Our client, a dynamic legal services firm, is undergoing a far-reaching digital transformation. With the rapid adoption of cloud technologies, AI applications and automated processes, their digital risk landscape is growing in complexity. To support this securely and compliantly, they are expanding their team with a hands-on GRC Officer.
You report directly to the Digital Risk & Compliance Lead and support the execution of the governance, risk and compliance activities. A key part of your role is creating and maintaining the processes, guidelines and policies that form the foundation of their GRC practice.
Responsibilities:
•Create, document and maintain GRC processes, guidelines and information security policies, aligned with evolving regulations and business needs.
•Support risk assessments on IT systems, vendors and digital projects (ISO 27001, CIS18, NIST) and maintain the risk register and treatment plans.
•Support compliance with NIS2, GDPR and the EU AI Act; prepare audit evidence and follow up on findings until closure.
•Execute vendor risk assessments and security questionnaires; maintain the third-party risk inventory.
•Track control effectiveness through KPIs and prepare status reports for the Lead and senior management.
•Support security awareness initiatives and act as first point of contact for day-to-day security and compliance questions.
Profile:
•1 to 2 years of experience in information security management, third-party risk management, GRC or a related discipline.
•A strong willingness to grow and develop further in the GRC field.
•First practical experience with regulatory frameworks (GDPR, NIS2, EU AI Act) and standards (ISO 27001, CIS18, NIST CSF).
•Hands-on exposure to risk assessments, audit preparation or third-party risk questionnaires.
•Structured, precise and self-organizing, with strong communication skills towards non-technical colleagues.
•Certifications such as ISO 27001 Foundation/Lead Implementer or CompTIA Security+ are an advantage.
•Fluent in French and English; knowledge of Dutch is a plus.
•Experience with (or exposure to) an ISMS or GRC platform.
•Good understanding of cloud and SaaS environments (Azure, Microsoft 365) and their governance implications.
•Basic knowledge of IAM concepts (RBAC, MFA, Active Directory / Entra ID).
•Understanding of data classification and privacy-by-design in the context of GDPR.
•Familiarity with vulnerability management, patching and endpoint protection concepts.
Offer:
•A clearly scoped assignment with real ownership of the operational GRC agenda.
•Close collaboration with an experienced Lead — a strong learning environment for growing into a senior risk role.
•1 day of homeworking per week, with possibility of extension based on mutual agreement.
Reaction:
Greg Bastiaensen
Business Unit Manager
T: +32 477 87 03 06
E:
[email protected]
A: Amsterdamstraat 20, B-2000 Antwerp
📌 Grc officer (España)
🏢 Bridge Industrial
📍 España