We are seeking a Senior Chief Information Security Officer (CISO) to strengthen the governance of information security within our organization.
In the context of increasing digitalization of public services and the implementation of the NIS2 Directive, the CISO will lead the design, execution, and continuous improvement of the organization’s cybersecurity strategy and operational resilience framework.
This role combines strategic leadership, regulatory compliance oversight, risk management, crisis preparedness, and organizational transformation.
Define, maintain, and execute the organization’s cybersecurity and information risk management strategy, aligned with:
NIS2 requirements
The organization’s digital transformation roadmap
Public service objectives
Develop and manage a multi-year cybersecurity roadmap with clear priorities, deliverables, and KPIs.
Oversee cybersecurity program management and ensure alignment across departments.
Identify risks, assess impact, and ensure structured mitigation plans.
Lead the organization’s compliance with NIS2 and related regulatory obligations.
Conduct gap analyses and maturity assessments.
Develop and implement structured remediation plans.
Ensure proper documentation, audit readiness, and regulatory reporting.
Oversee third-party and supply chain cybersecurity risk management.
Design, implement, and continuously improve the Information Security Management System (ISMS), including:
Security policies and procedures
Governance structures
Defined roles and responsibilities
Internal controls and monitoring mechanisms
Risk and compliance dashboards
Ensure effective risk monitoring through measurable KPIs and KRIs.
Embed secure-by-design and risk-based approaches across projects.
Establish and maintain a structured cyber incident and crisis management framework.
Define escalation processes and crisis governance models.
Organize and lead simulation exercises (tabletop exercises, incident drills).
Coordinate with executive leadership during major incidents.
Strengthen overall organizational resilience.
Provide regular, structured reporting to executive management and/or the Board:
Risk exposure overview
Compliance status
Roadmap progress
Incident trends
Translate cybersecurity risks into business and operational impacts.
Support informed decision-making at strategic level.
Act as a bridge between:
Business units
IT and infrastructure teams
Legal and compliance
External service providers
Ensure cybersecurity is integrated into product development and operational processes.
Promote a security-aware culture across the organization.
Collaborate with peer institutions and sector bodies on best practices.
Guide teams and stakeholders in increasing cybersecurity maturity.
Provide mentorship and structured knowledge transfer to internal teams.
Support succession planning and capability building for long-term sustainability.
Master’s degree in Information Security, Computer Science, Engineering, or equivalent experience.
Minimum 10 years of experience in cybersecurity, including:
5+ years in a senior leadership role (CISO or equivalent).
Proven experience implementing NIS/NIS2 compliance programs.
Experience in public sector or regulated environments is strongly preferred.
Demonstrated experience in cybersecurity governance, risk management, and program leadership.
Un plan personnalisé pour postuler intelligemment à cette offre.
Cliquez sur "Postuler" pour accéder à l'offre.