IT Security Risk
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Company
Find out more about the daily tasks, overall responsibilities, and required experience for this opportunity by scrolling down now.
Lotus Bakeries is an international, dynamic and sustainable player in the FMCG industry. As a global leader, the company is renowned for its iconic Lotus Biscoff cookies, enjoyed all over the world.
Besides Lotus Biscoff, the company also offers a diverse portfolio of brands including Peijnenburg, Annas, nākd, TREK, and BEAR. Lotus Bakeries is a proud and passionate company that builds strong global and local brands and creates small moments of happiness. Its mission is to bring people together with delicious products and to spark joy.
The company passed a major revenue milestone of more than 1.3 billion euro, combined with a strong and growing net result. Driven by this impressive growth rate, Lotus Bakeries is confidently looking forward. The company is a successful BEL20 listed player, yet still a proud family business at its core.
Lotus Bakeries employs over 4100 people worldwide. The company has 20 Sales offices in 17 countries and 13 production facilities in 6 countries. The global headquarters are located in Lembeke (Belgium) & Baar (Switserland). The IT department is based exclusively in Lembeke (Belgium).
Role
As a hands-on operational expert, the IT Security - Risk & Compliance Officer takes full ownership of the international information security compliance landscape. Operating from the Belgian headquarters, this role coordinates and aligns global efforts to safeguard both Information Technology (IT) and Operational Technology (OT) environments, while continuously challenging the technical security teams and third-party vendors.
Key responsibilities include:
- ISMS & Policy Management: Maturing and strengthening the existing Information Security Management System (ISMS) based on the ISO27001 standard. This includes writing, updating, and embedding security policies across the global organization.
- Risk Assessments: Conducting annual and project-based risk analyses. This involves collaborating closely with stakeholders (such as sitting down with maintenance and plant managers) to identify, mitigate, and follow up on digital and data risks.
- Compliance & Regulatory Monitoring: Tracking and implementing evolving international regulations, specifically spearheading the NIS2 compliance project and mapping its requirements against existing frameworks.
- Audits & Vendor Evaluations: Planning and executing internal security audits, guiding external auditors, and systematically screening and evaluating third-party suppliers (Third-Party Risk Management).
- Culture & Awareness: Designing, driving, and delivering annual security awareness programs and training sessions (e.g., around phishing and cybersecurity) to foster a strong risk-aware culture worldwide.
- Incident & Project Support: Helping to coordinate incident response procedures when necessary, and conducting security/privacy assessments on new business projects (e.g., evaluating data retention and GDPR compliance for a new factory camera system).
Profile
- Education: a Master’s degree in a relevant field of study.
- Experience: at least 5 years of proven experience in a similar information security, risk, or compliance role within a multinational environment.
- Frameworks & Standards: Possesses strong, in-depth knowledge of the ISO27001 standard and practical experience with its implementation and maintenance.
- IT & OT Alignment: Demonstrates a solid understanding of both Information Technology (IT) and Operational Technology (OT). Experience or strong affinity with production environments—including systems like SCADA, PLCs, and factory automation—is considered a major asset for visiting and auditing global production plants.
- Stakeholder & Change Management: Displays exceptional stakeholder management skills, with the ability to confidently communicate across all levels of the organization—from factory maintenance managers and engineering teams to third-party vendors and C-level executives. Strong change management skills are essential to introduce new security protocols smoothly and build a positive risk culture.
Offer
Lotus Bakeries is a BEL20 listed, international player with strong g