Se rendre au contenu

Senior Security Compliance Officer - STIB-MIVB

Customer: STIB-MIVB Rue Royale 76 1000 Bruxelles Belgique
Dates: 2026-11-03 — 2027-11-30
Arrangements: Full time; hybrid working, combining on-site work and home working.
Apply before: 2026-10-05

Description

STIB - MIVB is strengthening its cybersecurity governance and regulatory compliance and is seeking a senior consultant to establish a coherent, measurable, auditable and sustainable compliance framework. The assignment sits within the cybersecurity programme and covers NIS2, PCI DSS, the Cyber Resilience Act and any other regulatory or normative requirements applicable to the organisation. The consultant will focus on structuring compliance rather than executing operational controls.

The consultant will analyse regulatory and normative requirements and translate them into concrete, measurable controls. This includes maintaining control repositories and defining each control's objective, evaluation criteria, evidence requirements, roles and responsibilities, monitoring indicators and expected maturity level. The work also includes defining evaluation methodologies, evidence expectations and associated reporting mechanisms.

A major part of the role is compliance governance and end-to-end traceability between regulatory requirements, cybersecurity risks, controls, remediation plans and evidence. The consultant will define governance mechanisms for compliance monitoring and contribute to monitoring and escalation processes, while business and IT teams retain responsibility for operational control execution. The mission is full time and hybrid in Brussels, running from 3 November 2026 through 30 November 2027.

Top Reasons to Apply
Shape compliance framework
★★★★★
Major cyber regulations
★★★★★
Cyber governance impact
★★★★★
Long-term Brussels mission
★★★★★
Hybrid working model
★★★★★
Responsibilities
Analyse regulatory requirements
Translate requirements controls
Build control repositories
Maintain control repositories
Define control objectives
Define evaluation criteria
Define evidence requirements
Define roles responsibilities
Must Have
Senior Compliance Officer experience
Recent relevant role experience
Expert audit expertise
Expert ISO 27K
Native Dutch or French
CISM certification
ISO27 Lead Auditor certification
10+ years IT Security
Nice to Have
English language proficiency

Detailed Responsibilities and Skills

Additional Responsibilities

  • Define monitoring indicators
  • Define maturity levels
  • Maintain requirements traceability
  • Maintain cybersecurity risk traceability
  • Maintain control traceability
  • Maintain remediation traceability
  • Maintain evidence traceability
  • Define compliance governance
  • Define monitoring processes
  • Define escalation processes
  • Maintain evaluation methodologies
  • Maintain reporting mechanisms

General skills

  • Senior Compliance Officer experience; most recent experience stated as 1 to 3 years ago.
  • Native or bilingual proficiency in Dutch or French.
  • CISM certification.
  • More than 10 years of experience in IT Security.
  • Ability to work in a hybrid model combining on-site work and home working.
  • English language proficiency is nice to have.

Technical skills

  • Expert-level Audit Expertise.
  • Expert-level ISO 27K knowledge.
  • ISO27 Lead Auditor certification.
  • Ability to analyse applicable regulatory and normative requirements.
  • Ability to translate regulatory, normative and cybersecurity requirements into concrete, measurable controls.
  • Knowledge of NIS2 compliance requirements.
  • Knowledge of PCI DSS compliance requirements.
  • Knowledge of Cyber Resilience Act compliance requirements.
  • Ability to address other regulatory or normative frameworks applicable to the organisation.
  • Ability to define control objectives, evaluation criteria, evidence requirements, roles and responsibilities, monitoring indicators and expected maturity levels.
  • Ability to maintain traceability between regulatory requirements, cybersecurity risks, controls, remediation plans and evidence.
  • Ability to define compliance governance, monitoring and escalation mechanisms.
  • Ability to define and maintain evaluation methodologies, evidence requirements and reporting mechanisms.