N’envoyez pas un CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.
Vivid Resourcing seeks a Defensive Security & Compliance Specialist to strengthen detection, response, and regulatory readiness for Brussels-based security function. You will work at the intersection of blue-team operations and governance, contributing to NIS2 and DORA compliance for EU clients.
The role collaborates with legal, IT, and business teams to ensure regulatory obligations are evidenced, supports audits, and advances policies and incident response practices across EU institutions and
Defensive Security & Compliance Specialist (GRC/SOC) – Brussels, Belgium
About the Role We're looking for a Defensive Security & Compliance Specialist to strengthen detection, response, and regulatory readiness for a growing security function in Brussels. This role sits at the intersection of blue-team operations and governance, playing a key part in NIS2 and DORA compliance efforts as clients across finance and critical infrastructure adapt to tightening EU regulation.
Key Responsibilities:
• Monitor, detect, and respond to security incidents via SIEM/EDR platforms; support containment and recovery efforts
• Maintain and improve detection rules, playbooks, and incident response procedures
• Lead or support risk assessments, gap analyses, and audits against ISO 27001, NIS2, DORA, and GDPR requirements
• Develop and maintain security policies, control frameworks, and compliance documentation
• Coordinate with legal, IT, and business stakeholders to ensure regulatory obligations are met and evidenced
• Support external audits and regulator engagement where required
• Track and report on security posture and compliance status to leadership
Requirements:
• 3+ years' experience across SOC operations, GRC, or a blended security/compliance role
• Working knowledge of NIS2, DORA, ISO 27001, and GDPR requirements as they apply in Belgium/EU
• Familiarity with SIEM tooling (Splunk, Sentinel, QRadar) and risk management frameworks
• Relevant certifications a plus (CISA, CISM, ISO 27001 Lead Implementer/Auditor, CRISC) • Strong stakeholder management skills — comfortable translating technical risk into business language
• Fluent English required; Dutch and/or French highly desirable given regulatory and client work in Belgium
• Experience with EU institutions, financial services, or critical infrastructure clients a plus
What's on Offer:
• Group and Health insurances.
• Clear progression path toward Incident Response or Threat Intelligence specialisms
• Exposure to EU institution and multinational client environments
If interested, feel free to reach out: jonty.dawes@vividresourcing.com