Daily rate: 650€/700€
Context
The Security Architect translates the CISO’s strategic directions into concrete and robust technical solutions. The Security Architect ensures consistency, regulatory compliance (NIS2, GDPR, ISO 27001, IEC 62443…), and the effectiveness of security measures across the entire organization, particularly in the context of critical services and vital infrastructures. Manager Teamlead Security Architect.
The Architect contributes to an integrated security architecture covering IT, OT, cloud, and network environments, leveraging Archimate models and functional frameworks such as CyFun and ISO 27001 to ensure traceability and governance of security capabilities, thereby guaranteeing resilience and business continuity.
Missions
Security Architecture
- Design, formalize, and evolve the target security architecture, integrating requirements from the early stages of project design (Security by Design, Privacy by Design).
- Define security architecture standards, models, and principles in alignment with the organization’s strategic directions.
- Integrate key security domains (network, cloud, IT/OT/IoT, ICAM, data, cryptography, etc.) into a coherent and modular vision.
- Lead or contribute to security intake processes and architecture committees to ensure alignment of solutions with the target architecture.
Risk Management
- Perform technical and architectural risk assessments on projects, infrastructures, business applications, support applications, and industrial systems.
- Identify threats, vulnerabilities, and attack scenarios, and recommend appropriate mitigation measures.
- Maintain a consolidated and up-to-date view of risks across various domains, including ERP systems (SAP), IT/OT/IoT environments, the use of Artificial Intelligence, access management, and inter-application data flows.
Standards, Compliance, and Governance
- Contribute to drafting and updating technical security standards, ensuring their alignment with legal requirements and reference frameworks (CyFun, ISO 27001, IEC 62443, NIST, NIS2, GDPR, etc.).
- Contribute to security governance committees to guide technical decisions.
- Ensure consistency of architectural principles with internal standards and maintain traceability of decisions.
- Participate in coordination with competent authorities when necessary.
Support and Advisory
- Assist project, IT, OT, and business teams in integrating security requirements, including in complex contexts (SAP integration, IT/OT convergence, cloud solutions, access management).
- Provide support during design phases, solution analysis, or procurement processes (RFI/RFP).
- Ensure the alignment of critical architectural components (ICAM, detection and response solutions, cryptography, etc.) with overall security objectives and the IT roadmap.
Continuous Improvement, Security and Technology
- Monitor the evolution of threats, technologies, regulations, and governance models, identifying innovation opportunities.
- Propose continuous improvements to strengthen the security posture, including detection and response, logging, resilience, and identity management.
- Promote modeling, reusability, and consistency of architectural components.
Conformity Criteria
- You comply with the conformity criteria
- Bachelor’s degree in IT, IT risk management, or information security (or equivalent) demonstrated in the CV
- Minimum 5 years of experience in cybersecurity architecture or risk assessment, demonstrated in IT, OT or IoT environments
- Active CISSP certification
- You communicate fluently in English (spoken and written), at least level C1
- You communicate fluently in French or Dutch (spoken and written), at least level C1
- Willing to work on-site at least 3 days per week
Evaluation Criteria
The more experience/knowledge you can demonstrate in the CV, the better your proposal will be evaluated for this criterion.
- Level of experience with cybersecurity frameworks (CyFun, ISO 27001, NIST, IEC 62443, NIS2, GDPR, CIS Controls), based on number of projects and role
- Level of experience in SAP integration (number of projects, role, responsibilities)
- Experience in security assessments including Business Impact Analysis, Threat modelling, Risk assessment and Gap analysis (scope, role, frequency)
- Breadth of technical experience across domains (network, cloud, ICAM, cryptography, monitoring, AI security), based on number of domains covered and project context
- Number and relevance of additional active cybersecurity certifications (CCSP, CISM, CISA, CGEIT, ISO 27001, SABSA)
- Demonstrated experience in stakeholder communication (type of stakeholders, level, context, deliverables)
- Experience in analysis and improvement initiatives (examples of assessments, recommendations, outcomes)
- Degree of autonomy and responsibility in previous roles (lead vs support, decision-making scope)
- Demonstrated through experience gained in previous assignments.
- Experience working in multi-stakeholder environment