Job Openings Cybersecurity GRC Manager Job ID: JP054446

About the job Cybersecurity GRC Manager Job ID: JP054446

Cybersecurity GRC Manager

Mission Overview
We are looking for an experienced Cybersecurity GRC Manager to strengthen a cybersecurity team responsible for governance, risk management, and compliance activities within a critical infrastructure environment. The role focuses on implementing and maintaining Information Security Management Systems (ISMS), supporting ISO 27001 certification initiatives, and ensuring compliance with NIS2 requirements across multiple organizations.

Key Responsibilities

  • Lead and maintain Information Security Management System (ISMS) documentation, including policies, procedures, risk treatment plans, and security governance frameworks.
  • Support organizations through ISO 27001 certification programs, from gap analysis to certification audits.
  • Prepare and coordinate internal and external audits, manage non-conformities, and ensure continuous improvement of the ISMS.
  • Drive NIS2 compliance initiatives for essential and important entities.
  • Manage and administer GRC platforms (CISO Assistant or equivalent) for risk, control, compliance, and action plan tracking.
  • Conduct risk assessments based on ISO 27005 or equivalent methodologies.
  • Facilitate workshops, compliance reviews, awareness sessions, and stakeholder meetings.
  • Collaborate closely with CISOs, technical teams, external partners, and business stakeholders.
  • Monitor regulatory developments and ensure alignment with security and privacy requirements, including GDPR.

Required Skills & Expertise

Governance, Risk & Compliance

  • Strong knowledge of ISO 27001:2022, including clauses 4–10 and Annex A controls.
  • Experience implementing and operating an ISMS using the PDCA cycle.
  • Expertise in Statement of Applicability (SoA) management and risk treatment planning.
  • Solid understanding of NIS2 requirements, cybersecurity governance, and incident notification obligations.
  • Knowledge of GDPR and its integration with security governance frameworks.
  • Experience with GRC tools such as CISO Assistant, ServiceNow GRC, Archer, OneTrust, or similar platforms.

Security & Technical Knowledge

  • Good understanding of IT infrastructure, networks, cybersecurity controls, and information security principles.
  • Ability to assess security controls and interact effectively with technical teams.
  • Familiarity with complementary frameworks such as CIS Controls, IEC 62443, and sector-specific security guidelines.
  • Knowledge of MSP environments and critical infrastructure sectors is an advantage.

Soft Skills

  • Excellent documentation and report-writing skills.
  • Strong communication and stakeholder management capabilities.
  • Ability to influence without direct authority and drive compliance initiatives.
  • Strong facilitation, coaching, and change management skills.
  • Autonomous, proactive, and results-oriented.
  • Comfortable working in multi-client and multi-stakeholder environments.

Experience Required

  • 3–5+ years of experience in Information Security, GRC, Compliance, or Cybersecurity Governance roles.
  • Proven experience supporting or leading ISO 27001 certification programs through a complete certification cycle.
  • Experience in consulting, managed services, or multi-client environments is highly desirable.
  • Experience in regulated sectors such as utilities, critical infrastructure, energy, healthcare, or finance is a strong asset.
  • ISO 27001 Lead Implementer certification is highly desirable.

Languages

  • French: Fluent (written and spoken)
  • English: Technical proficiency is an asset

Work Location

  • Couillet, Belgium
  • Hybrid working model

Contract Type

  • Long-term consulting assignment with potential extension based on project needs and performance.