IT & Cyber Third-Party Risk Expert
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
A major financial services organisation in Belgium is hiring a senior IT & Cyber Third-Party Risk Expert. The role is hybrid, with 50% on site. The Governance, Risk and Compliance team ensures robust IT and cyber risk management across the organisation. It has a strong focus on third-party technology risk. The team helps IT and business functions assess, mitigate and monitor the risks from internal and external suppliers, in line with internal IT and information security policies. You will evaluate and manage the cyber and operational risks of third-party services, particularly cloud solutions. You will work with cyber defence, security architecture, business continuity, data protection and procurement teams., Third-party risk assessment and due diligence
- Run IT and cyber risk assessments of internal and external suppliers during due diligence, covering cyber posture, IT controls, and regulatory and contractual compliance
- Assess cloud solutions (SaaS, hosted services, AWS and similar) with a deep focus on security, data protection and resilience
- Review vulnerability and penetration testing reports against security best practice and regulatory requirements
Contract and negotiation support
- Review, challenge and negotiate IT and cyber clauses in supplier contracts so they meet risk appetite and compliance standards
- Work with Procurement, Legal and the business to build risk mitigation into contracts
Onsite audit coordination and follow-up
- Steer IT and cyber onsite audits performed by external auditors, including scope and execution
- Review audit reports, validate findings and track supplier remediation plans
- Escalate critical IT and cyber risks and drive them to timely resolution
Continuous monitoring and governance
- Monitor supplier security posture through periodic reviews of security reports, incident responses and attestations (ISO 27001, SOC, NIST)
- Lead ICT risk and cyber committees with business representatives and supplier security teams
- Build and maintain ICT risk dashboards and summary reports for senior management
Cross-functional collaboration
- Cyber defence teams, on threat intelligence and incident response
- Security architects, on technical controls and cloud security frameworks
- Business and IT continuity experts, on supplier resilience and disaster recovery
- Data protection officers, on GDPR and privacy compliance
- Procurement and Legal, on supplier selection and contract lifecycle
Process and methodology
- Evolve third-party risk frameworks, tools and methods in line with group standards, best practice and regulation
- Develop ICT risk assessment templates, audit guidelines and reporting standards for expert and non-expert audiences
Requirements
- 10+ years in information security and IT & cyber risk management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS)
- Hands-on third-party IT and security assessments and supplier risk evaluations
- Application security, vulnerability management, penetration testing and audit methodologies (ISO 27001, SOC 2, NIST, OWASP)
- Financial services experience in a large corporate environment
- Reviewing and amending IT and cyber clauses in supplier contracts
- Process design and business analysis in IT and security risk management
- Delivering presentations and training on risk topics
- Strong IT background with exposure to operational and security risk
Preferred
- Knowledge of control frameworks and audit methodologies
- Familiarity with GRC tooling (ServiceNow)
Soft skills
- Strong analysis and synthesis: turning complex technical risk into clear, actionable insight for management
- Clear communication and influence with technical experts, business stakeholders and suppliers
- Autonomous, proactive and structured, able to juggle priorities in a multicultural environment
- Negotiation and conflict-resolution skills for contract and remediation discussions
- Able to adapt to stakeholder expectations while respecting established processes
- Able to mentor and coach others
Languages, education and setup
Item Requirement French Fluent (mandatory) English Fluent (mandatory) Dutch Fluent (strong plus) Education Master’s in IT, cybersecurity or risk management, or equivalent experience Certifications Optional: CISSP, CISM, CIPP, CCSK Location Belgium, hybrid: 50% on site, 50% remote
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…