Overslaan naar inhoud

Security Risk Manager bpost

Customer: bpost Anspach 1000 Brussels België
Dates: 2026-09-01 2026-11-30
Arrangements: Full-time; 5 days per week; 40 hours per week; hybrid; 1 position; long-term contract with an initial duration of 3 months.
Apply before: 2026-09-03

Description

As Security Risk Manager within the bpost CISO Office, you will join a growing Security Risk Management team. The team strengthens the organisation's ability to identify, assess, manage, and report security risks. You will help develop efficient risk management processes and tools. You will also promote a risk-aware culture across the enterprise.

The role acts as a key liaison between business stakeholders and security architects. You will conduct and support risk assessments across IT and security domains and participate in project and architecture reviews. You will define, document, track, and follow up proportionate mitigation measures and action plans. You will also maintain and continuously improve the central risk register.

Your work directly supports compliance with NIS2, ISO 27001, and GDPR and reinforces bpost's overall security and resilience. You will contribute to implementing and monitoring NIS2 controls related to risk management, including reporting and documentation. The position requires extensive cybersecurity or risk experience, strong technical control knowledge, and experience translating regulatory requirements into operational controls. Strong analytical, organisational, reporting, and stakeholder communication capabilities are essential.

Top Reasons to Apply
Enterprise security impact
Regulatory compliance leadership
Cross-functional stakeholder exposure
Build risk processes
Hybrid Brussels role
Responsibilities
Contribute risk processes tools
Conduct risk assessments documentation
Review projects architectures risks
Propose track risk responses
Follow up action plans
Maintain improve risk register
Promote risk awareness initiatives
Implement monitor NIS2 controls
Must Have
10+ years cybersecurity experience
Technical control selection experience
Control implementation guidance
Network security controls
IAM security controls
SSDLC security controls
Cryptography security controls
Regulatory compliance experience
Nice to Have
Dutch language proficiency
French language proficiency

Detailed Responsibilities and Skills

General skills

  • 10+ years of experience in cybersecurity, risk management, or related fields.
  • Proven experience in regulatory compliance, cybersecurity governance, risk management, or audit programmes.
  • Experience translating regulatory requirements into operational controls and measurable compliance activities.
  • Experience coordinating compliance programmes across multiple departments and stakeholders.
  • Strong knowledge of control frameworks, policy management, and compliance monitoring practices.
  • Experience preparing evidence packages for audits and regulatory reviews.
  • Strong analytical skills.
  • Strong documentation skills.
  • Strong reporting skills.
  • Ability to communicate effectively with technical teams.
  • Ability to communicate effectively with management.
  • Ability to communicate effectively with auditors.
  • Ability to communicate effectively with regulatory stakeholders.
  • Excellent organisational skills.
  • Excellent project coordination skills.
  • Fluent in English.
  • Dutch is a plus.
  • French is a plus.

Technical skills

  • Strong technical experience in control selection.
  • Strong technical experience in control implementation guidance.
  • Technical control experience covering Network.
  • Technical control experience covering IAM.
  • Technical control experience covering SSDLC.
  • Technical control experience covering Crypto.
  • Knowledge and practical application of NIS2 risk-management controls.
  • Work supporting compliance with ISO 27001.
  • Work supporting compliance with GDPR.

Tools

  • Risk management processes and tools.
  • Central risk register.