Digital Risk

Il y a 3 jours

Elsene, Brussel-Hoofdstad, Belgique Pauwels Consulting Temps plein 60 000 € - 90 000 € Contrat

Our client, a leading organization in the legal sector, is undergoing a significant digital transformation involving cloud technologies and AI applications. A dedicated professional is required to manage digital risks and ensure compliance across the growing digital landscape while facilitating secure organizational growth.

  • Develop and maintain information security policies, standards, and procedures in alignment with organizational goals.
  • Conduct structured risk assessments across IT systems and third-party vendors using frameworks such as CIS18, ISO 27001, or NIST.
  • Monitor the threat landscape to proactively identify and mitigate emerging risks relevant to the project.
  • Contribute to internal and external IT audits and test the effectiveness of digital controls.
  • Collaborate with cross-functional teams to embed security and compliance requirements into operational processes and digital projects.
  • Implement pragmatic security controls and build digital risk awareness courses for employees.
  • Assess the risk profiles and compliance posture of critical SaaS vendors and digital partners.
  • You bring 1+ years of experience in information security, IT risk management, or a related discipline.
  • You possess practical knowledge of security frameworks and standards such as ISO 27001, CIS18, and NIST CSF.
  • You have a solid understanding of regulatory requirements including GDPR, NIS2, and the EU AI Act.
  • You're experienced in conducting vendor risk assessments and collaborating on IT audits.
  • You have a technical understanding of Azure cloud governance, Microsoft 365, and hybrid infrastructure.
  • You possess knowledge of Identity & Access Management concepts including RBAC, PAM, MFA, and Entra ID.
  • You bring familiarity with vulnerability management processes and tooling such as Qualys or Tenable.
  • You are fluent in French and English.

Nice to Haves

  • Possession of ISO 27001 Foundation, ISO 27001 Lead Implementer, or CompTIA Security+ certifications.
  • Experience setting up an ISMS or GRC platform to manage controls and risks.
  • Understanding of secure software development practices and application-level risks.
  • Knowledge of Dutch.
  • Start date: ASAP
  • Duration: 6–12 months
  • Work regime: Full-time
  • Location: Brussels
  • Working model: Hybrid (4 days onsite, 1 day remote)
  • Contract: open to both permanent employees and freelancers