CISO Officer
Job Opportunity: CISO Officer
Location: Brussels + Remote
Languages: Dutch, French, English
Start Date: 7th September 2026
End Date: 31st August 2027
Deadline for Application: 11th August 2026
Job Title: CISO Officer TPRM
Description:
We are looking for a CISO Officer to ensure effective management of cybersecurity risks related to third parties, including suppliers, partners, service providers, integrators, and vendors. The role involves integrating and enforcing cybersecurity requirements within procurement and tendering processes (RFI, RFC, RFQ, RFP, tenders, etc.), in alignment with the CISO strategy, regulatory frameworks, and organizational standards. The aim is to ensure that security commitments with third parties are consistent, compliant, controlled, and traceable from a technical, regulatory, and contractual perspective throughout the entire lifecycle of the third-party relationship.
Main Activities:
- Third Party Risk Management (TPRM):
- Establish, maintain, and continuously improve the cybersecurity third-party risk management framework, aligning with applicable regulatory and industry standards.
- Identify, analyze, and assess cybersecurity risks associated with third parties based on security questionnaires, supporting documentation (certifications, policies, audit reports), and reviews of proposed architectures or solutions.
- Define, monitor, and document risk mitigation measures, acceptance conditions, and related action plans.
- Procurement Processes and Tender Documentation:
- Review and secure cybersecurity requirements within procurement processes (RFI, RFC, RFQ, RFP, etc.) and tender documentation, ensuring compliance with applicable reference frameworks.
- Assess suppliers’ responses and proposals from a security, compliance, and risk management perspective.
- Contribute to drafting security-related responses and identify associated risks, conditions, and commitments, in collaboration with relevant stakeholders.
- Reporting and Continuous Improvement:
- Ensure reporting and monitoring of third-party risks and reviewed RFPs.
- Provide consolidated visibility to the CISO and management, and propose continuous improvement actions.
Conformity Criteria:
- Fluent communication in Dutch, French, and English (spoken and written). Dutch or French at C1 level, the other language at least B2, English at least C1.
- Master’s degree in a relevant field such as IT, law, risk management, or information security.
- At least one active certification valid at submission date from the following list: ISC2 CISSP, CCSP, ISACA CISA, CRISC, CISM, CDPSE, or CGEIT.
- Minimum 5 years of experience in domains such as Third Party Risk Management, Security Assurance, GRC/compliance, Audit, or security assessment.
- Proven experience in reviewing procurement documentation (RFI, RFQ, RFP, etc.).
- Willing to work on-site at least 2 days per week in Brussels.
Evaluation Criteria:
- Level of experience with cybersecurity frameworks (number of projects, role, responsibilities).
- Experience in assessing IT/security architectures (scope, number of assessments, role).
- Experience in analyzing cybersecurity requirements and procurement documentation (scope and tasks).
- Experience in producing deliverables (type: reports, policies, assessments).
- Experience in analytical tasks (risk analysis, compliance, audits).
- Experience in drafting structured reports (type, audience, context).
- Level and complexity of stakeholder management (IT, Legal, CISO, etc.).
- Experience in risk-based decision making (examples in CV).
- Degree of autonomy in previous roles (lead vs support).