Third Party IT Security & Risk Analyst – Banking Client – Brussels
- Duration: 6-12 months
- Rate: 600 – 650 Euro per day
- Hybrid working: onsite presence is 1-3 days per month in Brussels
IT and Cyber Risk Team
Aligning with the overall corporate mission of being a ‘trusted Financial Market Infrastructure’, the ‘IT and Cyber Risk’ team within CISO Division provides several services that aim to:
- Ensure ‘end-to-end’ management of risks by identifying IT, information security or cyber risks or deficiencies
- Ensure root cause issues and risks are structurally remediated through sustainable controls, and ensure reduce risk exposure through increased control maturity
- Ensure risk exposure is in line with the risk appetite of the firm
- Ensure regulatory compliance is evidenced
- Ensure accountability, ownership and risk culture is embed within first line
Within the context of the overall Enterprise Risk Management (ERM) framework, the IT and Cyber Risk team provides a strong control environment based on internationally recognized controls that allows all IT, information security and cyber risks to be continually identified, assessed, monitored, and mitigated (or accepted).
Role Description – IT Security Manager
The role will be responsible for execution of risk-based IT Security controls for Third Parties. Key responsibilities:
Customer and Third-Party Assurance Lifecycle
- Due Diligence – risk profiling, onboarding, re-certification
- Contract Management – ensuring that the security expectations included in the contract are proportionate to the risk profiling
- Exit Management – performance of necessary security checks at the end of a contractual agreement with a Third Party
Ecosystem Third Party Security Monitoring & Alerting
- Continuous, automated monitoring of Third Party related Cyber Threats with the potential to impact the client . Monitoring is executed with the help Cyber Threat intelligence tools. The capability enables the client to quickly act, limiting the risk of contagion or severity of impacts.
- Continuous monitoring, alerting and incident management of external connections based on several distinct use-cases
Core Skills
- Knowledge of the customer, third-party and connectivity ecosystems
- Knowledge of security risk management
- Knowledge of control frameworks, e.g., ISO 27000, NIST, CIS-18, COBIT-5
- Knowledge of logging, monitoring and alerting is an advantage
- Knowledge of similar ecosystem frameworks, e.g., SWIFT CSP is an advantage
- Knowledge of financial markets, FMIs and CSD operations is an advantage
- Experience with supplier and supply chain due diligence framework, procedures, data gathering risk and control assessment.
- Experience with contract review of information security schedules and terms
- Knowledge of logging, monitoring and alerting is an advantage
- Experience with ServiceNow GRC is an advantage
- IT Security Certification such as CISSP, CSSLP, CCSP, CISM, CISMP, GCIH, CEH, etc. is an advantage.
Soft Skills
- Be an inspiring and engaging leader by providing strategy and direction to team members, by showing business acumen, by possessing self-reflection and by being results-driven
- Be self-motivated and proactive, have strong, innovative and creative problem-solving skills, be open and welcoming to change, work comfortably in a constantly evolving environment and have an ability to remain calm under pressure and in the face of uncertainty.
- Work comfortably with business executives and stakeholders, within group settings or with team-members
- Ability to handle multiple projects against tight deadlines whilst being instrumental in delivering cultural change throughout the organisation
Please do send across to me the most up to date CV to eobiechefu@welovesalt.com
Job Information
Job Reference: JO-2304-333230
Salary: €600 - €650 per day
Salary per: day
Job Duration: 6-12 months
Job Start Date: ASAP
Job Industries: Cyber Security Jobs
Job Locations: Greater London
Job Types: Contract
Job Skills: CIS-18, COBIT-5, ISO 27000, IT security, NIST, Third Party