Se rendre au contenu

Tribe Risk officer - Artificial intelligence (Expert) - BNP Paribas Fortis

Customer: BNP Paribas Fortis Koningsstraat 97 1000 Brussels Belgique
Dates: 2026-09-30 — 2027-11-30
Arrangements: Hybrid - 50% on site & 50% homeworking
Apply before: 2026-10-15

Description

BNP Paribas Fortis is seeking an expert Tribe Risk Officer to support its Artificial Intelligence Tribe in Brussels. The position addresses technology, operational, cybersecurity, regulatory and AI-related risks. The consultant bridges Risk Management, Information Security, Architecture, Delivery Management and business stakeholders. The objective is to turn fragmented findings into measurable remediation roadmaps.

The consultant owns the risk lifecycle from identification through closure and coordinates remediation across squads. Work includes analyzing audit findings, structuring risk themes, defining mitigation actions and tracking dependencies and residual exposure. The role involves regular risk reviews, quarterly evaluation meetings and executive reporting. It also supports AI governance, operational resilience and regulatory compliance.

Candidates need at least five years of relevant technology or risk experience and a strong background in remediation governance and Agile delivery. Cross-functional leadership, clear executive communication and constructive challenge are essential. AI governance expertise and relevant certifications are advantages. The assignment is based in Brussels with a 50/50 on-site and homeworking expectation and occasional group-entity travel.

Top Reasons to Apply
AI governance exposure
★★★★★
Enterprise risk leadership
★★★★★
Cross-functional stakeholder influence
★★★★★
Regulatory transformation impact
★★★★★
Hybrid working arrangement
★★★★★
Responsibilities
Analyze and challenge risk findings raised by Internal Audit, Information Security, Risk Management, Architecture reviews and external assessments.
Consolidate and restructure risk observations into coherent risk themes, remediation streams and implementation plans.
Define practical mitigation actions and ensure alignment with architecture, security, operational and regulatory requirements.
Coordinate with squads, architects, product owners and tribe leadership to secure execution of remediation activities.
Monitor implementation progress, dependencies, residual risks and target dates.
Report overall risk posture, remediation status and risk reduction achievements to Tribe management and governance bodies.
Contribute to the development of a sustainable risk management culture across the Tribe.
Organise quarterly risl evaluation meetings to track progress on audits and risk closure.
Must Have
Bachelor or Master degree in Information Technology, Engineering, Cybersecurity, Risk Management or equivalent through experience.
Minimum 5 years of experience in IT Risk, Operational Risk, Cybersecurity, Technology Governance or Technology Transformation.
Demonstrated experience managing complex remediation programs across multiple stakeholders.
Experience in translating audit findings and risk assessments into actionable delivery plans.
Strong experience in Operational Risk, IT Risk and Cyber Risk Management.
Experience with risk remediation planning and implementation governance.
Experience working with Agile organizations (Tribes, Squads, Chapters).
Strong understanding of software delivery, DevSecOps and cloud environments.
Nice to Have
Experience in AI Governance, Model Risk Management or Responsible AI practices.
Familiarity with NIST AI RMF, EU AI Act or emerging AI governance frameworks.
Knowledge of financial sector regulatory environments.
Experience within banking, insurance or financial services.
Experience with regulatory inspections, internal audits or supervisory reviews.
Knowledge of either French or Dutch
CRISC certification
CISA certification
CISSP certification
ISO27001 Lead Implementer / Lead Auditor certification
PMP, Prince2 or Agile certification
ITIL Foundation certification

Detailed Responsibilities and Skills

Additional Responsibilities

  • Own the end-to-end lifecycle of risks from identification to closure.
  • Review existing risk inventories and transform fragmented findings into structured remediation programs.
  • Translate risk statements into concrete implementation actions, backlog items, epics and delivery plans.
  • Define target operating models and mitigation roadmaps together with architects and delivery teams.
  • Ensure risks are properly assessed, prioritized and documented.
  • Challenge remediation proposals to ensure they address root causes and not only symptoms.
  • Coordinate risk reduction initiatives across multiple squads and stakeholders.
  • Facilitate regular risk review sessions with Tribe leadership.
  • Maintain a consolidated view of risk exposure, mitigation progress and residual risks.
  • Prepare management reporting and executive-level summaries.
  • Support audits, regulatory reviews and control assessments.
  • Build trusted relationships with Product Owners, Architects, Delivery Leads, Security Officers and Business representatives.
  • Contribute to the continuous improvement of risk management frameworks, tooling and reporting.
  • Support the implementation of AI governance, operational resilience and regulatory compliance requirements where applicable.
  • Act as the Tribe's Single Point of Contact for risk governance activities.

General skills

  • Bachelor or Master degree in Information Technology, Engineering, Cybersecurity, Risk Management or equivalent through experience.
  • Minimum 5 years of experience in IT Risk, Operational Risk, Cybersecurity, Technology Governance or Technology Transformation.
  • Demonstrated experience managing complex remediation programs across multiple stakeholders.
  • Experience in translating audit findings and risk assessments into actionable delivery plans.
  • Strong knowledge of risk management frameworks and control methodologies.
  • Experience in large and complex organizations.
  • Experience managing cross-functional transformation initiatives.
  • Experience leading workshops and facilitating stakeholder alignment.
  • Experience preparing and presenting executive-level reporting.
  • Ability to challenge stakeholders constructively and influence decision-making.
  • Strong analytical and problem-solving capabilities.
  • Ability to structure ambiguity into actionable plans.
  • Excellent communication and influencing skills.
  • Strong stakeholder management capabilities.
  • Strong organizational and planning skills.
  • Ability to work independently while driving collaboration across teams.
  • Results-oriented and execution-focused mindset.
  • Excellent presentation and reporting skills.
  • Ability to challenge constructively and facilitate consensus.
  • Strong writing skills, capable of producing concise executive documentation.
  • Comfortable operating in a fast-moving and complex environment.
  • Strong sense of ownership and accountability.
  • Ability to mentor and coach teams on risk management practices.
  • French or Dutch knowledge is a plus
  • English proficiency requirement unspecified
  • Experience within banking, insurance or financial services.
  • Experience with regulatory inspections, internal audits or supervisory reviews.

Technical skills

  • Strong experience in Operational Risk, IT Risk and Cyber Risk Management.
  • Experience with risk remediation planning and implementation governance.
  • Experience working with Agile organizations (Tribes, Squads, Chapters).
  • Strong understanding of software delivery, DevSecOps and cloud environments.
  • Experience with SaaS platforms, public cloud and enterprise platforms.
  • Knowledge of security frameworks and control environments.
  • Experience in change management, release management and operational governance.
  • Experience working with multi-disciplinary teams including Architecture, Security and Delivery.
  • Strong reporting and executive communication skills.
  • Experience in AI Governance, Model Risk Management or Responsible AI practices.
  • Familiarity with NIST AI RMF, EU AI Act or emerging AI governance frameworks.
  • Knowledge of financial sector regulatory environments.

Tools and certifications

  • SaaS platforms, public cloud and enterprise platforms
  • DevSecOps
  • Agile Tribes, Squads and Chapters
  • NIST AI RMF and EU AI Act (preferred)
  • CRISC certification
  • CISA certification
  • CISSP certification
  • ISO27001 Lead Implementer / Lead Auditor certification
  • PMP, Prince2 or Agile certification
  • ITIL Foundation certification