- Contract
- Anywhere
Location: Near Spa, Belgium Duration: 12-month contract (with possible extension) Work Setup: Hybrid, 2 days on-site per week Language: Fluent French required, English mandatory
The Opportunity
Our client, a key organization operating within the utilities sector, is looking for an experienced CISO (Chief Information Security Officer) to lead and mature its information security program. The consultant will be responsible for cybersecurity governance, risk management, regulatory compliance, and the implementation of security best practices across the organization.
Key Responsibilities
Information Security Strategy
Â
- Define and implement the information security strategy aligned with NIS2 and ISO 27001 requirements.
- Identify critical assets and assess information security risks.
- Develop and present a multi-year cybersecurity roadmap to executive stakeholders.
Governance, Risk & Compliance
Â
- Ensure compliance with NIS2 and relevant cybersecurity regulations.
- Develop, maintain, and improve security policies and procedures.
- Support and maintain ISO 27001 certification initiatives.
- Establish and monitor security KPIs and KRIs.
Risk Management
Â
- Lead information security risk assessments and treatment plans.
- Advise projects and operational teams on security requirements.
- Implement appropriate controls to mitigate identified risks.
Incident Management & Cyber Resilience
Â
- Develop and maintain incident response plans.
- Coordinate security incident handling and reporting.
- Ensure compliance with mandatory notification requirements.
- Improve threat detection and response capabilities.
Security Awareness
Â
- Develop and deliver security awareness programs.
- Promote a strong security culture across the organization.
- Organize workshops, communications, and targeted training sessions.
Stakeholder Management
Â
- Work closely with senior management, IT teams, external partners, and regulatory bodies.
- Collaborate with Data Protection and Compliance stakeholders.
- Provide regular reporting on security posture, risks, and remediation activities.
Required Experience
Â
- Minimum 5 years of experience in Information Security, Cybersecurity, Risk Management, or a CISO-related role.
- Proven experience designing and implementing security governance frameworks.
- Strong knowledge of: ISO 27001 NIS2 Security Risk Management Security Governance & Compliance Incident Response Security Awareness Programs
- Experience engaging with executive-level stakeholders.
Preferred Qualifications
Â
- Previous experience as a CISO or Deputy CISO.
- CISSP and/or CISM certification.
- ISO 27001 Lead Implementer or Lead Auditor certification.
- Knowledge of ISO 27005 and ISO 31000.
- Experience within critical infrastructure, utilities, energy, water, industrial, or public sector environments.
- Experience leading ISO 27001 certification programs from inception to certification.
- Familiarity with cloud security, IAM, industrial systems/OT security, and vulnerability management.
Language Requirements
Â
- French: Native or Fluent (mandatory)
- English: Professional working proficiency
- Dutch is a plus.
Contract Details
Â
- Freelance contract
- Initial duration: 12 months
- Hybrid working model
- 2 days per week on-site near Spa
- Immediate or short-notice start preferred
