Senior Security Compliance Officer

Il y a 11 heures

Brussels, Belgique Virtual Connect Solutions Temps plein

As part of the strengthening of its cybersecurity governance and compliance with several regulatory and normative requirements, STIB is looking for a Security Compliance Consultant.

The consultant will be involved in the cybersecurity program in order to build, maintain and develop the compliance framework to meet the requirements of several regulatory and normative frameworks, including:

  • NIS2
  • PCI DSS
  • Cyber Resilience Act (CRA)
  • Any other regulatory or normative requirements applicable to the organization

The mission is mainly oriented towards the construction of the compliance framework, the formalization of requirements and the definition of controls. The consultant will not be responsible for the operational execution of the controls, which will remain the responsibility of the business and IT teams concerned.

The consultant will be responsible for translating regulatory, normative and cybersecurity requirements into a coherent, measurable, auditable and sustainable compliance framework.

In this capacity, he will ensure the definition and maintenance of control frameworks, evaluation methodologies, evidentiary requirements and associated reporting mechanisms.

Key Responsibilities

Construction and maintenance of control reference systems

  • Analyze applicable regulatory and normative requirements.
  • Translate these requirements into concrete and measurable controls.
  • Build and maintain control repositories associated with:
    • NIS2
    • PCI DSS
    • CRA
    • other applicable regulatory frameworks.
  • Set for each control:
    • the objective;
    • evaluation criteria;
    • the requirements of proof;
    • roles and responsibilities;
    • monitoring indicators;
    • the expected level of maturity.

Compliance Governance

  • Maintain traceability between:
    • regulatory requirements;
    • cybersecurity risks;
    • controls;
    • remediation plans;
    • evidence.
  • Define governance mechanisms to track compliance.
  • Participate in the definition of monitoring and escalation processes.