Pauwels Consulting Logo
Apply now

Digital Risk & Compliance Officer – GRC & Security Frameworks

Digital
Security
Junior (0+)
Location
Ixelles, Brussels-Capital
Work type
Consultancy
Work model
Fulltime, Hybrid

Our client, a leading organization in the legal sector, is undergoing a significant digital transformation involving cloud technologies and AI applications. A dedicated professional is required to manage digital risks and ensure compliance across the growing digital landscape while facilitating secure organizational growth.

Responsibilities

  • Develop and maintain information security policies, standards, and procedures in alignment with organizational goals.
  • Conduct structured risk assessments across IT systems and third-party vendors using frameworks such as CIS18, ISO 27001, or NIST.
  • Monitor the threat landscape to proactively identify and mitigate emerging risks relevant to the project.
  • Contribute to internal and external IT audits and test the effectiveness of digital controls.
  • Collaborate with cross-functional teams to embed security and compliance requirements into operational processes and digital projects.
  • Implement pragmatic security controls and build digital risk awareness courses for employees.
  • Assess the risk profiles and compliance posture of critical SaaS vendors and digital partners.

Requirements

  • You bring 1+ years of experience in information security, IT risk management, or a related discipline.
  • You possess practical knowledge of security frameworks and standards such as ISO 27001, CIS18, and NIST CSF.
  • You have a solid understanding of regulatory requirements including GDPR, NIS2, and the EU AI Act.
  • You're experienced in conducting vendor risk assessments and collaborating on IT audits.
  • You have a technical understanding of Azure cloud governance, Microsoft 365, and hybrid infrastructure.
  • You possess knowledge of Identity & Access Management concepts including RBAC, PAM, MFA, and Entra ID.
  • You bring familiarity with vulnerability management processes and tooling such as Qualys or Tenable.
  • You are fluent in French and English.

Nice to Haves

  • Possession of ISO 27001 Foundation, ISO 27001 Lead Implementer, or CompTIA Security+ certifications.
  • Experience setting up an ISMS or GRC platform to manage controls and risks.
  • Understanding of secure software development practices and application-level risks.
  • Knowledge of Dutch.

Offer

  • Start date: ASAP
  • Duration: 6–12 months
  • Work regime: Full-time
  • Location: Brussels
  • Working model: Hybrid (4 days onsite, 1 day remote)
  • Contract: open to both permanent employees and freelancers
# 102189
With a plus sign and country code (e.g. +32 400 00 00 00).
We accept Word and PDF files up to 3 MB.
Candidates must be legally authorised to work in the EU and possess the required language skills for the job location.
Chat with Alex
Not sure if this job is right for you? Chat with Alex, our AI career coach, and discover the vacancies that match your profile.