IT & Cyber Third-Party Risk Expert

Stott and May
Belgium
2 days ago
Apply on find.stottandmay.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Languages
Dutch, English, French

Tech stack

Software System Penetration Testing Software as a Service Cloud Computing Security Cyber Security Infrastructure as a Service (IaaS) Open Web Application Security Platform as a Service (PAAS) Software Vulnerability Management Software Security Cyber Threat Analysis Servicenow

Job description

A major financial services organisation in Belgium is hiring a senior IT & Cyber Third-Party Risk Expert. The role is hybrid, with 50% on site. The Governance, Risk and Compliance team ensures robust IT and cyber risk management across the organisation. It has a strong focus on third-party technology risk. The team helps IT and business functions assess, mitigate and monitor the risks from internal and external suppliers, in line with internal IT and information security policies. You will evaluate and manage the cyber and operational risks of third-party services, particularly cloud solutions. You will work with cyber defence, security architecture, business continuity, data protection and procurement teams., Third-party risk assessment and due diligence

  • Run IT and cyber risk assessments of internal and external suppliers during due diligence, covering cyber posture, IT controls, and regulatory and contractual compliance
  • Assess cloud solutions (SaaS, hosted services, AWS and similar) with a deep focus on security, data protection and resilience
  • Review vulnerability and penetration testing reports against security best practice and regulatory requirements

Contract and negotiation support

  • Review, challenge and negotiate IT and cyber clauses in supplier contracts so they meet risk appetite and compliance standards
  • Work with Procurement, Legal and the business to build risk mitigation into contracts

Onsite audit coordination and follow-up

  • Steer IT and cyber onsite audits performed by external auditors, including scope and execution
  • Review audit reports, validate findings and track supplier remediation plans
  • Escalate critical IT and cyber risks and drive them to timely resolution

Continuous monitoring and governance

  • Monitor supplier security posture through periodic reviews of security reports, incident responses and attestations (ISO 27001, SOC, NIST)
  • Lead ICT risk and cyber committees with business representatives and supplier security teams
  • Build and maintain ICT risk dashboards and summary reports for senior management

Cross-functional collaboration

  • Cyber defence teams, on threat intelligence and incident response
  • Security architects, on technical controls and cloud security frameworks
  • Business and IT continuity experts, on supplier resilience and disaster recovery
  • Data protection officers, on GDPR and privacy compliance
  • Procurement and Legal, on supplier selection and contract lifecycle

Process and methodology

  • Evolve third-party risk frameworks, tools and methods in line with group standards, best practice and regulation
  • Develop ICT risk assessment templates, audit guidelines and reporting standards for expert and non-expert audiences

Requirements

  • 10+ years in information security and IT & cyber risk management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS)
  • Hands-on third-party IT and security assessments and supplier risk evaluations
  • Application security, vulnerability management, penetration testing and audit methodologies (ISO 27001, SOC 2, NIST, OWASP)
  • Financial services experience in a large corporate environment
  • Reviewing and amending IT and cyber clauses in supplier contracts
  • Process design and business analysis in IT and security risk management
  • Delivering presentations and training on risk topics
  • Strong IT background with exposure to operational and security risk

Preferred

  • Knowledge of control frameworks and audit methodologies
  • Familiarity with GRC tooling (ServiceNow)

Soft skills

  • Strong analysis and synthesis: turning complex technical risk into clear, actionable insight for management
  • Clear communication and influence with technical experts, business stakeholders and suppliers
  • Autonomous, proactive and structured, able to juggle priorities in a multicultural environment
  • Negotiation and conflict-resolution skills for contract and remediation discussions
  • Able to adapt to stakeholder expectations while respecting established processes
  • Able to mentor and coach others

Languages, education and setup

Item Requirement French Fluent (mandatory) English Fluent (mandatory) Dutch Fluent (strong plus) Education Master’s in IT, cybersecurity or risk management, or equivalent experience Certifications Optional: CISSP, CISM, CIPP, CCSK Location Belgium, hybrid: 50% on site, 50% remote

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.stottandmay.com
Prepare application

Good distractions

Loading talks and stories from around this role…