For one of our corporate clients in Brussels, we are looking for a Senior Security Risk Assessment Manager to support the CISO Office.
The focus of this role is very clear: risk assessments.
We are not looking for a broad GRC, compliance or policy profile. We need someone who has spent several years performing security risk assessments hands-on and can independently assess risks across complex IT environments.
The organisation is going through a major digital transformation, with more integration across different entities and an increasing number of security assessments as a result. The current team needs additional senior capacity.
What you will do
- Perform end-to-end IT and security risk assessments
- Identify, assess and document security risks
- Evaluate existing controls and define appropriate mitigation measures
- Follow up remediation actions and make sure risks are properly addressed
- Work closely with security teams, architects, IT teams and business stakeholders
- Assess risks in cloud environments, including AWS and Azure
- Help improve and standardise the way risk assessments are performed
- Contribute to better processes, tooling and overall security risk maturity
- Communicate risks clearly and raise awareness across the organisation
What we are looking for
- Several years of hands-on security risk assessment experience
- Risk assessment must have been a core part of your role, not just an occasional responsibility
- Strong background in IT security
- Experience with cloud environments, ideally AWS and Azure
- Good understanding of security controls, risk treatment and remediation
- Able to work independently and take ownership of assessments
- Senior enough to challenge existing approaches and suggest better ways of working
- Strong communication and stakeholder management skills
- Fluent English; Dutch and/or French is a plus
Experience with ISO 27001, NIS2, GDPR or broader security governance is useful, but this is not primarily a compliance or audit role.
The key question is simple: have you spent several years actually performing security risk assessments?
The assignment is intended to be long-term. The initial contract period is shorter, but the expectation is that the consultant will stay involved beyond that period.
📌 Security risk assesment consultant (España)
🏢 recurv
📍 España