Security Risk Manager bpost
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Dates: 2026-09-01 — 2026-11-30
Arrangements: Full-time; 5 days per week; 40 hours per week; hybrid; 1 position; long-term contract with an initial duration of 3 months.
As Security Risk Manager within the bpost CISO Office, you will join a growing Security Risk Management team. The team strengthens the organisation's ability to identify, assess, manage, and report security risks. You will help develop efficient risk management processes and tools. You will also promote a risk-aware culture across the enterprise.
The role acts as a key liaison between business stakeholders and security architects. You will conduct and support risk assessments across IT and security domains and participate in project and architecture reviews. You will define, document, track, and follow up proportionate mitigation measures and action plans. You will also maintain and continuously improve the central risk register.
Your work directly supports compliance with NIS2, ISO 27001, and GDPR and reinforces bpost's overall security and resilience. You will contribute to implementing and monitoring NIS2 controls related to risk management, including reporting and documentation. The position requires extensive cybersecurity or risk experience, strong technical control knowledge, and experience translating regulatory requirements into operational controls. Strong analytical, organisational, reporting, and stakeholder communication capabilities are essential.
Responsibilities
Contribute risk processes tools
Review projects architectures risks
Follow up action plans
Promote risk awareness initiatives
Implement monitor NIS2 controls
Must Have
10+ years cybersecurity experience
Technical control selection experience
Network security controls
IAM security controls
SSDLC security controls
Cryptography security controls
Regulatory compliance experience
Nice to Have
Dutch language proficiency
French language proficiency
Detailed Responsibilities and Skills
- 10+ years of experience in cybersecurity, risk management, or related fields.
- Proven experience in regulatory compliance, cybersecurity governance, risk management, or audit programmes.
- Experience translating regulatory requirements into operational controls and measurable compliance activities.
- Experience coordinating compliance programmes across multiple departments and stakeholders.
- Strong knowledge of control frameworks, policy management, and compliance monitoring practices.
- Experience preparing evidence packages for audits and regulatory reviews.
- Strong analytical skills.
- Ability to communicate effectively with technical teams.
- Ability to communicate effectively with management.
- Ability to communicate effective with auditors.
- Ability to communicate effective with regulatory stakeholders.
- Excellent organisational skills.
- Excellent project coordination skills.
- Dutch is a plus.
- French is a plus.
Technical skills
- Strong technical experience in control selection.
- Strong technical experience in control implementation guidance.
- Technical control experience covering Network.
- Technical control experience covering IAM.
- Technical control experience covering SSDLC.
- Technical control experience covering Crypto.
- Knowledge and practical application of NIS2 risk-management controls.
- Work supporting compliance with ISO 27001.