Overslaan naar inhoud

Senior Initiative Owner - Cyber Security Strategy (Post-Quantum Readiness) - BNP Paribas Fortis

Customer: BNP Paribas Fortis Koningsstraat 97 1000 Brussels België
Dates: 2026-08-03 2027-06-07
Arrangements: Hybrid (50% on-site / 50% homeworking)
Apply before: 2026-09-02

Description

The Senior Initiative Owner joins the CoE Security – Strategy and Delivery team to define cyber security initiative strategy, including emerging post-quantum threats, and translate it into a prioritized portfolio of projects, enhancements, and studies. The role oversees the purpose, value, status, and cross-dependencies of portfolio items so they collectively achieve business outcomes. It combines strategic ownership with day-to-day roadmap delivery and resolution of impediments, including challenges associated with the PQC transition. The consultant will balance traditional security measures with quantum-resistant approaches.

The role develops high-level and detailed short- and medium-term roadmaps, priority actions, and budgets while accounting for long-term cryptographic resilience and PQC migration timelines. It directs cyber security initiatives from inception through completion, including PQC readiness assessments and mitigation planning. Workstreams, milestones, master-plan adherence, risks, issues, vendor dependencies, legacy constraints, and cryptographic agility must all be actively managed. The Initiative Owner also collaborates with Group to roll out standard solutions while balancing business needs and quantum-safe security requirements.

A major part of the assignment is executive and cross-functional engagement across the bank. The consultant will build quantum-risk awareness, justify investments, aggregate stakeholder input into management deliverables, and communicate effectively with both executives and technicians. Initiatives must align with Group standards, regulations, and evolving cryptographic policies such as ETSI/IETF PQC guidelines, while contributing to improvements such as quantum-safe data security frameworks. Success requires deep information-security governance knowledge, PQC understanding, analytical strength, leadership, communication, and proactive problem-solving.

Top Reasons to Apply
Post-quantum strategy leadership
Bank-wide strategic impact
Executive stakeholder exposure
Cryptographic modernization
Hybrid work flexibility
Responsibilities
Define security initiative strategy
Translate strategy into portfolio
Oversee portfolio value status
Manage portfolio cross-dependencies
Drive roadmap daily delivery
Resolve initiative delivery impediments
Engage diverse security stakeholders
Co-develop strategy roadmaps actions
Must Have
Master’s degree
Project management certification
Change management certification
Fluent French
Fluent Dutch
Fluent English
10+ years IT/security management
Information security governance
Nice to Have
CISSP certification
CISA certification
CRISC certification
IT transformation projects
Cryptographic modernization experience
Financial services experience
Agile methodology experience
Maturity transformation experience
Quality transformation experience

Detailed Responsibilities and Skills

Additional Responsibilities

  • Balance traditional quantum security
  • Deliver bank-wide security roadmaps
  • Set security investment priorities
  • Communicate with senior management
  • Develop strategic security roadmaps
  • Develop priority actions budgets
  • Account for cryptographic resilience
  • Plan PQC migration timelines
  • Collaborate on standard solutions
  • Balance business security needs
  • Direct cyber initiative phases
  • Conduct PQC readiness assessments
  • Plan PQC risk mitigation
  • Prioritize security initiative workstreams
  • Embed cryptographic agility designs
  • Set project delivery milestones
  • Ensure master plan adherence
  • Mitigate project risks issues
  • Flag PQC-specific dependencies
  • Challenge roadmaps with awareness
  • Engage senior executive management
  • Build quantum risk awareness
  • Justify security investments
  • Aggregate stakeholder input deliverables
  • Produce PQC impact memos
  • Ensure Group standards alignment
  • Ensure regulatory policy alignment
  • Contribute security policy improvements

General skills

  • Master’s degree (mandatory).
  • Project management certification such as PRINCE2 or ITIL (mandatory).
  • Change management certification such as ADKAR (mandatory).
  • Fluent French for Group communication (mandatory).
  • Fluent Dutch.
  • Fluent English.
  • 10+ years managing multiple IT/security projects or programs.
  • Information security governance experience (mandatory).
  • Analytical skills to break down complex issues such as PQC migration trade-offs (mandatory).
  • Leadership to drive success across disciplines and navigate technical uncertainty such as PQC vendor maturity.
  • Communication skills to tailor messaging for executives, including quantum-risk ROI.
  • Communication skills to tailor messaging for technicians, including algorithm trade-offs.
  • Proactive problem-solving addressing long-term cryptographic risks alongside immediate vulnerabilities.

Technical skills

  • Strong understanding of information security governance, including frameworks and risk management.
  • Strong understanding of Post-Quantum Cryptography fundamentals, including lattice-based algorithms, hybrid encryption, and NIST standardization.
  • Strong understanding of cryptographic inventory and assessment methodologies, including identification of PQC-vulnerable systems.
  • CISSP certification (preferred).
  • CISA certification (preferred).
  • CRISC certification (preferred).
  • IT transformation project experience, such as cryptographic modernization (preferred).
  • Financial services industry experience (preferred).
  • Agile methodology experience, including maturity/quality transformation (preferred).