Third-Party Risk Manager – NIS2 Compliance
Position Overview: The Third-Party Risk Manager is responsible for overseeing and mitigating information security risks related to external suppliers, service providers, and business partners. The primary objective is to ensure strict compliance with the NIS2 Directive and international standards such as ISO 27001, safeguarding the organisation from risks introduced by third parties.
- Develop governance structures and processes for third-party risk management, ensuring integration with overall compliance frameworks.
- Evaluate and classify suppliers based on criticality and risk profile, using established methods aligned with NIS2 requirements.
- Conduct due diligence and risk assessments for external partners, with a focus on regulatory compliance and risk mitigation.
- Collaborate closely with internal stakeholders including CISO, procurement, IT, and legal teams, to embed robust security clauses and processes throughout the supplier lifecycle.
- Monitor ongoing compliance through the implementation of KPIs, SLAs, audits, and data-driven reporting dashboards.
- Manage incident reporting and escalation with third-party suppliers in accordance with NIS2 Directive timelines and best practices.
- Organise awareness and training sessions for suppliers, focusing on supply chain security and adherence to NIS2 requirements.
- Act as the central point of contact for all matters relating to third-party information security risk management and NIS2 implementation.
Requirements:
- Demonstrable background in information security, cybersecurity, or risk management roles.
- Thorough knowledge of the NIS2 Directive and/or international standards such as ISO 27001.
- Proven experience managing suppliers, conducting audits, and defining security clauses in contractual agreements.
- Advanced skills in communication, reporting, and stakeholder engagement.
- Fluency in Dutch or French, and professional proficiency in English is essential for this role.
We are looking for candidates who excel in navigating complex compliance environments and have a keen understanding of the evolving regulatory landscape, particularly with regards to information security and supply chain risk. The ideal person is solution-oriented, demonstrating exceptional analytical abilities and a rigorous attention to detail when assessing third-party risks and ensuring robust governance.
- Proven expertise in information security, cybersecurity, or risk management, with a demonstrable track record of implementing best practices and frameworks.
- Strong grasp of the NIS2 Directive as well as standards such as ISO 27001, particularly in the context of supplier management and compliance audits.
- Skilled communicator who collaborates seamlessly with internal teams (such as IT, procurement, legal, and executive leadership) and external partners to drive a shared commitment to security.
- Experience integrating security requirements into contracts, performing due diligence, and establishing effective reporting mechanisms and Key Performance Indicators (KPIs).
- Natural leader and facilitator with the confidence to act as the central point of contact for all matters related to third-party security and NIS2 alignment, fostering awareness through tailored training and stakeholder engagement.
- Insightful evaluator who applies a structured and pragmatic approach to risk assessment, supplier classification, and oversight of contractual compliance, incident reporting, and audit processes.
- Resourceful and proactive mindset, always seeking to anticipate emerging risks and act decisively to uphold the organisation’s security posture.
- Language proficiency in Dutch or French (fluent), with professional-level English communication skills ensuring effective interaction in a multilingual environment.
Those who thrive in this role are diplomatic yet assertive, comfortable making informed judgments, and capable of translating complex regulatory requirements into actionable strategies across the organisation and its third-party ecosystem.
Opportunités similaires
Le job de vos rêves n’est plus qu’à un clic.
Envoyez-nous votre CV et nous vous mettrons directement en contact avec l'un de nos recruteurs spécialisés qui vous guidera dans la recherche de l'emploi de vos rêves !
Derniers articles
Comment mettre en place sa stratégie marque employeur ? Découvrez les 7 étapes
La marque employeur est un concept marketing indispensable à toute entreprise qui souhaite soutenir son attractivité et fidéliser ses talents. Si les raisons de construire une marque employeur solide et positive sont évidentes, ce travail, pour qu’il soit réussi, ne peut se faire en deux temps trois mouvements. Il demande de mettre en œuvre un certain nombre d’actions.
Les tendances incontournables de l’employer branding en 2024
L'employer branding a évolué pour devenir un incontournable pour les entreprises qui cherchent à se distinguer dans la course aux talents.
Marque employeur : 7 erreurs à ne surtout pas commettre
Back Market, KPMG, Dassault, Shine… Ces entreprises de taille différente ont une marque employeur forte leur garantissant une attractivité et une fidélisation à faire pâlir leurs concurrents.
Rejoignez notre communauté active de professionnels et découvrez votre potentiel.
Pour vous tenir au courant de nos dernières actualités.