About this role
We are partnering with our client, a leading organisation in the banking sector, to recruit an experienced IT & Cyber Third Party Risk Assessor for their Governance, Risk & Compliance (GRC) team. In this strategic role, you will safeguard our client's operations by assessing and managing IT and cyber risks related to external vendors and intragroup providers, with a strong focus on cloud services and key technology partners. Working Model 50% onsite in Brussels 50% remote If this aligns with your profile in information security and cyber risk, we would welcome a discussion about joining our client's team. To find out more about Huxley please visit www.huxley.com Third-Party IT & Security Assessments - Conduct due diligence, evaluate controls and ensure suppliers meet security and regulatory expectations. Cloud Security (SaaS, IaaS, PaaS) - Assess cloud solutions and providers, reviewing architectures and risk mitigations. Vulnerability Management & Penetration Testing - Analyse reports, challenge remediation plans and track closure of critical findings. Application Security - Identify and assess application-related risks and ensure appropriate security measures. Risk & Control Frameworks (ISO 27001, SOC 2, NIST, OWASP) - Apply recognised standards to structure assessments and recommendations. Contractual IT & Cyber Clauses - Review and negotiate security clauses with Procurement and Legal to embed robust protections. Audit & GRC Practices - Coordinate supplier audits, use GRC tools (e.g. ServiceNow) and support continuous monitoring. Stakeholder Management - Collaborate with cyber defense, security architects, continuity experts, DPOs, and business teams. Soft Skills - Strong analytical capabilities, clear communication, structured approach, negotiation skills, and ability to coach and influence across our client's team. Languages - French and English are mandatory Dutch is a plus.