IT & Cyber Third Party Risk Assessor - Contract, Brussels
We are partnering with our client, a leading organisation in the banking sector, to recruit an experienced IT & Cyber Third Party Risk Assessor for their Governance, Risk & Compliance (GRC) team. In this strategic role, you will safeguard our client's operations by assessing and managing IT and cyber risks related to external vendors and intragroup providers, with a strong focus on cloud services and key technology partners.
Key Skills & Experience
- Third-Party IT & Security Assessments - Conduct due diligence, evaluate controls and ensure suppliers meet security and regulatory expectations.
- Cloud Security (SaaS, IaaS, PaaS) - Assess cloud solutions and providers, reviewing architectures and risk mitigations.
- Vulnerability Management & Penetration Testing - Analyse reports, challenge remediation plans and track closure of critical findings.
- Application Security - Identify and assess application-related risks and ensure appropriate security measures.
- Risk & Control Frameworks (ISO 27001, SOC 2, NIST, OWASP) - Apply recognised standards to structure assessments and recommendations.
- Contractual IT & Cyber Clauses - Review and negotiate security clauses with Procurement and Legal to embed robust protections.
- Audit & GRC Practices - Coordinate supplier audits, use GRC tools (e.g. ServiceNow) and support continuous monitoring.
- Stakeholder Management - Collaborate with cyber defense, security architects, continuity experts, DPOs, and business teams.
- Soft Skills - Strong analytical capabilities, clear communication, structured approach, negotiation skills, and ability to coach and influence across our client's team.
- Languages - French and English are mandatory Dutch is a plus.
Working Model
- 50% onsite in Brussels
- 50% remote
If this aligns with your profile in information security and cyber risk, we would welcome a discussion about joining our client's team.
To find out more about Huxley please visit www.huxley.com