IT & Cyber Third Party Risk Management Expert - HQ Brussels

EDITX BV· Arr. de Bruxelles-Capitale/Arr. Brussel-Hoofdstad· EURES· published 07/14/2026
Must-have:CloudSecuritySenior

YOUR JOB IN A NUTSHELL

As a Third-Party Technology Risk Management (TPTRM) Expert in our CoE Security - Governance, Risk & Compliance team, you will assess, evaluate and monitor IT and cybersecurity risks related to intragroup and external suppliers. Join our Brussels-based team of 10 specialists, where you will collaborate closely with internal and external stakeholders to ensure robust risk management in a dynamic environment.

AND IN DETAIL

  • Conduct comprehensive IT and cyber risk assessments of third-party suppliers (intragroup and external) and cloud-based solutions to evaluate their cybersecurity posture, IT controls, and compliance with regulatory requirements.
  • Review, challenge, negotiate, and embed IT and cybersecurity clauses in supplier contracts, collaborating with Procurement, Legal, and Business teams.
  • Coordinate onsite audits, validate findings, and drive remediation plans with third parties, escalating critical risks to stakeholders.
  • Track third-party security posture through periodic reviews (vulnerability reports, incident responses, compliance attestations) and synthesize risks for senior management via dashboards.
  • Enhance TPTRM methodologies, tools, and templates (e.g., risk assessment questionnaires, audit guidelines) to reflect emerging threats and regulatory changes.

YOUR TALENTS AND COMPETENCES

  • You are an expert in cybersecurity, risk management, and compliance, including deep knowledge of cyber threats, frameworks (ISO 27001, SOC, NIST, OWASP), and you are able to provide expert security guidance.
  • You have 10+ years of experience in IT & Cyber Risk Management with a strong focus on third-party technical security risk assessments, supplier/vendor evaluations, audit methodologies and cloud security (SaaS, IaaS, PaaS).
  • You have contractual and IT security review skills, including experience in reviewing and amending IT and cybersecurity clauses in contracts.
  • You have some experience in process design and business analysis, particularly in IT and security risk management.
  • You have worked in the Financial services industry, particularly in large corporate environments, with a focus on IT and security risk management.
  • You have strong analytical and synthesis skills – you are able to distill complex technical risks into clear, actionable insights for management.
  • You are an excellent communicator, capable to influence and engage with technical experts, business stakeholders, and external suppliers.
  • You are autonomous, proactive, and results-driven with a structured and methodical approach.
  • You have strong English professional written and verbal persuasion skills and fluent in French (mandatory) or Dutch.