Security Officer
Are you the person who makes sure IT keeps running when things don’t go according to plan?
We are looking for an experienced IT Service Continuity Officer to join the CISO team in Brussels. In this key role, you will take ownership of the vision, strategy and implementation of initiatives related to IT Service Continuity, Disaster Recovery, Information Security and IT Risk Management.
Reporting directly to the CISO, you will have a broad impact across the organization and work closely with IT and business stakeholders, external service providers, the Data Protection Officer, Business Continuity teams and internal audit.
If you enjoy combining IT resilience, risk management, cybersecurity and stakeholder management, this is an excellent opportunity to play a key role in strengthening an organization's ability to withstand and recover from disruption.
Role
IT Service Continuity Management
- Act as the central coordination point for IT resilience and Service Continuity activities.
- Identify, assess, manage and report on IT Service Continuity Management (ITSCM) risks.
- Assess IT resilience and Disaster Recovery readiness, including the capabilities of external service providers.
- Work closely with technical architects and subject-matter experts to assess resilience documentation, recovery strategies and controls.
- Ensure Service Continuity requirements are incorporated into IT projects and operational planning.
- Align IT Service Continuity with Business Resilience requirements and support business objectives.
- Develop and embed a structured Disaster Recovery testing cycle covering application and data recovery.
- Monitor and report on recovery tests, lessons learned and improvement actions.
- Develop ITSCM awareness, training and communication initiatives.
Information Security & Risk Management
- Contribute to the implementation and continuous improvement of the Information Security Management System (ISMS).
- Develop and maintain information security policies, standards, procedures and guidelines.
- Monitor implementation and provide clear reporting on security and risk-related matters.
- Support Information Security awareness initiatives.
- Provide tactical Information Security advice to IT and business projects.
- Coordinate projects and initiatives within the CISO organization.
- Support the handling of information and cybersecurity incidents, including coordination of forensic activities.
- Manage the day-to-day follow-up of the CISO mailbox and related actions.
- Contribute to the definition and implementation of Information Risk Management policies, standards and procedures.
- Maintain the information risk register.
- Perform risk assessments, including Business Impact Assessments (BIAs) and Threat & Vulnerability Assessments.
IT Risk Management
- Identify, analyze and report on IT risks, with particular focus on IT Service Continuity.
- Maintain the IT risk register and provide management reporting.
- Ensure identified risks are appropriately followed up and mitigated.
- Help integrate IT risk management processes into existing business and IT processes.
You will collaborate closely with stakeholders across the organization, including IT teams, business owners, the Data Protection Officer, Business Continuity process owners and champions, and internal auditors.
Profile
You are an analytical, pragmatic and proactive professional who can connect technology, risk, security and business requirements.
You bring:
- A Master's degree or equivalent professional experience.
- 3–10 years of relevant experience in IT Service Continuity, IT Risk Management and/or Information Security.
- Knowledge of frameworks and standards such as ISO 22301, ISO 2700x, ISO 31000, NIST, COBIT 5 and ITIL.
- Broad knowledge of IT processes and technologies.
- Knowledge of security architectures and controls.
- Understanding of infrastructure resilience, including data centers, GCP and Azure IaaS/PaaS.
- Experience assessing and monitoring security and resilience at external service providers.
- Strong analytical and problem-solving skills.
- Excellent presentation, communication and facilitation skills.
- Project and change management experience.
- A customer-oriented mindset and strong organizational awareness.
- The ability to work independently while collaborating effectively with multiple stakeholders.
- Fluency in Dutch or French, both spoken and written, with a good understanding of the other language.
Certifications such as BCI, CISSP, CISM, CISA or CRISC are considered an asset.
Offer
A challenging and varied role with significant responsibility and visibility across the organization.
The opportunity to contribute directly to the organization's IT resilience, cybersecurity and risk strategy.
A competitive salary package with numerous extra-legal benefits.
Group insurance and hospitalization insurance for you and your family.
Employee discounts and Benefits at Work.
Vacation days supplemented with ADV days.
Meal vouchers.
Mobile phone subscription and a voucher towards the purchase of a mobile phone.
Company car with fuel or charging card.
Bonus.
Extensive professional and technical learning and development opportunities.
A modern working environment with a collaborative and supportive team.
A stable organization that values solidarity, empathy and expertise.
The flexibility to work from home several days a week.
Opportunities to grow your career horizontally, vertically or diagonally, according to your ambitions.
3 dagen telewerken