Senior Security Compliance Officer – NIS2 & ISO 27001

Senior Security Compliance Officer (NIS2 & ISO 27001) for a public infrastructure client, hybrid in Brussels, fulltime, open to permanent and freelance.

Locatie
Brussel, BE
Werkvorm
hybride

Geen duidelijke warme-stoelaanwijzingen in de beschikbare beoordeling.

Bekijk en reageer bij Pauwels Consulting (externe link)

Eisen

  • Expert-level knowledge of ISO 27001 and construction of security compliance frameworks
  • 8+ years of experience in IT Security and cybersecurity governance
  • Fluent in French or Dutch
  • Ability to translate complex regulatory texts into actionable technical and organizational requirements
  • Expert-level expertise in Security Auditing and internal control methodologies
  • Professional CISM (Certified Information Security Manager) certification
  • Deep knowledge of NIS2, PCI DSS, and Cyber Resilience Act (CRA) regulations
  • ISO 27001 Lead Auditor certification

Wensen

  • Working knowledge of English
Volledige omschrijving

Our client, a prominent organization in the public infrastructure sector, is seeking a Senior Security Compliance Officer to strengthen its cybersecurity governance. The role focuses on building and evolving a compliance framework to meet critical regulatory and normative requirements within a large-scale security program.

Responsibilities: Analyze and translate regulatory and normative requirements into concrete, measurable security controls. Develop and maintain control frameworks for NIS2, PCI DSS, and the Cyber Resilience Act (CRA). Define evaluation criteria, evidence requirements, and key performance indicators for each security control. Establish governance mechanisms to ensure full traceability between risks, controls, and remediation plans. Design monitoring and escalation processes for continuous compliance tracking.

Collaborate with business and IT teams to define maturity levels and reporting structures without direct operational execution.

Requirements: You possess 8+ years of experience in IT Security and cybersecurity governance. You bring expert-level knowledge of ISO 27001 and the construction of security compliance frameworks. You have expert-level expertise in Security Auditing and internal control methodologies. You possess deep knowledge of NIS2, PCI DSS, and Cyber Resilience Act (CRA) regulations. You have a professional CISM (Certified Information Security Manager) certification.

You possess an ISO 27001 Lead Auditor certification. You're able to translate complex regulatory texts into actionable technical and organizational requirements. You are fluent in French or Dutch.

Nice to Haves: Working knowledge of English.

Offer: Start date: 03/11/2026.

Duration: 13 months.

Work regime: Full-time.

Location: Brussels.

Working model: Hybrid.

Contract: open to both permanent employees and freelancers.

Je CV en reacties