- Location
- Brussels
- Workplace
- Onsite
- Type
- Full-time
- Experience
- 10+ years
- Education
- Master
- Closing date
- Today
- Source
- CareersPage
Description
Mission Overview:
The IT and Cyber Third Party Risk Assessor role is a consultancy mission at the client site, representing Keystone Solutions. As a Keystone Solutions consultant, you will be hired to deliver expert services on client projects, focusing on robust IT and Cyber Risk Management with a strong emphasis on Third-Party Technology Risk Management.Responsibilities:
- Conduct comprehensive IT and Cyber risk assessments of third-party suppliers (intragroup and external) during the due diligence phase, evaluating their cybersecurity posture, IT controls, and compliance with regulatory and contractual obligations.
- Assess cloud-based solutions (SaaS, HSP, AWS, etc.) with a deep focus on security, data protection, and resilience.
- Review vulnerability and penetration testing reports, ensuring alignment with security best practices and regulatory requirements.
- Review, challenge, and negotiate IT and cybersecurity clauses in supplier contracts, ensuring they meet risk appetite and compliance standards.
- Collaborate with procurement, legal, and business teams to integrate risk mitigation measures into contractual agreements.
- Pilot IT and Cyber onsite audits conducted by external auditors, ensuring proper scope, execution, and alignment with TPTRM objectives.
- Review IT audit reports, validate findings, and track remediation plans with third-party suppliers.
- Escalate critical IT and Cyber risks and ensure timely resolution in collaboration with internal stakeholders.
- Monitor third-party IT and Security posture through periodic reviews of security reports, incident responses, and compliance attestations (ISO 27001, SOC, NIST, etc.).
- Lead ICT Risk & Cyber Committees involving internal business representatives and supplier security teams to assess ongoing risks, track mitigation progress, and enforce accountability.
- Develop and maintain ICT risk dashboards and synthetic reports for senior management, highlighting key risks, trends, and recommendations.
- Work closely with Cyber Defense Teams, Security Architects, Business & IT Continuity Experts, Data Protection Officers, Procurement & Legal Teams to align third-party risk management with threat intelligence, technical controls, resilience, privacy regulations, and contract lifecycle management.
- Contribute to the evolution of TPTRM frameworks, tools, and methodologies, ensuring alignment with group standards, industry best practices, and regulatory changes.
- Develop and refine ICT risk assessment templates, audit guidelines, and reporting standards for both expert and non-expert audiences.
Requirements:
- Master degree in IT, Cybersecurity, Risk Management or equivalent by experience.
- Security certifications like CISSP, CISM, CIPP, CCSK are optional.
- Fluent in French (mandatory), Dutch, and English (mandatory).
- Professional experience in information security (10+ years).
- Experience in process design and business analysis.
- Experience in third-party IT and security assessments.
- Experience in IT risk management.
- Experience in delivering presentations and training.
- 10+ years of professional experience in IT & Cyber Risk Management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS).
- Experience with application security, vulnerability management, penetration testing, and audit methodologies (ISO 27001, SOC 2, NIST, OWASP).
- Knowledge of control frameworks and audit methodologies.
- Familiarity with GRC tools (ServiceNow).
- Proficiency in Information Security and Risk Management frameworks (e.g., ISO 27001, SOC, NIST, OWASP).
- Professional experience in Financial Services, particularly in large corporate environments.
- Experience in reviewing and amending IT and Cyber Third-Party clauses in contracts.
- Process design and business analysis, particularly in IT and security risk management.
- Delivery of presentations and training to stakeholders on risk-related topics.
- Strong IT background, with exposure to operational and security risk management.
- Strong analytical and synthesis skills – ability to distill complex technical risks into clear, actionable insights for management.
- Excellent communication and influencing skills – capable of engaging with technical experts, business stakeholders, and external suppliers.
- Autonomous, proactive, and results-driven with a structured and methodical approach.
- Ability to manage multiple priorities in a dynamic, multicultural environment.
- Negotiation and conflict-resolution skills for contractual and risk mitigation discussions.
- Ability to capture and adapt to stakeholder expectations while respecting processes in place.
- Ability to mentor/coach people.
Consultancy Advantages at Keystone Solutions:
- As a consultant, you will work on-site at the client, bringing Keystone Solutions’ expertise and values to every engagement.
- Experience a wide variety of dynamic projects and challenges across diverse client environments.
- Accelerate your professional development with turbo-charged learning and broad exposure to industry best practices.
- Grow your career ambitions within a framework that supports your progression and recognizes your achievements.
- Being a “K-Stone” means embodying core values and delivering excellence in every mission.
Work Location:
Brussels (50% on site & 50% homeworking expected)Travel:
Frequency and location or N/AIf you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.
Skills
AWSServiceNowCybersecurityPenetration TestingSOCRisk ManagementComplianceProcurementNegotiationSOC 2ISO 27001CISSP