Senior Security Compliance Officer - STIB-MIVB
Description
STIB - MIVB is strengthening its cybersecurity governance and regulatory compliance and is seeking a senior consultant to establish a coherent, measurable, auditable and sustainable compliance framework. The assignment sits within the cybersecurity programme and covers NIS2, PCI DSS, the Cyber Resilience Act and any other regulatory or normative requirements applicable to the organisation. The consultant will focus on structuring compliance rather than executing operational controls.
The consultant will analyse regulatory and normative requirements and translate them into concrete, measurable controls. This includes maintaining control repositories and defining each control's objective, evaluation criteria, evidence requirements, roles and responsibilities, monitoring indicators and expected maturity level. The work also includes defining evaluation methodologies, evidence expectations and associated reporting mechanisms.
A major part of the role is compliance governance and end-to-end traceability between regulatory requirements, cybersecurity risks, controls, remediation plans and evidence. The consultant will define governance mechanisms for compliance monitoring and contribute to monitoring and escalation processes, while business and IT teams retain responsibility for operational control execution. The mission is full time and hybrid in Brussels, running from 3 November 2026 through 30 November 2027.
Top Reasons to Apply
Shape compliance framework
Major cyber regulations
Cyber governance impact
Long-term Brussels mission
Hybrid working model
Detailed Responsibilities and Skills
Additional Responsibilities
- Define monitoring indicators
- Define maturity levels
- Maintain requirements traceability
- Maintain cybersecurity risk traceability
- Maintain control traceability
- Maintain remediation traceability
- Maintain evidence traceability
- Define compliance governance
- Define monitoring processes
- Define escalation processes
- Maintain evaluation methodologies
- Maintain reporting mechanisms
General skills
- Senior Compliance Officer experience; most recent experience stated as 1 to 3 years ago.
- Native or bilingual proficiency in Dutch or French.
- CISM certification.
- More than 10 years of experience in IT Security.
- Ability to work in a hybrid model combining on-site work and home working.
- English language proficiency is nice to have.
Technical skills
- Expert-level Audit Expertise.
- Expert-level ISO 27K knowledge.
- ISO27 Lead Auditor certification.
- Ability to analyse applicable regulatory and normative requirements.
- Ability to translate regulatory, normative and cybersecurity requirements into concrete, measurable controls.
- Knowledge of NIS2 compliance requirements.
- Knowledge of PCI DSS compliance requirements.
- Knowledge of Cyber Resilience Act compliance requirements.
- Ability to address other regulatory or normative frameworks applicable to the organisation.
- Ability to define control objectives, evaluation criteria, evidence requirements, roles and responsibilities, monitoring indicators and expected maturity levels.
- Ability to maintain traceability between regulatory requirements, cybersecurity risks, controls, remediation plans and evidence.
- Ability to define compliance governance, monitoring and escalation mechanisms.
- Ability to define and maintain evaluation methodologies, evidence requirements and reporting mechanisms.