Experis is seeking an Information Security Officer, who you will play a key role in translating the organization's CISO vision into actionable strategies, processes, and services. Your primary focus will be implementing high-level, innovative, yet practical solutions to safeguard the organization’s assets, including physical and electronic information/data and IT systems, as well as those of its subsidiaries.
Responsibilities:
- Define security objectives and metrics aligned with the CISO's strategic plan and priorities. Actively maintain the Information Security Management System (ISMS) following international standards. Monitor and update CISO dashboards, initiate corrective measures within the IT organization, and manage the CISO mailbox. Follow up on internal and external IT audit actions, providing regular updates to IT management and internal audit teams.
- Develop and maintain an information risk management framework based on ISF IRAM. Create, implement, and manage processes for information risk analysis, treatment, and monitoring. Integrate risk management processes into existing business and IT workflows. Conduct and document risk analyses for new projects and existing systems while maintaining an information risk register. Report risks clearly and ensure follow-up on mitigating actions with business owners.
- Define requirements for cybersecurity solutions and services. Oversee cybersecurity services provided by IT sourcing partners. Establish, maintain, and execute CSIRT (Computer Security Incident Response Team) activities. Develop and implement strategies, solutions, and governance for Identity & Access Management.
- Draft, approve, communicate, enforce, and regularly review security policies, standards, and procedures. Roll out a company-wide long-term information security awareness program in collaboration with HR, internal communication teams, and training initiatives. Engage security liaisons to implement policies, resolve incidents, and promote awareness.
- Manage and coordinate projects within the Information Security department, focusing on priorities, budgets, and resource planning. Collaborate with IT PMO and other departments to align security projects with IT processes.
- Prepare quarterly reports on CISO domains for the executive committee. Provide progress updates, budget and resource reports, and project templates for senior management. Generate reports on security findings and ensure timely follow-ups.
- Develop and maintain an IT audit and compliance framework aligned with legal and strategic objectives. Collaborate with Data Protection Officers and Risk Managers to address audit findings and compliance breaches. Conduct IT audits to identify issues, draft findings, and propose mitigation scenarios.
- Stay updated on security threats, market trends, technologies, and relevant legislation. Continuously attend training, seminars, and workshops to maintain expertise in the rapidly evolving cybersecurity domain.
Required Qualifications:
- Master’s degree or equivalent experience. 3–5 years of relevant experience in information security. Proficiency in ISO2700x standards and IT processes. In-depth knowledge of one or more CISO domains (e.g., IT Risk Management, Compliance). Familiarity with security architecture and controls. Certifications such as CISSP, CISM, or CISA are highly valued. Strong communication skills in Dutch, French, and English (both written and verbal).
Competencies:
- Ability to translate strategic plans into concrete objectives and actions. Capable of managing multiple projects simultaneously and delegating tasks effectively. Skilled in developing frameworks, procedures, and awareness programs. Analytical mindset for risk assessments and incident management. Expertise in presenting technical and strategic insights to senior management.
This role offers the opportunity to work in a fast-paced and evolving environment where your expertise will directly impact the organization’s security posture. If you’re passionate about information security and risk management, we encourage you to apply!