Job Openings IT and Cyber Third Party Risk Assessor Consultant

About the job IT and Cyber Third Party Risk Assessor Consultant

Mission Overview:

The IT and Cyber Third Party Risk Assessor role is a consultancy mission at the client site, representing Keystone Solutions. As a Keystone Solutions consultant, you will be hired to deliver expert services on client projects, focusing on robust IT and Cyber Risk Management with a strong emphasis on Third-Party Technology Risk Management.

Responsibilities:

  • Conduct comprehensive IT and Cyber risk assessments of third-party suppliers (intragroup and external) during the due diligence phase, evaluating their cybersecurity posture, IT controls, and compliance with regulatory and contractual obligations.
  • Assess cloud-based solutions (SaaS, HSP, AWS, etc.) with a deep focus on security, data protection, and resilience.
  • Review vulnerability and penetration testing reports, ensuring alignment with security best practices and regulatory requirements.
  • Review, challenge, and negotiate IT and cybersecurity clauses in supplier contracts, ensuring they meet risk appetite and compliance standards.
  • Collaborate with procurement, legal, and business teams to integrate risk mitigation measures into contractual agreements.
  • Pilot IT and Cyber onsite audits conducted by external auditors, ensuring proper scope, execution, and alignment with TPTRM objectives.
  • Review IT audit reports, validate findings, and track remediation plans with third-party suppliers.
  • Escalate critical IT and Cyber risks and ensure timely resolution in collaboration with internal stakeholders.
  • Monitor third-party IT and Security posture through periodic reviews of security reports, incident responses, and compliance attestations (ISO 27001, SOC, NIST, etc.).
  • Lead ICT Risk & Cyber Committees involving internal business representatives and supplier security teams to assess ongoing risks, track mitigation progress, and enforce accountability.
  • Develop and maintain ICT risk dashboards and synthetic reports for senior management, highlighting key risks, trends, and recommendations.
  • Work closely with Cyber Defense Teams, Security Architects, Business & IT Continuity Experts, Data Protection Officers, Procurement & Legal Teams to align third-party risk management with threat intelligence, technical controls, resilience, privacy regulations, and contract lifecycle management.
  • Contribute to the evolution of TPTRM frameworks, tools, and methodologies, ensuring alignment with group standards, industry best practices, and regulatory changes.
  • Develop and refine ICT risk assessment templates, audit guidelines, and reporting standards for both expert and non-expert audiences.

Requirements:

  • Master degree in IT, Cybersecurity, Risk Management or equivalent by experience.
  • Security certifications like CISSP, CISM, CIPP, CCSK are optional.
  • Fluent in French (mandatory), Dutch, and English (mandatory).
  • Professional experience in information security (10+ years).
  • Experience in process design and business analysis.
  • Experience in third-party IT and security assessments.
  • Experience in IT risk management.
  • Experience in delivering presentations and training.
  • 10+ years of professional experience in IT & Cyber Risk Management, with a strong focus on third-party risk assessments and cloud security (SaaS, IaaS, PaaS).
  • Experience with application security, vulnerability management, penetration testing, and audit methodologies (ISO 27001, SOC 2, NIST, OWASP).
  • Knowledge of control frameworks and audit methodologies.
  • Familiarity with GRC tools (ServiceNow).
  • Proficiency in Information Security and Risk Management frameworks (e.g., ISO 27001, SOC, NIST, OWASP).
  • Professional experience in Financial Services, particularly in large corporate environments.
  • Experience in reviewing and amending IT and Cyber Third-Party clauses in contracts.
  • Process design and business analysis, particularly in IT and security risk management.
  • Delivery of presentations and training to stakeholders on risk-related topics.
  • Strong IT background, with exposure to operational and security risk management.
  • Strong analytical and synthesis skills – ability to distill complex technical risks into clear, actionable insights for management.
  • Excellent communication and influencing skills – capable of engaging with technical experts, business stakeholders, and external suppliers.
  • Autonomous, proactive, and results-driven with a structured and methodical approach.
  • Ability to manage multiple priorities in a dynamic, multicultural environment.
  • Negotiation and conflict-resolution skills for contractual and risk mitigation discussions.
  • Ability to capture and adapt to stakeholder expectations while respecting processes in place.
  • Ability to mentor/coach people.

Consultancy Advantages at Keystone Solutions:

  • As a consultant, you will work on-site at the client, bringing Keystone Solutions’ expertise and values to every engagement.
  • Experience a wide variety of dynamic projects and challenges across diverse client environments.
  • Accelerate your professional development with turbo-charged learning and broad exposure to industry best practices.
  • Grow your career ambitions within a framework that supports your progression and recognizes your achievements.
  • Being a “K-Stone” means embodying core values and delivering excellence in every mission.

Work Location:

Brussels (50% on site & 50% homeworking expected)

Travel:

Frequency and location or N/A

If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.