuous improvement actions.

Requirements

  • You communicate fluently in Dutch, French and English (spoken and written): Dutch or French at C1 level, the other language at least B2, English at least C1.

  • Master’s degree in a relevant field from the following list: IT, law, risk management, information security.

  • At least one active certification valid at submission date from the following list: ISC2 CISSP, CCSP, ISACA CISA, CRISC, CISM, CDPSE, or CGEIT.

  • Minimum 5 years of experience in at least one of the following domains: such as Third Party Risk Management, Security Assurance, GRC / compliance, Audit or security assessment.

  • Proven experience in reviewing procurement documentation (RFI, RFQ, RFP, etc.)

  • Willing to work on-site at least 2 days per week in Brussels

EVALUATION CRITERIA

The more experience the better your proposal will be evaluated for this criterion.

  • Level of experience with cybersecurity frameworks (number of projects, role, responsibilities)

  • Experience in assessing IT/security architectures (scope, number of assessments, role)

  • Experience in analyzing cybersecurity requirements and procurement documentation (scope and tasks)

  • Experience in producing deliverables (type: reports, policies, assessments)

  • Experience in analytical tasks (risk analysis, compliance, audits)

  • Experience in drafting structured reports (type, audience, context)

  • Level and complexity of stakeholder management (IT, Legal, CISO, etc.)

  • Experience in risk-based decision making (examples in CV)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all