Information Security Compliance & Governance Coordinator (NIS2 / ISO 27001)

Information Security Compliance & Governance Coordinator (NIS2 / ISO 27001) voor een essentiële entiteit in België, contract, fulltime.

Geen duidelijke warme-stoelaanwijzingen in de beschikbare beoordeling.

Bekijk en reageer bij Sparagus (externe link)

Eisen

  • Advanced Excel skills (formulas, pivot tables, dashboards) and strong PowerPoint skills for clear management reporting
  • Assertive and credible communicator, comfortable chasing stakeholders at all levels
  • Highly structured, organized and detail-oriented, with a strong sense of follow-up
  • Strong written and spoken English and French; Dutch is a clear asset in the Belgian context
  • First experience (1–3 years) in compliance, GRC, audit support, PMO/PSO or a similar role
  • Working knowledge of information security governance and a good understanding of ISO/IEC 27001 (certification not required)
  • Bachelor's degree or higher (information management, business administration, IT, law, or a related field)

Wensen

  • Knowledge of other frameworks (ISO 27002, NIST, CIS) or GRC tools
  • Familiarity with NIS2 and the Belgian framework (national law, Centre for Cybersecurity Belgium, CyFun)
  • Foundation-level certification (e.g. ISO 27001 Foundation)
Volledige omschrijving

We are an essential entity under the NIS2 Directive (as transposed in Belgium) and are building our compliance posture via the ISO/IEC 27001 framework. We are looking for a structured and assertive coordinator to join the Information Security team and keep our NIS2 / ISO 27001 compliance program on track. You will be the operational backbone of the program: tracking policy implementation, collecting and managing evidence, maintaining reporting dashboards, and running the practical side of project governance.

Key responsibilities: Compliance tracking and reporting - Build and maintain Excel dashboards and PowerPoint progress reports on NIS2 / ISO 27001 compliance for the management and steering committees; Consolidate status information, highlight gaps, delays and risks, and keep the data accurate and up to date. Owner engagement and evidence management - Collaborate with the owners responsible for implementing policies and controls across the organization; Follow up with these owners, assertively and constructively, to obtain status updates and deliverables within agreed deadlines; Collect, review for completeness, and organise evidence supporting control implementation; Maintain a structured, audit-ready evidence repository with clear naming, versioning and traceability.

Project governance and coordination - Organise and coordinate governance meetings (steering committees, working groups, follow-up meetings), including agendas, minutes, action logs and follow-ups; Handle the administrative and practical aspects of project governance; Escalate blockers and overdue actions to the CISO in a timely manner. Audit planning - Plan and coordinate the agendas for internal and external audits (ISO 27001 certification, surveillance audits, NIS2-related assessments); Schedule auditees and interviews, and make sure documentation and evidence are ready beforehand; Track audit findings and follow up on corrective actions with the relevant owners.

Profile - Required: Bachelor's degree or higher (information management, business administration, IT, law, or a related field); Working knowledge of information security governance and a good understanding of ISO/IEC 27001 (certification not required); Highly structured, organized and detail-oriented, with a strong sense of follow-up; Assertive and credible communicator, comfortable chasing stakeholders at all levels; Advanced Excel skills (formulas, pivot tables, dashboards) and strong PowerPoint skills for clear management reporting; Strong written and spoken English and French; Dutch is a clear asset in the Belgian context; First experience (1–3 years) in compliance, GRC, audit support, PMO/PSO or a similar role.

Nice to have: Familiarity with NIS2 and the Belgian framework (national law, Centre for Cybersecurity Belgium, CyFun); Knowledge of other frameworks (ISO 27002, NIST, CIS) or GRC tools; Foundation-level certification (e.g. ISO 27001 Foundation).

Soft skills: Rigor, autonomy and reliability; Diplomacy combined with the ability to hold people to their commitments; Good sense of priorities and deadlines; Discretion when handling sensitive information.

Je CV en reacties