Security Risk and Compliance Analyst

il y a 3 heures


Bruxelles Schaarbeek, Belgique Proximus Temps plein

The mission of the Security Management section within Proximus Ada is to protect Proximus SA, its affiliates, customers, business, operations, and its reputation against external and internal cybersecurity threats. We oversee all cyber security matters across the company and its affiliates, ensuring that necessary security controls are implemented on IT and telecommunication systems, in accordance with the related risks and in line with security regulations, standards, and policies.

We are seeking a motivated and enthusiastic colleague to join our Vendor Risk Management team. If you are well-versed in cybersecurity, have a knack for adhering to rules and an interest in legal matters, can bring a creative flair that enhances team efficiency, and a can-do attitude in a high paced work environment, you are the perfect fit.

**Key responsibilities**
- Conduct comprehensive audits of third-party information security policies, procedures, and controls.
- Participate in contract negotiations concerning the third-party information security annex.
- Lead online and in-person meetings with third parties.
- Analyse submitted security questionnaires and documentation to identify and assess potential vulnerabilities and risks. Raise issues promptly and provide mitigation options based on security issues identified.
- Prepare detailed risk assessment reports for senior leadership, providing insights and recommendations for third-party risk reduction.
- Contribute to the continuous improvement of the team's processes based on experience in third-party risk assessment, industry best practices, and internal policies and frameworks.
- Produce clear and structured documentation of processes, meetings, and other relevant activities.
- Initiate and lead improvement projects aimed at enhancing the efficiency and effectiveness of the Vendor Risk Management team.
- Collaborate with other sections within the company to ensure alignment of processes.
- Stay up-to-date with emerging technologies, threats, vulnerabilities, and industry best practices.

**Qualifications**
- 2+ years’ experience in third/party risk management, information security risk management, compliance, or a background in cybersecurity.
- Familiarity with information security processes, including risk assessment, vulnerability management, and incident response.
- Understanding of regulatory requirements (e.g. GDPR, NIS2, DORA)
- Proficiency in risk management, cybersecurity control frameworks and standards (e.g. NIST RMF, ISO 27001, ISO 28000, CyFun, CCM)
- Excellent analytical and problem-solving skills, with the ability to interpret complex risk data and make informed decisions.
- Attention to detail and proven ability to initiate and drive projects.
- Experience in aligning team processes with broader organizational goals.
- A collaborative mindset and a positive attitude towards working with a diverse team.
- Relevant certifications such as CISA, CISSP, CISM, ISO/IEC 27001Lead Implementer/Auditor, ISO/IEC 28000 Lead Implementer/Auditor, Security+.
- Capable of conducting professional business communications and effectively handling information security aspects of contract negotiations.
- Strong written and verbal communication skills in **English.** Capability to articulate complex risk concepts to technical and non-technical audiences.
- Relevant certifications such as CISA, CISSP, CISM, ISO/IEC 27001Lead Implementer/Auditor, ISO/IEC 28000 Lead Implementer/Auditor, Security+.
- Advanced knowledge of Microsoft Office Suite (Word, Excel, PowerPoint, Outlook) to create professional documentation, presentations, dashboards, prepare statistics calculations, and optimize workflows.

**Preferred**additional skills**
- Knowledge of emerging technologies and their associated risks, especially in AI and cloud computing.
- Experience of using a Governance, Risk, and Compliance (GRC) tool
- Experience in the telecommunication domain.
- Proficiency in French or Dutch.


  • Is Security Risk Expert

    il y a 2 heures


    Bruxelles Ixelles, Belgique ATS4IT Temps plein

    Founded in 2020 in Belgium, ATS4IT is part of the Moongy Group, established to strengthen agap2IT’s presence in Europe. Since 2021 we expanded further with the opening of our Danish branch in Copenhagen, and our Spanish brand in Madrid, reinforcing our commitment to being a key player in the European technology landscape. Proximity, transparency, and...


  • Bruxelles, Belgique Innova Solutions Temps plein

    Risk and Controls Testing Expert – Digital Operational Resilience We are seeking a highly skilled Risk and Controls Testing Expert to join our Digital Operational Resilience team. This role is critical in ensuring that our organization maintains robust operational resilience in line with regulatory requirements and industry best practices. The successful...

  • Talencia Consulting

    il y a 3 semaines


    Bruxelles, Belgique Talencia Consulting Temps plein

    Information Security & risk officer (FR/NL) - brussels - permanent Our client is a leading Belgian cooperative in the pharmaceutical sector, known for its strong local roots and commitment to improving healthcare accessibility. The company combines technological innovation with a human approach to deliver reliable, secure, and accessible healthcare...

  • Risk Management Manager

    il y a 4 semaines


    Bruxelles, Belgique Innova Solutions Temps plein

    Risk and Controls Testing Expert – Digital Operational Resilience We are seeking a highly skilled Risk and Controls Testing Expert to join our Digital Operational Resilience team. The successful candidate will design, execute, and report on control testing activities to assess the effectiveness of compliance and risk management frameworks, focusing on...

  • Security Operation Analyst

    il y a 4 semaines


    Bruxelles, Belgique Enzo Tech Group Temps plein

    Job Opportunity: SOC Tier 2 Analyst (Temporary – Night Shift) Schedule: Night shifts, 12 hours (19:00–07:00) We are urgently looking for an entry-level SOC Tier 2 Analyst to join our Cyber Defense team on a temporary basis. This role is critical to supporting our 24/7 security operations and ensuring continuous monitoring during night hours. The...


  • Bruxelles Etterbeek, Belgique Degroof Petercam Temps plein

    Locatie: **Bank Degroof Petercam SA** **Belgium** - Rue De L'Industrie 44, 1040 Brussels Context Bank Degroof Petercam, a financial institution specialized in private banking and wealth management, headquartered in Brussels and operating 15 branch offices across the country, is looking to recruit an experienced Senior Security & Hard Services Manager for...


  • Bruxelles-Capitale, Belgique Sander Temps plein

    Are you the kind of security expert who advises stakeholders and drives strategic initiatives ? As an Information Security Officer within a major player in the financial sector, you will be responsible for safeguarding critical information assets and ensuring regulatory compliance in a fast-paced and highly regulated environment. You’ll operate at the...

  • IT Risk

    il y a 3 semaines


    Bruxelles, Belgique Randstad Digital Belgium Temps plein

    Are you an expert in IT risk management with a passion for digital security and operational excellence? At Randstad Digital, we are looking for an experienced IT Risk & Operations Manager to join one of our major clients in the financial sector. In this pivotal role, you will safeguard the stability and security of digital channels within the enterprise...

  • Ai Compliance Officer

    il y a 3 heures


    Bruxelles Schaarbeek, Belgique Proximus Temps plein

    Are you passionate about #AI and #cybersecurity? Do you love working with high profile teams with a sure taste of challenge and variety? You dream of joining a fast-growing company with start-up mentality? Eager to learn continuously and drive innovation via AI while securing the digital world of our customers? Join **Proximus Ada**! **Role...

  • Business Analyst

    il y a 4 semaines


    Bruxelles, Belgique ThoughtBot Temps plein

    Description: Project context Within a large financial organization, a transversal GRC program is underway to implement a ServiceNow IRM (Integrated Risk Management) platform. The initiative focuses on strengthening policy management, third-party risk management, and data privacy processes in line with regulatory and internal governance requirements. The...