SAP Cyber Security Expert

il y a 3 semaines


Anderlecht, Belgique Empiric Temps plein

Translating the central CISO strategy into practical and pragmatic solutions within a major SAP system renewal program, which will eventually replace a number of OnPrem SAP solutions with S/4HANA PCE and a number of SAP SaaS satellites. This includes collecting and processing information from SAP or SI contracts, (IT) processes, risk analyses, and proposing and implementing mitigating actions (with IT suppliers and SAP or non-SAP teams within the IT department) to adequately secure the company's assets (physical and electronic information, data, and IT assets). This includes, among other things, compliance with the GDPR and NIS2 standards. Main Activities:• Information Security Management: - Serves as the point of contact for and assists the CISO with maintaining a central Information Security Management System (ISMS) in line with international (mandated) standards for everything related to the SAP transformation program and existing and new SAP solutions; - Actively monitors and supplements the various CISO dashboards and other information sources within the CISO community regarding existing and new SAP solutions; - Monitors the defined actions of internal and external audits for the ERP organization and provides monthly feedback to department management and maintains operational contact with the Internal Audit department; • Information Risk Management: - Monitors the CISO processes, policies, and standards (and helps improve them) for defining, developing, and applying "information risk analysis, risk treatment and risk monitoring" to the business and IT processes that have been or will be implemented with the new SAP solutions; - Assists the ERP delivery teams with incorporating information risk management processes into the business and IT processes supported by existing or new SAP solutions; - Pragmatically conducts information risk analyses and monitors them together with the CISO for projects in the transformation process, as well as for operational existing situations; - Responsible for maintaining the section of the central CISO information risk register related to SAP solutions and projects; - Ensures that the risks and associated mitigating actions are clearly reported to the business owners, together with the CISO; • CISO Solutions & Services: - Defines any requirements for cybersecurity solutions and services within the ERP organization, in close consultation with the central CISO team; - Collaborates with the CISO organization on controls for the cybersecurity services of the (IT) sourcing partners within the ERP organization; - Collaborates with the SAP Basis and central CISO teams to establish, maintain, and execute CSIRT (computer security incident response team) activities; - Guides the SAP Authorization team in setting up Identity & Access Management solutions and governance in line with central CISO guidelines; • Governance, Policies & Awareness: - Supports the central CISO organization in developing and communicating within the ERP department policies, standards, procedures, and guidelines regarding information security and data protection; - Implements compliance and necessary controls within the ERP department according to central CISO agreements, legal regulations, and the agreed-upon review cycle; - Contributes to company-wide long-term information security awareness, in close collaboration with the HR team, internal communication, and existing training initiatives to raise awareness among internal and external employees about information security and privacy risks and teach them best practices; - Serves as the point of contact for security liaisons in the various departments for implementing policy, applying policies, and resolving security incidents with SAP solutions; • Reporting: - Supports the central CISO team with quarterly reports to the executive committee; - Is responsible for drafting, preparing, and following up on status reports (progress, budget, resources, planning, project templates) on cybersecurity-related initiatives within the ERP organization; - Is responsible for drafting, preparing, and following up on reports on security findings from the CISO dashboards; • IT Compliance Monitoring: - Supports the central CISO organization with establishing and maintaining an IT audit and IT compliance framework, in line with legal requirements or strategic IT objectives, and is responsible for the administrative follow-up of outstanding (audit) improvement proposals within the ERP organization and SAP solutions;- Establishes close collaboration with the Data Protection Officer and the InformationRisk Manager (risk identification) to exchange audit findings and compliance violations within the SAP applications or ERP organization; - Supports the execution of IT audits and IT compliance assignments based on information security and data protection policies and Information Risk Management processes, identifying deficiencies or violations within the (existing or new) SAP applications and the (existing or new) IT processes within the ERP organization; - Facilitates the writing up of findings, both at a high-level (executive summary) and technical level (architects/engineers/developers), including proposing mitigation scenarios; • Knowledge Development: - Stays informed of new developments in SAP and CISO domains and makes proposals for how these can be applied within the ERP organization; - Stays informed about security threats, market developments, technologies, relevant legislation, IT technical and other security developments; - Continuously attends training courses, seminars, webinars, etc., and helps disseminate this knowledge within the ERP organization; Minimum knowledge and experience (conformity criteria) • Minimum 5 years of experience as a CISO officer in a large enterprise; • Minimum 3 years of experience with IT Security & Risk Management within an SAP context; • Minimum 3 years of experience with the implementation and operations of CISO solutions & services within a modern SAP cloud-based context; • Minimum 3 years of experience with IT Audits & Compliance within an SAP context; • Minimum 2 project lifecycles in a leading role to achieve/maintain ISO 2700x and GDPR certifications in an SAP context; • Minimum 5 years of experience as an SAP Project or Program Manager with at least 3 years of experience with SAP cloud-based solutions; • Minimum C1-level knowledge of Dutch, French, and English; • Certifications: PMP, CISSP, CISM, or CISA are a plus; Comments: 1 - Only missions longer than 9 months will be accepted for the years of experience. Shorter missions may be relevant for knowledge development, but are not counted towards the number of years of experience; 2 - We are NOT looking for an SAP authorization consultant, but an SAP project manager who is familiar with all CISO areas; • Responsibility Scope • Information Security Management; Information Risk Management; • CISO Security Solutions & Services; • Governance, Policies & Awareness regarding information security and data protection; • Coordination and management of one or more projects and initiatives within the ERP organization, in collaboration with the central Information Security department; • Reporting on the CISO domains and security findings; • Monitoring IT Compliance; • Keeping your own knowledge up-to-date and expanding; Possible consequences of incorrect decisions and/or incorrectly executed activities: - Late or inadequate security policies, procedures, and guidelines; - Late identification and treatment of information security risks; - Lack of awareness among internal and external employees regarding information security & privacy risks and best practices; - Delivery of information security projects not in accordance with predefined project plans; - Late and/or incomplete reporting on the CISO domains to management and senior management;- Potential system infections with far-reaching consequences for the operations of YPTO and the client; - Potential breaches of applicable laws and regulations; Problem solving • The ability to execute multiple projects in parallel and coordinate work across multiple people; • Ability to implement established frameworks, procedures, policies, standards, and awareness programs; • Making accurate risk assessments, analysing security incidents, and proposing solutions and mitigations; • Giving and preparing presentations to senior management and directors; • Keeping up-to-date knowledge in rapidly evolving domains (trends, technology, SAP, etc.); • Is bound by the policy and vision regarding Information Security, the strategic CISO plan, ISO 2700x, applicable legislation (GDPR, NKI, NIS, etc.), and international standards; • Refers to the manager in case of escalations, to discuss incidents, to validate project plans, budgets, resources, and (interim) reporting; • Communication • Speak and write fluently in Dutch, French, and English; • Explain a technical issue in a structured manner that is understandable to laypeople; • Speak and write fluently in Dutch, French, and English; • Explain a technical issue in a structured manner that is understandable to laypeople; • Speaks and writes fluently in Dutch, French, and English; • Explains a technical issue in a structured manner that is understandable to laypeople; Internal Contacts • Daily to weekly contact with fellow CISO officers regarding policy, projects, and incidents; • Daily contact with the various ERP teams and IT departments regarding the coordination and management of information security projects; • Weekly contact with Heads of CISO, ERP, IT PMO, etc.


  • SAP Cybersecurity Expert

    il y a 5 jours


    Bruxelles Anderlecht, Belgique Ypto NV Temps plein

    **Objective**: Translate the central CISO strategy into practical cybersecurity solutions within a major SAP transformation program, transitioning from OnPrem SAP to S/4HANA PCE and SAP SaaS modules. Ensure compliance with GDPR, NIS2, and other standards by managing risks, implementing controls, and coordinating with internal teams and external...

  • Team Lead Cybersécurité

    il y a 1 semaine


    Anderlecht, Belgique Infrabel Temps plein

    **LE TRAVAIL** - Infrabel est un opérateur essentiel et critique en Belgique étant donné son rôle sociétal et militaire. Le périmètre digital et industriel d’Infrabel est vaste et l’évolution du contexte de la menace ainsi que des obligations légales (NIS2) d’Infrabel, réclame une prise en charge et un pilotage fort de son activité de...


  • Anderlecht, Belgique WhatJobs Temps plein

    Senior Consultant R&P et Talent Acquisition & Development - STIB-PU_2026_003 Dans le cadre du déploiement de sa stratégie RH, le département «Reward & Performance» est en charge de 2 projets majeurs stratégiques: Le projet CFe(Classification des Fonctions Employés): ce projet a pour objectif de mettre en place un nouveau système de classification, de...


  • Bruxelles Anderlecht, Belgique Cronos Europa Temps plein

    **Responsabilities** **DevSecOps Pipeline Management** - Promote and advocate DevSecOps methodologies and best practices across IT projects **Security Architecture and Cloud Engineering** - Architect and design API Security, Container Security, and Cloud Security frameworks - Ensure security, compliance, and performance in multi-cloud and hybrid...

  • HR Reward Expert

    il y a 5 jours


    Anderlecht, Belgique Heads & Hunters Temps plein

    **Als je een passie hebt voor de "harde HR" onderwerpen, als je wilt werken aan programma's die bijdragen aan het behoud van werknemers en op zoek bent naar een plek om jezelf te ontwikkelen, dan is dit the place to be. De functie is gesitueerd in Anderlecht (Brussel) maar met maximaal 3 dagen/week kantoor aan huis.** **Je bent verantwoordelijk**: Voor de...

  • Digital Technology Expert

    il y a 5 jours


    Anderlecht, Belgique UCB Temps plein

    **Make your mark for patients** We are looking for a **Digital Technology Expert - Veeva Platform Connectors** who is curious, collaborative, and delivery focused to join us in our **Clinical and Patient Evidence Technology team**, based in our** Brussels office in Belgium.** **About the role** In this global role, you will lead the design,...


  • Anderlecht, Belgique Auto 5 Temps plein

    **Société**: Auto5 est à la recherche d'un conseiller-vendeur pour son centre situé à Auderghem. La filiale belge du Groupe Norauto, est la première enseigne belge d’équipement et d’entretien automobile avec 55 centres en Belgique. Auto5 c’est aussi plus de 600 personnes animées par la même vision du métier : l'innovation automobile et la...

  • Data Architect

    il y a 5 jours


    Anderlecht, Belgique Ypto NV Temps plein

    At SNCB/NMBS we want to become data-driven. We strive to make data a shared asset giving all stakeholders a common view of the company. We provide users with the tools they need to analyse and explore data, and generate insights that improve customer satisfaction and operational efficiency. As Data Architect within our Data & Analytics team, you play an...


  • Anderlecht, Belgique Securitas Temps plein

    **Bedrijfsomschrijving** Our industry is in constant evolution. Together with colleagues around the world, we stay ahead of changes in technology. Tomorrow's solutions are today's challenges. People and technology are building the next generation of security with us! **Vacatureomschrijving** We’re looking for a proactive and independent Finance Business...


  • Bruxelles Anderlecht, Belgique Alight Temps plein

    Payroll Specialist Belgium **Our story** At Alight, we believe a company’s success starts with its people. It’s why we’re so driven to connect passion with purpose. Our team’s expertise in human insights and cloud technology, allows companies and employees around the world to transform and thrive. With a competitive total rewards package,...