Rhox

IT And Cyber Third Party Risk Assessor

Closes on 16/10/2026
Brussels
Hybrid, 50% on site
Starts as soon as possible
Remuneration: 3.300 - 3.800 EUR/mo gross+ extralegal advantages ·Freelance also possible

Apply for this role

or apply with email & CV

Drag & drop your CV here, or click to browse

PDF, DOC, DOCX, or TXT (max 4MB)

By applying, you agree to our Terms of Service and Privacy Policy.

We're looking for an IT and Cyber Third Party Risk Assessor to assess supplier technology risks and strengthen security controls. The work centres on third-party risk assessments, cloud security and contract reviews.

What you'll do

  • Assess third-party IT and cyber risks during due diligence and periodic reviews.
  • Evaluate cloud controls, data protection and resilience across SaaS, IaaS and PaaS.
  • Review application security, vulnerability and penetration-testing evidence.
  • Challenge supplier IT and cyber contract clauses and agree risk mitigations.
  • Coordinate external audits, track remediation and escalate critical supplier risks.
  • Report risk trends and recommendations, improve assessment methods and train stakeholders.

What you bring

  • 10+ years' professional experience in IT and cyber risk management, focused on third-party risk assessments.
  • Experience assessing cloud security across SaaS, IaaS and PaaS, plus application security, vulnerability management and penetration testing.
  • Knowledge of ISO 27001, SOC 2, NIST and OWASP audit methodologies.
  • Experience reviewing supplier IT and cyber clauses and negotiating contract changes.
  • Financial services experience and a strong IT background in operational and security risk.
  • Experience in process design, business analysis and risk methodology improvement.
  • Experience presenting risk findings and delivering stakeholder training.
  • Ability to turn technical risks into clear recommendations and influence stakeholders.
  • Master's degree in IT, cybersecurity or risk management, or equivalent experience.
  • French (C1), Dutch (C1) and English (C1).

Nice to have

  • Familiarity with ServiceNow and control frameworks.
  • Experience with cloud services such as AWS or HSP.
  • CISSP, CISM, CIPP or CCSK certification.

What's next?

The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.

We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.

It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.