IT – Risk Officer

  • Location: Brussel
  • Type: Perm
  • Job #13545


You are responsible for guarding the vision, the development of strategy and the implementation of the Information Security Risk and IT Risk Management program within the organization (including its affiliates).

You identify, analyze and report information security risks for different Business Units. You provide Information Security requirements for IT projects. You will follow up on the implementation status of agreed controls.

You identify, analyze and report on the internal IT risks, and take care of the follow-up. You maintain the risk register and take care of the management reporting.

You participate in the implementation of an ISMS. You define risk policies, standards, procedures and guidelines. You take care of their communication and awareness at the respective audiences. You follow up and report on their implementation and status.

The influence of the IT Risk Officer extends across the entire enterprise. You report to the Teamlead IT Risk Office.

Location: Brussels


  • Information Risk Management
    • Setting up and maintaining an Information Risk Management framework, based on ISF IRAM.
    • Defining, organizing and applying "information risk analysis", "information risk treatment" and “information risk monitoring” processes, policies and standards.
    • Defining and managing the approval and evaluation processes of these new processes and standards.
    • Incorporation of information risk management processes in the existing business and IT processes.
    • Execute, formulate practically and pragmatically, monitor and adjust information risk analysis for new projects and existing situations.
    • Setting up, reporting and maintaining an information risk registry.
  • IT Risk Management
    • Maintaining an IT risk management framework, based on ISF IRAM.
    • Applying information risk analysis, information risk treatment and information risk monitoring processes, policies and standards.
    • Execute, formulate practically and pragmatically, monitor and adjust information risk analysis for new projects and existing situations.
    • Maintaining an information risk registry.
    • Unambiguous reporting of risks as well as follow-up of mitigating actions towards the business owners.

In both of these domains, you will work closely with IT PMO to align with existing IT processes, with IT project managers and operational managers to identify or mitigate risks, with Data Protection Officers to guard privacy, with IT Compliance Officers, with the Cybersecurity team, and with IT Service Continuity Officers to align on risks and BIA’s.


  • Bachelor’s in Computer Science, Information Systems or related field; or you have equivalent work experience.
  • Minimum of 3 to 10 years of work experience in risk management and/or information security.


  • Experience in assessing and managing IT and/or Information Risk
  • Knowledge of ISO2700x, ISO31000, COBIT5, ITIL, …
  • Knowledge of security architectures and controls
  • Broad knowledge of IT processes and technology
  • Experience in managing and overseeing security in third party service providers
  • Knowledge of ISF IRAM is a plus
  • Certifications: CISSP, CISM, CISA or CRISC is a plus
  • Customer focus and able to handle in an organization-sensitive way
  • Problem analysis and conflict management
  • Record of responsibility
  • Language requirements: fluent (oral and written) in Dutch/English; passive understanding of French.


  • Total compensation package including fringe benefits.
  • A company that values innovation and contribution, uncompromising integrity, trust, respect and teamwork, speed, focus, and accountability.
  • There is the possibility to start on customer’s payroll with long term perspective.


Interested in this opportunity?

Send your latest resume and/or questions to [email protected]

Attach a resume file. Accepted file types are DOC, DOCX, PDF, HTML, and TXT.

We are uploading your application. It may take a few moments to read your resume. Please wait!