Senior IT and Cyber Third Party Risk Assessor
IT
Mission.
The mission consists of strengthening IT and Cyber third-party risk management practices by structuring risk assessment processes, improving visibility on risk exposure, and enhancing control over third-party activities.
The role focuses on identifying, assessing, and mitigating operational IT and Cyber risks across applications, projects, and external partners, while ensuring alignment with Information Security policies and regulatory frameworks.
Beyond risk assessment, the objective is to improve consistency, governance, and monitoring of third-party risk activities, enabling better decision-making and optimized risk reduction at controlled cost.
The goal is to enable the organization to enhance its overall risk posture, ensure compliance, and strengthen control over third-party IT and security risks within a complex operational environment.
Key Responsibilities
- IT & Cyber Risk Assessment and Management
- Third-Party Risk Oversight
- Risk Governance and Reporting
- Process Structuring and Improvement
- Advisory and Stakeholder Support
Required profile.
- IT Risk and Security Risk Management (Expert, current experience)
- Third-Party Risk Assessments and Audits (Advanced, current experience)
- IT Control Frameworks and Audit Methodologies (Advanced, current experience)
- Risk Governance, Reporting, and Monitoring (Advanced, current experience)
- Process Design and Improvement (Advanced, 1–3 years experience)
- IT Security Frameworks (ISO27001, NIST, SOC, OWASP, etc.) (Advanced, current experience)
- Data Protection, Access Management, and Business Continuity (Preferred)Experience in large organizations / Financial Services (Preferred)
Experience
- At least 3+ years of experience in IT Risk Management
- Proven experience in operational and security risk management
Technical Expertise
Mandatory
- Strong background in IT and Information Security
- Knowledge of control frameworks and audit methodologies
Preferred
- Experience in third-party IT and security assessments
- Experience in process improvement and governance structuring
- Security certifications such as CISSP, CISM, CIPP, CCSK
Business Knowledge
Mandatory
- Strong understanding of Information Security and Risk Management frameworks
- Solid IT background
Education & Certifications
- Bachelor’s or Master’s degree (or equivalent experience)
- Security certifications (CISSP, CISM, CIPP, CCSK) are considered a strong asset
Languages
- French – Fluent (or Dutch)
- Dutch – Fluent (or French)
- English – Good professional proficiency