IT and Cyber Third-party Risk Assessor
Mission context | Our client’s Risk and Compliance team supports IT and Business Units to develop adequate solutions on operational risk management practices, focusing but not restricted to Information Security. Their main missions are: – Identify operational IT and Cyber risks on assets/applications, projects and 3rd-parties. – Advice, consult, monitor and report on risk treatment in order to reduce the overall risk exposure of IT and Business at an optimized cost. – Elaborate and manage the implementation of a flexible strategy to reduce IT and Information Security risks in accordance to the IT and Information Security policies of the company. |
|||
Function description | – you execute IT and security risk assessments in IT and business, scoping projects or legacy assets (applications, business solutions, 3rd-parties organization, processes…). Maintenance of identified risks in the risk registry database – you ensure that information security and IT requirements are included in third party’s contracts. – you execute the information security and IT control plans on third parties to ensure that they are performing accordingly with the contract. – you coordinate and perform IT and security audits on third parties. – you set up processes and procedures for an end to end IT and security management for third-parties. – you deliver consulting on risk management to internal customers (IT and Business) :
– you report risks and overall risk posture regarding Third-parties to Information Security, IT or Business Management
– you manage customer relationship and are the Single Point Of Contact for the risk management services you delivered. You customize services to meet customer needs or expectations while ensuring compliance with risk management methodologies and guidelines of company. |
|||
Language requirements | Dutch | Fluent | ||
French | Fluent (mandatory) | |||
English | Fluent (mandatory) | |||
Education | Master or equivalent by experience | |||
Certification | (Preferable) Security certifications like CISSP, CISM, CIPP, CCSK. | |||
Required experience / knowledge |
|
|||
Technical experience | mandatory |
|
||
preferable |
|
|||
Business experience | mandatory |
|
||
preferable |
|
|||
Soft skills |
|