Security Risk Manager bpost
Description
As Security Risk Manager within the bpost CISO Office, you will join a growing Security Risk Management team. The team strengthens the organisation's ability to identify, assess, manage, and report security risks. You will help develop efficient risk management processes and tools. You will also promote a risk-aware culture across the enterprise.
The role acts as a key liaison between business stakeholders and security architects. You will conduct and support risk assessments across IT and security domains and participate in project and architecture reviews. You will define, document, track, and follow up proportionate mitigation measures and action plans. You will also maintain and continuously improve the central risk register.
Your work directly supports compliance with NIS2, ISO 27001, and GDPR and reinforces bpost's overall security and resilience. You will contribute to implementing and monitoring NIS2 controls related to risk management, including reporting and documentation. The position requires extensive cybersecurity or risk experience, strong technical control knowledge, and experience translating regulatory requirements into operational controls. Strong analytical, organisational, reporting, and stakeholder communication capabilities are essential.
Top Reasons to Apply
Enterprise security impact
Regulatory compliance leadership
Cross-functional stakeholder exposure
Build risk processes
Hybrid Brussels role
Detailed Responsibilities and Skills
General skills
- 10+ years of experience in cybersecurity, risk management, or related fields.
- Proven experience in regulatory compliance, cybersecurity governance, risk management, or audit programmes.
- Experience translating regulatory requirements into operational controls and measurable compliance activities.
- Experience coordinating compliance programmes across multiple departments and stakeholders.
- Strong knowledge of control frameworks, policy management, and compliance monitoring practices.
- Experience preparing evidence packages for audits and regulatory reviews.
- Strong analytical skills.
- Strong documentation skills.
- Strong reporting skills.
- Ability to communicate effectively with technical teams.
- Ability to communicate effectively with management.
- Ability to communicate effectively with auditors.
- Ability to communicate effectively with regulatory stakeholders.
- Excellent organisational skills.
- Excellent project coordination skills.
- Fluent in English.
- Dutch is a plus.
- French is a plus.
Technical skills
- Strong technical experience in control selection.
- Strong technical experience in control implementation guidance.
- Technical control experience covering Network.
- Technical control experience covering IAM.
- Technical control experience covering SSDLC.
- Technical control experience covering Crypto.
- Knowledge and practical application of NIS2 risk-management controls.
- Work supporting compliance with ISO 27001.
- Work supporting compliance with GDPR.
Tools
- Risk management processes and tools.
- Central risk register.