18 hours, 29 minutes ago

Medior GRC Cyber Security Expert

Expert Cyber Security GRC Medior

Context

SPW Digital supports the digital transformation of Walloon public services while ensuring a high level of information security.

To strengthen its operational capacity in the fields of governance, risk management, and compliance, the Security Department wishes to enlist the services of a medior GRC expert.

The expert will join a multidisciplinary team dedicated to cybersecurity and will mainly contribute to the execution of risk management activities as well as to the updating of the security documentation framework.

They will carry out their duties under the supervision of senior experts from the department and will apply the methods, procedures, and guidelines defined by the SPW.

Main Missions

The medior GRC expert contributes to the operational implementation of Governance, Risk, and Compliance (GRC) activities of SPW Digital.

The expert will work under the supervision of managers and senior experts in the department.

Their activities are mainly focused on:

  • carrying out cyber risk management activities;
  • reviewing and updating security policies, standards, and procedures;
  • executing various operational activities related to governance, compliance, and the information security management system.

The expert holds an essentially operational role. They contribute to the production of deliverables, the execution of processes, and the follow-up of GRC activities defined by the managers and senior experts of the department.

Activities

  • Conducting cyber risk analyses and monitoring treatment plans.
  • Maintaining risk registers and producing associated reports.
  • Reviewing and drafting security policies, standards, and procedures under the supervision of senior experts.
  • Contributing to compliance activities (NIS2, CyFun, ISO 27001) and audits.
  • Feeding GRC tools, the ISMS, and governance dashboards.
  • Supporting Governance, Risk, and Compliance activities of the Security Department.

Depending on the priorities of the service, the expert may also be required to work on other topics within the security program.

Important

The expert applies the risk management methodology, models, and criteria defined by the SPW. They do not define the methods, acceptance thresholds, or risk management guidelines themselves.

Profile Sought

Education & Experience

  • Higher education degree (Bachelor’s or Master’s) in IT, cybersecurity, risk management, or a related field.
  • Minimum of 3 years of experience in a role related to cybersecurity, risk management, or compliance.
  • Practical experience in conducting risk analyses.
  • Experience in drafting or updating governance or compliance documents.

Technical Skills

  • Good knowledge of cybersecurity risk management principles.
  • Good knowledge of ISO 27005 and ISO 27001 frameworks.
  • Knowledge of NIS2 requirements.
  • Knowledge of CyFun is an asset.
  • Good understanding of IT environments: infrastructures, networks, systems, Active Directory, cloud, applications.
  • Ability to use tracking, reporting, and GRC platforms/tools.

Personal Qualities

  • Excellent writing skills.
  • Ability to structure and synthesize complex information.
  • Rigor in documentation.
  • Organizational skills and sense of priorities.
  • Good listening and communication skills.
  • Ability to work with technical and business stakeholders.
  • Team spirit.
  • Autonomy in carrying out assigned tasks.

What we are primarily looking for

We are looking for a GRC expert capable of producing risk analyses, drafting quality security documents, and ensuring rigorous follow-up of GRC activities.

The expert will join an existing team and will work under the supervision of senior experts. Their added value lies above all in their ability to efficiently execute defined processes, produce quality deliverables, and concretely advance the governance, risk management, and compliance activities of the SPW.

SOFT SKILLS

  • Rigor in task execution
  • Organizational skills
  • Analytical mindset
  • Good written and oral communication
  • Team spirit

EVALUATION METHOD

The remaining candidates will be invited for an interview before a panel, the composition of which will be communicated later.

The interview may take place remotely if circumstances require.

On-site selection interview

The on-site selection interview will take place within 1 to 2 weeks following the offer submission date, at time slots set by SPW. Unavailability of the candidate to participate in the interview will result in their exclusion.

The interview aims to assess:

  1. Fit with the mission
  2. Skills
  3. Communication and personal qualities
  4. Motivation and cultural fit

Mission for a maximum duration of 3 years.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration