Overslaan naar inhoud

Sollicitatieformulier

Provide either a resume file or a linkedin profile
Functieomschrijving
Vacature
CISO Officer TPRM (YPTO001875)
Locatie
Brussel (Anderlecht), België

CISO Officer TPRM

DESCRIPTION
Ensure effective management of cybersecurity risks related to third parties (suppliers, partners, service providers, integrators, vendors) as well as the integration and enforcement of cybersecurity requirements within procurement and tendering processes (RFI, RFC, RFQ, RFP, tenders, etc.), in alignment with the CISO strategy, regulatory frameworks, and the organization’s standards.

The role aims to ensure that security commitments made with third parties are consistent, compliant, controlled, and traceable from a technical, regulatory, and contractual perspective throughout the entire lifecycle of the third-party relationship.

MAIN ACTIVITIES

  • Third Party Risk Management (TPRM)
    • Establish, maintain, and continuously improve the cybersecurity third party risk management framework, in alignment with applicable regulatory and industry standards.
    • Identify, analyse, and assess cybersecurity risks associated with third parties based on security questionnaires, supporting documentation (certifications, policies, audit reports), and reviews of proposed architectures or solutions.
    • Define, monitor, and document risk mitigation measures, acceptance conditions, and related action plans.
  • Procurement Processes and Tender Documentation
    • Review and secure cybersecurity requirements within procurement processes (RFI, RFC, RFQ, RFP, etc.) and tender documentation, ensuring compliance with applicable reference frameworks.
    • Assess suppliers’ responses and proposals from a security, compliance, and risk management perspective.
    • Contribute to drafting security-related responses and identify associated risks, conditions, and commitments, in collaboration with relevant stakeholders.
  • Reporting and Continuous Improvement
    • Ensure reporting and monitoring of third-party risks and reviewed RFPs.
    • Provide consolidated visibility to the CISO and management, and propose continuous improvement actions.

CONFORMITY CRITERIA

Evidence of compliance with the requested skills (criteria) needs to be provided in the CV.

  • You communicate fluently in Dutch, French and English (spoken and written). Dutch or French at C1 level, the other language at least B2, English at least C1.
  • Master’s degree in a relevant field from the following list: IT, law, risk management, information security.
  • At least one active certification valid at submission date from the following list: ISC2 CISSP, CCSP, ISACA CISA, CRISC, CISM, CDPSE, or CGEIT.
  • Minimum 5 years of experience in at least one of the following domains: such as Third Party Risk Management, Security Assurance, GRC / compliance, Audit or security assessment.
  • Proven experience in reviewing procurement documentation (RFI, RFQ, RFP, etc.)
  • Willing to work on-site at least 2 days per week in Brussels

EVALUATION CRITERIA

The more experience the better your proposal will be evaluated for this criterion.

  • Level of experience with cybersecurity frameworks (number of projects, role, responsibilities)
  • Experience in assessing IT/security architectures (scope, number of assessments, role)
  • Experience in analyzing cybersecurity requirements and procurement documentation (scope and tasks)
  • Experience in producing deliverables (type: reports, policies, assessments)
  • Experience in analytical tasks (risk analysis, compliance, audits)
  • Experience in drafting structured reports (type, audience, context)
  • Level and complexity of stakeholder management (IT, Legal, CISO, etc.)
  • Experience in risk-based decision making (examples in CV)
  • Degree of autonomy in previous roles (lead vs support)