OmDev Logo
GetYourJob
0
Publié il y a 207 jours

IT & Cyber Risk Management Advisor – Expert - Freelance

Entreprise
Localisation
Brussels, Belgium
Hybride
Type de contrat
Freelance
Niveau
Top profil
Rémunération
650 - 750ۥ Taux journalier
4vues
0clics

Description du poste

Daily rate: 650€/750€ or CDI

Position Overview

We are looking for an experienced IT & Cyber Risk Management Advisor to join a Governance, Risk & Compliance (GRC) team within a large and complex organization.

In this role, you will support IT and Business stakeholders in identifying, assessing, monitoring, and mitigating IT and Cyber risks. You will act as a trusted advisor, ensuring that operational risk management practices are effectively implemented and aligned with internal policies and industry best practices.

This position requires strong expertise in IT risk governance, cybersecurity, cloud environments, and control frameworks, combined with excellent stakeholder management capabilities.

Key Responsibilities

IT & Cyber Risk Oversight

  • Support and monitor IT and Cyber risks owned by IT domains, business units, or product organizations.

  • Ensure quality assurance of IT and Cyber risks from identification through treatment to formal closure.

  • Perform risk assessments on applications, projects, Agile structures (e.g., Tribes, Squads), and third-party providers.

  • Assess and manage risks related to Shadow IT (applications outside formal IT governance).

Advisory & Stakeholder Support

  • Provide expert guidance on IT and Cyber Risk Management to internal IT and Business stakeholders.

  • Advise on risk treatment plans and challenge mitigation strategies where needed.

  • Promote risk-aware decision-making while balancing business objectives and regulatory requirements.

Reporting & Governance

  • Report IT and Cyber risk exposure and overall risk posture to relevant management and security stakeholders.

  • Contribute to risk dashboards, executive reporting, and governance forums.

  • Ensure alignment with internal IT and Cyber policies and broader group standards.

Continuous Improvement

  • Contribute to the evolution and enhancement of risk management methods, processes, and tools.

  • Integrate best practices and lessons learned from operational experience.

  • Support the alignment and integration between ISMS frameworks and IT Risk processes.

Required Experience & Expertise

Experience

  • Minimum 8 years of proven experience in IT Risk Management, Cyber Security, or related technical/functional domains.

  • Strong experience in complex IT environments with multiple stakeholders.

  • Experience in a regulated environment is highly desirable (banking or financial services is a plus).

Technical & Functional Skills (Mandatory)

  • Strong understanding of ISMS frameworks and the linkage between ISMS and IT Risk processes.

  • Knowledge of control frameworks and audit methodologies (e.g., ISO 27001, NIST, COBIT or similar).

  • Solid experience with cloud services (SaaS, Hosted Service Providers, AWS or similar platforms).

  • Knowledge of secure software development practices.

  • Experience in release management, change management, incident management, and testing processes.

  • Ability to assess risks across infrastructure, applications, cloud services, and third parties.

Preferred Certifications

  • CISSP

  • CISM

  • CIPP

  • CCSK

  • Or equivalent security certifications

Education

  • Master’s degree (or equivalent experience).

Language Requirements

  • Sound knowledge of English (written and spoken) is mandatory.

  • Dutch and/or French are considered strong assets.

  • At least English plus one local language is expected.

Soft Skills & Personal Attributes

  • Strong autonomy, ownership, and perseverance.

  • Proactive mindset and quick self-starter attitude.

  • Team player with a results-oriented approach.

  • Excellent written communication skills in English.

  • Strong interpersonal skills with the ability to interact with stakeholders at all levels of the organization.

  • Strong analytical and synthesis skills.

  • Ability to produce structured, concise, and precise documentation.

  • Detail-oriented and control-minded, while remaining pragmatic and flexible.

Exigences du poste

Stack technique :

CybersecurityGestion des risquesConsulting Cybersecurity

Plan d'action

Un plan personnalisé pour postuler intelligemment à cette offre.

Publié par

Recruteur
Recruteur

Intéressé par cette offre ?

Cliquez sur "Postuler" pour accéder à l'offre.