SAP Cyber Security Expert
il y a 3 semaines
Translating the central CISO strategy into practical and pragmatic solutions within a major SAP system renewal program, which will eventually replace a number of OnPrem SAP solutions with S/4HANA PCE and a number of SAP SaaS satellites. This includes collecting and processing information from SAP or SI contracts, (IT) processes, risk analyses, and proposing and implementing mitigating actions (with IT suppliers and SAP or non-SAP teams within the IT department) to adequately secure the company's assets (physical and electronic information, data, and IT assets). This includes, among other things, compliance with the GDPR and NIS2 standards. Main Activities: • Information Security Management: - Serves as the point of contact for and assists the CISO with maintaining a central Information Security Management System (ISMS) in line with international (mandated) standards for everything related to the SAP transformation program and existing and new SAP solutions; - Actively monitors and supplements the various CISO dashboards and other information sources within the CISO community regarding existing and new SAP solutions; - Monitors the defined actions of internal and external audits for the ERP organization and provides monthly feedback to department management and maintains operational contact with the Internal Audit department; • Information Risk Management: - Monitors the CISO processes, policies, and standards (and helps improve them) for defining, developing, and applying "information risk analysis, risk treatment and risk monitoring" to the business and IT processes that have been or will be implemented with the new SAP solutions; - Assists the ERP delivery teams with incorporating information risk management processes into the business and IT processes supported by existing or new SAP solutions; - Pragmatically conducts information risk analyses and monitors them together with the CISO for projects in the transformation process, as well as for operational existing situations; - Responsible for maintaining the section of the central CISO information risk register related to SAP solutions and projects; - Ensures that the risks and associated mitigating actions are clearly reported to the business owners, together with the CISO; • CISO Solutions & Services: - Defines any requirements for cybersecurity solutions and services within the ERP organization, in close consultation with the central CISO team; - Collaborates with the CISO organization on controls for the cybersecurity services of the (IT) sourcing partners within the ERP organization; - Collaborates with the SAP Basis and central CISO teams to establish, maintain, and execute CSIRT (computer security incident response team) activities; - Guides the SAP Authorization team in setting up Identity & Access Management solutions and governance in line with central CISO guidelines; • Governance, Policies & Awareness: - Supports the central CISO organization in developing and communicating within the ERP department policies, standards, procedures, and guidelines regarding information security and data protection; - Implements compliance and necessary controls within the ERP department according to central CISO agreements, legal regulations, and the agreed-upon review cycle; - Contributes to company-wide long-term information security awareness, in close collaboration with the HR team, internal communication, and existing training initiatives to raise awareness among internal and external employees about information security and privacy risks and teach them best practices; - Serves as the point of contact for security liaisons in the various departments for implementing policy, applying policies, and resolving security incidents with SAP solutions; • Reporting: - Supports the central CISO team with quarterly reports to the executive committee; - Is responsible for drafting, preparing, and following up on status reports (progress, budget, resources, planning, project templates) on cybersecurity-related initiatives within the ERP organization; - Is responsible for drafting, preparing, and following up on reports on security findings from the CISO dashboards; • IT Compliance Monitoring: - Supports the central CISO organization with establishing and maintaining an IT audit and IT compliance framework, in line with legal requirements or strategic IT objectives, and is responsible for the administrative follow-up of outstanding (audit) improvement proposals within the ERP organization and SAP solutions;- Establishes close collaboration with the Data Protection Officer and the Information Risk Manager (risk identification) to exchange audit findings and compliance violations within the SAP applications or ERP organization; - Supports the execution of IT audits and IT compliance assignments based on information security and data protection policies and Information Risk Management processes, identifying deficiencies or violations within the (existing or new) SAP applications and the (existing or new) IT processes within the ERP organization; - Facilitates the writing up of findings, both at a high-level (executive summary) and technical level (architects/engineers/developers), including proposing mitigation scenarios; • Knowledge Development: - Stays informed of new developments in SAP and CISO domains and makes proposals for how these can be applied within the ERP organization; - Stays informed about security threats, market developments, technologies, relevant legislation, IT technical and other security developments; - Continuously attends training courses, seminars, webinars, etc., and helps disseminate this knowledge within the ERP organization; Minimum knowledge and experience (conformity criteria) • Minimum 5 years of experience as a CISO officer in a large enterprise; • Minimum 3 years of experience with IT Security & Risk Management within an SAP context; • Minimum 3 years of experience with the implementation and operations of CISO solutions & services within a modern SAP cloud-based context; • Minimum 3 years of experience with IT Audits & Compliance within an SAP context; • Minimum 2 project lifecycles in a leading role to achieve/maintain ISO 2700x and GDPR certifications in an SAP context; • Minimum 5 years of experience as an SAP Project or Program Manager with at least 3 years of experience with SAP cloud-based solutions; • Minimum C1-level knowledge of Dutch, French, and English; • Certifications: PMP, CISSP, CISM, or CISA are a plus; Comments: 1 - Only missions longer than 9 months will be accepted for the years of experience. Shorter missions may be relevant for knowledge development, but are not counted towards the number of years of experience; 2 - We are NOT looking for an SAP authorization consultant, but an SAP project manager who is familiar with all CISO areas; • Responsibility Scope • Information Security Management; Information Risk Management; • CISO Security Solutions & Services; • Governance, Policies & Awareness regarding information security and data protection; • Coordination and management of one or more projects and initiatives within the ERP organization, in collaboration with the central Information Security department; • Reporting on the CISO domains and security findings; • Monitoring IT Compliance; • Keeping your own knowledge up-to-date and expanding; Possible consequences of incorrect decisions and/or incorrectly executed activities: - Late or inadequate security policies, procedures, and guidelines; - Late identification and treatment of information security risks; - Lack of awareness among internal and external employees regarding information security & privacy risks and best practices; - Delivery of information security projects not in accordance with predefined project plans; - Late and/or incomplete reporting on the CISO domains to management and senior management; - Potential system infections with far-reaching consequences for the operations of YPTO and the client; - Potential breaches of applicable laws and regulations; Problem solving • The ability to execute multiple projects in parallel and coordinate work across multiple people; • Ability to implement established frameworks, procedures, policies, standards, and awareness programs; • Making accurate risk assessments, analysing security incidents, and proposing solutions and mitigations; • Giving and preparing presentations to senior management and directors; • Keeping up-to-date knowledge in rapidly evolving domains (trends, technology, SAP, etc.); • Is bound by the policy and vision regarding Information Security, the strategic CISO plan, ISO 2700x, applicable legislation (GDPR, NKI, NIS, etc.), and international standards; • Refers to the manager in case of escalations, to discuss incidents, to validate project plans, budgets, resources, and (interim) reporting; • Communication • Speak and write fluently in Dutch, French, and English; • Explain a technical issue in a structured manner that is understandable to laypeople; • Speak and write fluently in Dutch, French, and English; • Explain a technical issue in a structured manner that is understandable to laypeople; • Speaks and writes fluently in Dutch, French, and English; • Explains a technical issue in a structured manner that is understandable to laypeople; Internal Contacts • Daily to weekly contact with fellow CISO officers regarding policy, projects, and incidents; • Daily contact with the various ERP teams and IT departments regarding the coordination and management of information security projects; • Weekly contact with Heads of CISO, ERP, IT PMO, etc.
-
Cyber Security Engineer
il y a 2 jours
Laeken, Belgique DigiTribe Temps pleinWe are looking for a hands-on Cybersecurity Specialist/Engineer with experience in strengthening the cybersecurity posture and embedding senior-level security expertise within the team. This role is ideal for a plug-and-play security professional who can quickly add value, collaborate effectively, and lead by example. Key Responsibilities Own and...
-
Cyber Security Analyst
il y a 3 semaines
Laeken, Belgique IBSC LTD Temps pleinCybersecurity Architect You will be responsible for designing, supporting implementation, and maintaining our customer's security infrastructure to protect IT systems, networks, and data from cyber threats. This role involves developing security frameworks, defining best practices, and ensuring compliance with industry standards and regulations in a delivery...
-
Cyber Security Specialist
il y a 2 jours
Laeken, Belgique DigiTribe Temps pleinWe are looking for experienced professionals to join our Cyber & Information Security team. You will work on risk assessments for a wide range of IT security projects, related to access management, network security, application security, cloud security, amongst other topics. What you'll do Advise on security architecture, risk mitigation, and “secure by...
-
Cyber Security Lead
il y a 14 heures
Laeken, Belgique Strativ Group Temps pleinCyber Security Capability Lead Location: Brussels Responsibilities: Define and own the Group Security vision and roadmap, aligned to cyber strategy, business priorities, and regulatory obligations (e.g. NIS2), and actively drive alignment across leadership and stakeholders. Deliver measurable outcomes and risk reduction, owning cyber risk, compliance...
-
Cyber Security Analyst
il y a 5 jours
Laeken, Belgique ConSol Partners Temps pleinHi, I'm excited to share that one of our clients in Belgium is hiring for an ICT Functional Analyst! Below are the job details. If you're interested, please send your CV to apply. Title: ICT Functional Analyst Location: Brussels, Belgium Duration: 12 months freelance contract (extension possible) Job Type: Hybrid (3 days per onsite and 2 days remote every...
-
Senior Cyber Security Consultant
il y a 4 semaines
Laeken, Belgique Salt Temps pleinSenior Cyber Security Consultant (IT & Architecture Assurance) Rate: 500 – 900 per day – dependant on experience Duration: 1 year + Locations: London, Paris, Amsterdam and Brussels (8 days onsite in any location of this locations is required every month – the rest can be worked remotely) Required Technical and Professional Expertise We are looking for...
-
Cyber Security Consultant
il y a 6 jours
Laeken, Belgique Harvey Nash Temps pleinWe're Hiring – Cybersecurity Professionals At Harvey Nash, we're partnering with multiple clients across industries to strengthen their cybersecurity capabilities. We're currently looking for Cybersecurity professionals who are passionate about protecting digital platforms, data, and modern cloud environments. Your mission Depending on the role and client...
-
Cyber Security Specialist
il y a 2 jours
Laeken, Belgique CBSbutler Temps pleinJunior CyberArk Engineer – Freelance 6 Months Rolling - Hybrid Working Brussels CBSbutler are working with a Cyber Security start up, who are looking for a Junior CyberArk Engineer to join on a 6 month rolling freelance engagement , starting ASAP ideally but they can wait for notice periods. Despite their small size, they provide blue teaming and...
-
SAP Cyber Security Project Manager
il y a 3 semaines
Laeken, Belgique Whitehall Resources Temps pleinSAP Cybersecurity Project Manager - Dutch & French speaking An exciting new opportunity has arisen for an experienced SAP Cybersecurity / CISO-domain Project Manager to join a major client in Belgium. You will support a large-scale SAP transformation program, moving from On-Prem SAP to S/4HANA, with a strong focus on governance, risk, compliance, and...
-
IT & Cyber GRC Technical
il y a 2 jours
Laeken, Belgique Nexeo Temps pleinNexeo Belgium supports leading organizations in the banking, finance, insurance, and public sectors throughout their most critical transformation, risk, and cybersecurity initiatives. We are currently looking for a IT & Cyber GRC Technical Consultant who wants to shape, evolve, and drive Governance, Risk and Compliance practices in a complex, regulated...