Bekijk alle vacatures

GRC Officer

  • Brussel, Brussel

GRC Officer (Governance, Risk & Compliance)

Location

Belgium (Hybrid) ; 4d a week on site

Start Date

ASAP

Contract

Full-time

About the Role

We are looking for a hands-on GRC Officer to strengthen a growing Governance, Risk & Compliance team. In this role, you will support the implementation and continuous improvement of information security governance, risk management, and compliance activities within a dynamic digital environment.

You will work closely with the Digital Risk & Compliance Lead and contribute to establishing a solid GRC framework by developing policies, processes, and controls that support secure and compliant business operations.

Key Responsibilities

  • Develop, document, and maintain governance, risk, and compliance processes, policies, and guidelines.
  • Support IT risk assessments for systems, suppliers, and digital initiatives.
  • Maintain the risk register and follow up on mitigation actions.
  • Contribute to compliance with relevant regulations and security frameworks.
  • Support internal and external audits by preparing evidence and following up on remediation actions.
  • Perform third-party/vendor risk assessments and maintain supplier risk documentation.
  • Monitor the effectiveness of security controls and prepare management reports.
  • Promote security awareness and provide day-to-day guidance on governance and compliance topics.
  • Collaborate with internal stakeholders to continuously improve information security and risk management processes.

Required Skills & Experience

  • 1–2 years of experience in Governance, Risk & Compliance (GRC), information security, third-party risk management, or a related field.
  • Experience with information security standards and regulatory frameworks such as ISO 27001, NIST, CIS Controls, GDPR, NIS2, or similar.
  • Exposure to risk assessments, audit preparation, or vendor security assessments.
  • Strong analytical and organizational skills with attention to detail.
  • Excellent communication skills and the ability to explain security concepts to non-technical stakeholders.
  • Eagerness to further develop within the GRC and information security domain.

Technical Knowledge

  • Experience with or exposure to GRC or Information Security Management (ISMS) platforms.
  • Good understanding of cloud environments and SaaS governance.
  • Basic knowledge of Identity & Access Management (IAM), including concepts such as RBAC, MFA, and directory services.
  • Understanding of data classification and privacy principles.
  • Familiarity with vulnerability management, patch management, and endpoint security concepts.

Nice to Have

  • Relevant certifications such as ISO 27001 Foundation, ISO 27001 Lead Implementer, CompTIA Security+, or similar.
  • Experience working in regulated environments.
  • Knowledge of modern security and compliance practices.

Languages

  • Fluent in French and English.
  • Knowledge of Dutch is considered an asset.

What We Offer

  • A challenging assignment with ownership of operational GRC activities.
  • The opportunity to work closely with experienced security and compliance professionals.
  • A collaborative environment with room for learning and professional growth.
  • Hybrid working model with a good balance between on-site and remote work.