OmDev Logo
GetYourJob
0
Publié il y a 213 jours

CISO - Freelance

Entreprise
Localisation
Brussels, Belgium
Hybride
Type de contrat
Freelance
Niveau
Top profil
Rémunération
750 - 850ۥ Taux journalier
0vues
0clics

Description du poste

Daily rate: 750€/850€

Position Overview

We are seeking a Senior Chief Information Security Officer (CISO) to strengthen the governance of information security within our organization.

In the context of increasing digitalization of public services and the implementation of the NIS2 Directive, the CISO will lead the design, execution, and continuous improvement of the organization’s cybersecurity strategy and operational resilience framework.

This role combines strategic leadership, regulatory compliance oversight, risk management, crisis preparedness, and organizational transformation.

Key Responsibilities

1. Cybersecurity Strategy & Program Leadership

  • Define, maintain, and execute the organization’s cybersecurity and information risk management strategy, aligned with:

    • NIS2 requirements

    • The organization’s digital transformation roadmap

    • Public service objectives

  • Develop and manage a multi-year cybersecurity roadmap with clear priorities, deliverables, and KPIs.

  • Oversee cybersecurity program management and ensure alignment across departments.

  • Identify risks, assess impact, and ensure structured mitigation plans.

2. NIS2 Compliance & Regulatory Governance

  • Lead the organization’s compliance with NIS2 and related regulatory obligations.

  • Conduct gap analyses and maturity assessments.

  • Develop and implement structured remediation plans.

  • Ensure proper documentation, audit readiness, and regulatory reporting.

  • Oversee third-party and supply chain cybersecurity risk management.

3. ISMS Design & Maintenance

  • Design, implement, and continuously improve the Information Security Management System (ISMS), including:

    • Security policies and procedures

    • Governance structures

    • Defined roles and responsibilities

    • Internal controls and monitoring mechanisms

    • Risk and compliance dashboards

  • Ensure effective risk monitoring through measurable KPIs and KRIs.

  • Embed secure-by-design and risk-based approaches across projects.

4. Crisis Management & Operational Resilience

  • Establish and maintain a structured cyber incident and crisis management framework.

  • Define escalation processes and crisis governance models.

  • Organize and lead simulation exercises (tabletop exercises, incident drills).

  • Coordinate with executive leadership during major incidents.

  • Strengthen overall organizational resilience.

5. Executive Reporting & Risk Communication

  • Provide regular, structured reporting to executive management and/or the Board:

    • Risk exposure overview

    • Compliance status

    • Roadmap progress

    • Incident trends

  • Translate cybersecurity risks into business and operational impacts.

  • Support informed decision-making at strategic level.

6. Cross-Functional & External Collaboration

  • Act as a bridge between:

    • Business units

    • IT and infrastructure teams

    • Legal and compliance

    • External service providers

  • Ensure cybersecurity is integrated into product development and operational processes.

  • Promote a security-aware culture across the organization.

  • Collaborate with peer institutions and sector bodies on best practices.

7. Leadership & Knowledge Transfer

  • Guide teams and stakeholders in increasing cybersecurity maturity.

  • Provide mentorship and structured knowledge transfer to internal teams.

  • Support succession planning and capability building for long-term sustainability.

Profile & Qualifications

Education

  • Master’s degree in Information Security, Computer Science, Engineering, or equivalent experience.

Experience

  • Minimum 10 years of experience in cybersecurity, including:

    • 5+ years in a senior leadership role (CISO or equivalent).

  • Proven experience implementing NIS/NIS2 compliance programs.

  • Experience in public sector or regulated environments is strongly preferred.

  • Demonstrated experience in cybersecurity governance, risk management, and program leadership.

Exigences du poste

Stack technique :

CybersecurityGovernance

Plan d'action

Un plan personnalisé pour postuler intelligemment à cette offre.

Publié par

Recruteur
Recruteur

Intéressé par cette offre ?

Cliquez sur "Postuler" pour accéder à l'offre.