Senior Security Governance Specialist

il y a 19 heures


Brussels, Belgique Proximus Group Temps plein

The mission of Security Governance & Investigations is to protect Proximus, its customers, its business, its operations and reputation against external and internal threats. We oversee all cyber security matters across the company and its affiliates, with a whole set of activities covering governance, enterprise security architecture, security management and incident response (CSIRT). You will be fascinated by a highly dynamic environment, the cross-departmental collaboration and some deep technical aspects.

Within the Security Management team, we are looking for a highly motivated analyst to join and reinforce the team.
- You will be involved in the execution of the cybersecurity governance processes to ensure that the company’s information assets are properly protected, the level of risk is acceptable and that the corporate governance is respected.
- You will work closely with other teams within Security Governance and Investigations, Proximus Ada, business units’ security officers, commercial and technical business units, commercial and technical stakeholders, as well as with departments such as Legal, Internal Audit, Enterprise Risk Management, Communications, etc.

**Tasks to be performed by the Security Specialist include**:

- Define and update security policies and the security framework, with the aim to manage risk, to meet legal and regulatory requirements while ensuring that the business strategy and objectives can be implemented through the cybersecurity strategy.
- Define and document appropriate security controls, security guidelines and baselines for new technologies and environments in collaboration with enterprise security architects and security officers.
- Participate in the definition and execution of the implementation of cybersecurity processes and methodologies (e.g., risk management, compliance management,).
- Report on business risks and make recommendations to the Risk Management Committee.
- Monitor compliance and act on non-compliances. Guide stakeholders in their request for exceptions to security policies and report to the adequate decision body (PLT’s and Risk Management Committee).
- Oversee the cybersecurity processes and compliance of Proximus subsidiaries at Group level, measure KPIs and provide guidance on improvement opportunities. Report high risks of subsidiaries to the Proximus Risk Management Committee
- Develop and maintain regulatory and legal knowledge with Group Corporate Affairs colleagues and ensure proactive auditability (BIPT, ISO27001, etc.).
- Drive the execution of projects from the Cyber Security program (as delegate of the Business Sponsor).
- Provide support to the end users, upon request, during the implementation of security requirements.

**Profile**
- You are passionate about cybersecurity and how it enables business strategy.
- You understand Proximus business and have the ability to understand business products and related processes.
- You have strong interpersonal skills, mixing collaboration & communication skills, constructive assertiveness, and negotiation skills to convince other stakeholders.
- You are open minded, bring security in a positive manner and are always trying to find solutions. Your approach is cartesian and pragmatic. You can build a helicopter view and dig in the details whenever required.
- You can work autonomously, take responsibilities, and manage (sometimes changing) priorities. You have a high learning agility.
- You have an extensive understanding of security concepts, security domains and security tools, their implementation/usage in large IT and Telco environments (on-premises or in the cloud).
- You have a strong ability to detect security risks, propose/assess how to minimize them and communicate them clearly to non-technical stakeholders.
- Certification(s) like CISSP, CISM, CISA, SABSA, ISO27k Lead Auditor, ISO27k Lead Implementer,is(are) a plus.
- Language skills:

- Fluent in English with a good knowledge of French and/or Dutch.
- Excellent writing skills in English to be able to deliver clear and concise artefacts.



  • Brussels, Belgique Elia Temps plein

    **Ons bedrijf**: Elia is de beheerder van het Belgische hoogspanningsnet van 380 kV tot 30 kV. Elia staat in voor de ontwikkeling en het onderhoud van dit net, maakt het toegankelijk voor de gebruikers en regelt de energiestromen. De Elia groep heeft een team van 2000 professionals die als opdracht hebben de continuïteit van de elektriciteitsbevoorrading in...


  • Brussels, Belgique Elia Temps plein

    **The company**: Elia is the operator of the Belgian high-voltage transmission grid (380 kV to 30 kV) and is responsible for developing and maintaining the grid, providing users with access to it and controlling energy flows. The Elia group is a team of 2,000 professionals who have the task of ensuring the continuity of electricity supplies in Belgium. As...

  • Governance Specialist

    il y a 3 semaines


    Brussels, Belgique Enzo Tech Group Temps plein

    Governance Specialist – 60-Day Contract (ASAP Start)Brussels (Hybrid) | Freelance/SubcontractingI am looking for an experienced Governance Specialist to support on a short, high-impact mission. The consultant must be able to start quickly and bring strong governance, risk and compliance expertise.ResponsibilitiesStrengthen governance and compliance...


  • Brussels, Belgique NTT Temps plein

    JOB DESCRIPTION About usNTT DATA – a part of NTT Group - is a Top 10 global IT services provider, headquartered in Tokyo, with over 150,000 employees.We deliver consulting solutions by combining specialized sectorial knowledge, our transformation management skills, and our large technology expertise (data, RPA, AI, low code, cloud, IoT, virtual reality),...


  • Brussels, Belgique Luminus Temps plein

    Publicatiedatum: 15 mei 2024 - Brussels - Contract open-end As provider of essential energy services on the Belgian Market (NIS regulation), and in order to guarantee services continuity to its own customers, protect their personal data (GDPR), Luminus has to ensure the security of its own Network and Information systems. Currently, Luminus has two security...


  • Brussels, Belgique SWIFT Financial Messaging Services Temps plein

    About the Role Are you passionate about cyber and security challenges in information technology, cloud, agile and devsecops? Are you interested in enriching experience by working with an international and diverse team of IT security experts? If you are looking to interact with both external customers and internal stakeholders, exercise soft and technical...


  • Brussels, Belgique Talencia Consulting Temps plein

    **Homeworking**: Half-time remote **Location**: Brussels Central **Duration**: End of 2025+ **Project Context**: As part of the implementation of the NIS2 directive with the support of an external partner, significant progress has already been made, particularly regarding technical documentation. A first version of the documents has been produced, along with...


  • Brussels, Belgique Enzo Tech Group Temps plein

    CISO Role (Freelance)€1,200/dayRole OverviewFor our client, we are seeking an experienced Chief Information Security Officer (CISO) to lead the organisation's cybersecurity strategy and governance framework. The CISO will oversee enterprise information security, risk management, compliance, and operational resilience. Working closely with senior...


  • Brussels, Belgique Enzo Tech Group Temps plein

    CISO Role (Freelance)€1,200/dayRole OverviewFor our client, we are seeking an experienced Chief Information Security Officer (CISO) to lead the organisation’s cybersecurity strategy and governance framework. The CISO will oversee enterprise information security, risk management, compliance, and operational resilience. Working closely with senior...


  • Brussels, Belgique Vector Synergy Temps plein

    **Location**: Brussels, Belgium **Security Clearance**: EU Restricted **Introduction**: Information Security Management Service aims to ensure the confidentiality, integrity, and availability of the Contracting EU Institutions’ (EU-Is') information, data, and ICT services. This service relies on the identification of the Contracting EU-I's assets...