IT Risk & Compliance Officer ISO 27001 (Senior)

Rhox

Brussel

Sur place

EUR 85 000 - 120 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV personnalisé et une lettre de motivation en environ une minute.

Passez les filtres ATS

Résumé du poste

Rhox in Belgium is seeking a Senior IT Risk and Compliance Officer to strengthen its ISMS and governance. Reporting to the CISO, you assess IT, cloud, OT and information assets, translating findings into a prioritised improvement roadmap aligned with ISO 27001, CyFun and NIST.

You will map assets, review CMDBs, run interviews, and benchmark controls; you will present executive summaries and enable the information security team with autonomous expert advice.

Qualifications

  • Senior expertise in IT asset management assessments covering inventory, classification, ownership and lifecycle management.
  • Experience assessing IT, cloud, OT and information assets.
  • Knowledge of asset discovery and classification, including shadow IT detection.
  • Experience evaluating asset registers, CMDB and discovery tools, including ServiceNow, Lansweeper, Tanium or equivalent.
  • Ability to analyse risks linked to unmanaged, obsolete or unpatched assets.
  • Ability to benchmark controls against ISO 27001 Annex A 5.9-5.14, CyFun and NIST SP 800-53.

Responsabilités

  • Map the current management of hardware, software, data, cloud and OT assets.
  • Evaluate asset registers, CMDB and discovery tools for completeness and currency.
  • Run interviews and workshops with infrastructure, application management and security stakeholders.
  • Benchmark asset management against ISO 27001 Annex A 5.9-5.14, CyFun and NIST SP 800-53.
  • Analyse and prioritise risks from unmanaged, obsolete or unpatched assets.
  • Build a roadmap for asset discovery, classification, ownership and lifecycle management.
  • Present findings to the CISO and management, then transfer knowledge to the information security team.

Connaissances

Asset management
IT risk assessment
Cloud assets
CMDB evaluation
Discovery tools
Stakeholder interviews
Reporting to CISO

Formation

Master's degree or equivalent

Outils

ServiceNow
Lansweeper
Tanium

Description du poste

A public-sector organisation is strengthening its information security management system (ISMS) and governance. Reporting to the CISO, the senior IT Risk and Compliance Officer assesses IT, cloud, OT and information assets, then turns findings into a prioritised improvement roadmap aligned with ISO 27001, CyFun and NIST.

The mission

The assignment provides an objective asset management assessment across IT, cloud, OT and information assets. It covers the AS-IS state, coverage rates, maturity, risk exposure and highest-priority improvements. You review existing inventories, asset registers, the CMDB, discovery tools and processes.

Your analysis produces a risk and priority matrix for assets that are unmanaged, poorly known, obsolete or unpatched. It supports a concrete roadmap for discovery, classification, ownership and lifecycle management, alongside an executive summary for the CISO and management. The short scope requires autonomous expert advice from the start, while final follow-up and decisions remain with the CISO.

Your responsibilities
  • Map the current management of hardware, software, data, cloud and OT assets.
  • Evaluate asset registers, CMDB and discovery tools for completeness and currency.
  • Run interviews and workshops with infrastructure, application management and security stakeholders.
  • Benchmark asset management against ISO 27001 Annex A 5.9-5.14, CyFun and NIST SP 800-53.
  • Analyse and prioritise risks from unmanaged, obsolete or unpatched assets.
  • Build a roadmap for asset discovery, classification, ownership and lifecycle management.
  • Present findings to the CISO and management, then transfer knowledge to the information security team.
Your profile
Essential skills
  • Senior expertise in IT asset management assessments covering inventory, classification, ownership and lifecycle management.
  • Experience assessing IT, cloud, OT and information assets.
  • Knowledge of asset discovery and classification, including shadow IT detection.
  • Experience evaluating asset registers, CMDB and discovery tools, including ServiceNow, Lansweeper, Tanium or equivalent.
  • Ability to analyse risks linked to unmanaged, obsolete or unpatched assets.
  • Ability to benchmark controls against ISO 27001 Annex A 5.9-5.14, CyFun and NIST SP 800-53.
  • Clear, convincing reporting to management and the CISO.
  • Ability to provide authoritative advice under broad direction, equivalent to SFIA level 5, Ensure, advise.
  • Ability to work autonomously from the start of a short assignment.
Preferred skills
  • Certification such as ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, CISM or CDPSE.
Languages
  • English, B2, required.
  • Dutch, B2.
  • French, B2.
  • Dutch and French bilingualism is an advantage.
Education
  • Master's degree, or equivalent confirmed relevant experience.
Working context
  • Reports to the CISO and collaborates with IT infrastructure, application management and security teams.
  • Uses interviews and workshops to work with varied audiences, from management to IT administrators.
  • Transfers knowledge to the information security team at the end of the assignment.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Cybersecurity Specialist Security Awareness (Senior)
Cybersecurity Specialist Security Awareness (Senior)

Rhox • Brussel

Sur place
EUR 100 000 - 179 000
Asset Management Expert Consultant
Asset Management Expert Consultant

Keystone Solutions • Brussel

Hybride
EUR 90 000 - 140 000
Asset Management Expert Consultant
Asset Management Expert Consultant

keystone-solutions • Brussel

Hybride
EUR 90 000 - 120 000
Asset Management Expert Consultant
Asset Management Expert Consultant

Keystone Solutions • Belgique

Hybride
EUR 90 000 - 130 000
Hybrid work model
Client site assignment
Knowledge transfer
Senior IT Risk & Compliance Lead | ISO 27001 Asset Management
Senior IT Risk & Compliance Lead | ISO 27001 Asset Management

Rhox • Brussel

Sur place
EUR 85 000 - 120 000
Security Officer
Security Officer

Editx • Brussel

Sur place
EUR 70 000 - 100 000
General Cybersecurity Assessment Expert
General Cybersecurity Assessment Expert

keystone-solutions • Brussel

Sur place
EUR 70 000 - 100 000
Cybersecurity Awareness Expert
Cybersecurity Awareness Expert

Keystone Solutions • Brussel

Hybride
EUR 100 000 - 134 000
CISO Officer (TPRM)
CISO Officer (TPRM)

act digital • Brussel

Hybride
EUR 65 000 - 85 000
Cybersecurity Awareness Expert
Cybersecurity Awareness Expert

keystone-solutions • Brussel

Hybride
EUR 111 000 - 166 000