- Company Name
- Airties
- Job Title
- Information Security GRC Manager (Belgium)
- Job Description
-
**Job Title:** Information Security GRC Manager
**Role Summary:**
Lead and manage the organization’s Information Security Governance, Risk Management, and Compliance (GRC) program. Oversee the Information Security Management System (ISMS) team, govern risk processes, develop and maintain security policies and procedures, and act as the primary liaison for internal and external audits. Drive security awareness, incident response coordination, product security, and regulatory compliance, ensuring alignment with business objectives and industry standards.
**Expactations:**
- Minimum 8 years of progressive experience in information security, governance, risk, compliance, or audit roles.
- Bachelor’s degree in Information Security, Computer Science, or related discipline; Master’s preferred.
- Current professional certifications (CISSP, CISM, CRISC, CISA) highly desirable.
- Demonstrated expertise with ISO 27001/2/3, NIST, CIS frameworks and GRC toolsets.
- Proven leadership, cross‑functional collaboration, and stakeholder communication skills.
**Key Responsibilities:**
- Lead the ISMS team and oversee all ISMS activities and documentation.
- Govern organization‑wide information security risk processes, conduct risk assessments, and develop mitigation strategies.
- Develop, maintain, and enforce information security policies, procedures, and controls.
- Report security program status and compliance to senior management.
- Coordinate cross‑functional initiatives to align security practices with business goals.
- Provide guidance on security best practices and compliance requirements to stakeholders.
- Design and implement security awareness training and communications.
- Serve as the primary point of contact for external security audits and certification authorities.
- Conduct internal audits to evaluate control effectiveness and recommend improvements.
- Monitor emerging threats, vulnerabilities, and regulatory changes; update security posture accordingly.
- Ensure product security and compliance with contractual and regulatory obligations.
- Lead the organization’s incident response, including external communication.
**Required Skills:**
- Deep understanding of IT infrastructure, software development life cycle, and product architecture.
- Expertise in risk assessment, risk mitigation, and security control implementation.
- Proficient with GRC automation and monitoring tools.
- Strong analytical, problem‑solving, and decision‑making abilities.
- Excellent written and verbal communication, with the capability to collaborate across technical and business teams.
- Leadership and mentoring skills to guide and develop the security team.
- Ability to prioritize multiple tasks, meet deadlines, and adapt in a fast‑paced environment.
**Required Education & Certifications:**
- Bachelor’s degree in Information Security, Computer Science, or related field (Master’s preferred).
- CISSP, CISM, CRISC, or CISA certification required or highly desirable.
---