CISO Officer
Function
We’re looking for a CISO Officer specialized in Third Party Risk Management to join our client’s cybersecurity team. In this role, you will play a key part in strengthening the organization’s cybersecurity posture by ensuring that risks related to external partners, suppliers, and service providers are effectively assessed and managed. You will work closely with procurement, legal, IT, and security teams to integrate cybersecurity requirements into procurement processes and ensure compliance with internal standards, regulatory frameworks, and security best practices.
Role & Responsibilities
As part of the cybersecurity governance structure, you will focus on evaluating and managing risks associated with third-party relationships and ensuring that security requirements are embedded throughout procurement and vendor management processes.
-
Establish, maintain, and continuously improve the cybersecurity Third Party Risk Management framework in alignment with regulatory and industry standards.
-
Identify, analyze, and assess cybersecurity risks related to suppliers, partners, integrators, and service providers.
-
Review security questionnaires, certifications, policies, audit reports, and technical documentation to evaluate supplier security maturity.
-
Define and track risk mitigation actions, acceptance criteria, and remediation plans.
-
Ensure cybersecurity requirements are correctly integrated into procurement and tendering processes such as RFI, RFQ, and RFP documentation.
-
Assess supplier proposals from a cybersecurity and compliance perspective and identify potential risks or contractual security obligations.
-
Collaborate with internal stakeholders to define security-related requirements and contribute to procurement responses.
-
Provide structured reporting and visibility on third-party risks and reviewed procurement files to cybersecurity leadership.
-
Contribute to continuous improvement initiatives within the organization’s cybersecurity governance framework.
Profile & Experience
Our client is looking for a cybersecurity professional with strong experience in governance, risk management, and third-party security assessments.
-
Master’s degree in IT, information security, risk management, law, or a related field (or Bachelor’s degree with relevant experience).
-
Minimum 5 years of experience in cybersecurity-related roles such as Third Party Risk Management, Security Assurance, GRC/compliance, audit, or security assessment.
-
Experience reviewing procurement documentation such as RFI, RFQ, RFP, or other tendering processes from a cybersecurity perspective.
-
Strong knowledge of cybersecurity standards and frameworks including ISO 27001/27002, NIS2, GDPR, ISO 27036, CyFun, and ISA/IEC 62443.
-
Ability to evaluate technical architectures and supplier solutions from a cybersecurity risk perspective.
-
Experience analyzing supplier questionnaires, contractual clauses, and security commitments.
The Ideal Candidate
-
Strong analytical mindset with excellent written and documentation skills.
-
Ability to synthesize complex information and produce clear, structured deliverables.
-
Comfortable interacting with multiple stakeholders including procurement, legal, IT teams, business units, and cybersecurity leadership.
-
Solution-oriented mindset with strong attention to detail and risk awareness.
-
Able to work autonomously while maintaining strong collaboration within the team.
-
Fluent in Dutch, French, and English (Dutch or French at C1/native level, the other language at least B2, English at least C1).
-
Available to work on-site two days per week.