- Company Name
- EngiFlex
- Job Title
- Security Program Manager (Freelance possible)
- Job Description
-
**Job title**
Security Program Manager (Freelance possible)
**Role Summary**
Support the CISO in developing and executing the organization’s information security strategy and roadmap. Manage compliance, governance, and program management functions to strengthen security maturity and continuity. Coordinate cross‑functional initiatives, produce strategic artifacts, and drive the implementation of policies, ISMS, and technology solutions.
**Expectations**
- Deliver actionable security strategy and roadmap documents.
- Produce policies, procedures, and compliance reports.
- Develop templates, tools, and an awareness/training program.
- Track KPIs and maturity model metrics.
- Facilitate workshops, audits, and risk assessments.
- Align security projects with strategic priorities and budget.
- Optimize processes and advocate continuous improvement.
- Communicate status, risks, and recommendations to senior leadership.
**Key Responsibilities**
1. Prepare analyses and support CISO presentations and strategic meetings.
2. Coordinate development, implementation, and monitoring of cybersecurity policies and ISMS.
3. Track and report KPIs, maturity levels, and compliance status.
4. Identify and report non‑conformities and suggest corrective actions.
5. Facilitate workshops, awareness campaigns, and training initiatives.
6. Inventory ongoing projects, ensure alignment with the security roadmap, and recommend resource allocations.
7. Propose process optimization and budget‑efficiency measures.
8. Support internal audits and risk assessments, including incident response coordination.
9. Communicate, coordinate, and collaborate with internal and external stakeholders, including procurement and regulatory bodies.
10. Maintain up‑to‑date knowledge of laws, regulations, and industry standards (GDPR, NIS2, ISO 27001/27002).
**Required Skills**
- Strategic security planning and roadmap development.
- ISMS design, implementation, and continuous improvement (ISO 27001/27002).
- Regulatory compliance (GDPR, NIS2) and policy development.
- SOC/SIEM implementation and incident response coordination.
- Identity & Access Management (IAM) architecture and management.
- Cloud security and infrastructure security.
- Risk management, maturity modeling, and KPI tracking.
- Stakeholder management, cross‑functional collaboration, and senior management communication.
- Leadership, motivation, and influence of security culture.
- Fluent in English; Dutch or French required (additional proficiency an asset).
**Required Education & Certifications**
- Master’s degree in Information Security, Computer Science, or related field.
- Professional certifications: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer (preferred).