Digital Risk & Compliance Officer – GRC & Security Frameworks
Digital
Security
Junior (0+)
- Emplacement
- Ixelles, Bruxelles-Capitale
- Type de travail
- Consultancy
- Modèle de travail
- Fulltime, Hybrid
Our client, a leading organization in the legal sector, is undergoing a significant digital transformation involving cloud technologies and AI applications. A dedicated professional is required to manage digital risks and ensure compliance across the growing digital landscape while facilitating secure organizational growth.
Responsabilités
- Develop and maintain information security policies, standards, and procedures in alignment with organizational goals.
- Conduct structured risk assessments across IT systems and third-party vendors using frameworks such as CIS18, ISO 27001, or NIST.
- Monitor the threat landscape to proactively identify and mitigate emerging risks relevant to the project.
- Contribute to internal and external IT audits and test the effectiveness of digital controls.
- Collaborate with cross-functional teams to embed security and compliance requirements into operational processes and digital projects.
- Implement pragmatic security controls and build digital risk awareness courses for employees.
- Assess the risk profiles and compliance posture of critical SaaS vendors and digital partners.
Exigences
- You bring 1+ years of experience in information security, IT risk management, or a related discipline.
- You possess practical knowledge of security frameworks and standards such as ISO 27001, CIS18, and NIST CSF.
- You have a solid understanding of regulatory requirements including GDPR, NIS2, and the EU AI Act.
- You're experienced in conducting vendor risk assessments and collaborating on IT audits.
- You have a technical understanding of Azure cloud governance, Microsoft 365, and hybrid infrastructure.
- You possess knowledge of Identity & Access Management concepts including RBAC, PAM, MFA, and Entra ID.
- You bring familiarity with vulnerability management processes and tooling such as Qualys or Tenable.
- You are fluent in French and English.
Nice to Haves
- Possession of ISO 27001 Foundation, ISO 27001 Lead Implementer, or CompTIA Security+ certifications.
- Experience setting up an ISMS or GRC platform to manage controls and risks.
- Understanding of secure software development practices and application-level risks.
- Knowledge of Dutch.
Offre
- Start date: ASAP
- Duration: 6–12 months
- Work regime: Full-time
- Location: Brussels
- Working model: Hybrid (4 days onsite, 1 day remote)
- Contract: open to both permanent employees and freelancers
# 102189
Discuter avec Alex
Vous hésitez à postuler ? Discutez avec Alex, notre coach carrière IA, et découvrez les offres qui vous correspondent.
)