Bekijk vacature overzicht
Solliciteer naar GRC Officer
GRC Officer (Governance, Risk & Compliance)
Location
Belgium (Hybrid) ; 4d a week on site
Start Date
ASAP
Contract
Full-time
About the Role
We are looking for a hands-on GRC Officer to strengthen a growing Governance, Risk & Compliance team. In this role, you will support the implementation and continuous improvement of information security governance, risk management, and compliance activities within a dynamic digital environment.
You will work closely with the Digital Risk & Compliance Lead and contribute to establishing a solid GRC framework by developing policies, processes, and controls that support secure and compliant business operations.
Key Responsibilities
- Develop, document, and maintain governance, risk, and compliance processes, policies, and guidelines.
- Support IT risk assessments for systems, suppliers, and digital initiatives.
- Maintain the risk register and follow up on mitigation actions.
- Contribute to compliance with relevant regulations and security frameworks.
- Support internal and external audits by preparing evidence and following up on remediation actions.
- Perform third-party/vendor risk assessments and maintain supplier risk documentation.
- Monitor the effectiveness of security controls and prepare management reports.
- Promote security awareness and provide day-to-day guidance on governance and compliance topics.
- Collaborate with internal stakeholders to continuously improve information security and risk management processes.
Required Skills & Experience
- 1–2 years of experience in Governance, Risk & Compliance (GRC), information security, third-party risk management, or a related field.
- Experience with information security standards and regulatory frameworks such as ISO 27001, NIST, CIS Controls, GDPR, NIS2, or similar.
- Exposure to risk assessments, audit preparation, or vendor security assessments.
- Strong analytical and organizational skills with attention to detail.
- Excellent communication skills and the ability to explain security concepts to non-technical stakeholders.
- Eagerness to further develop within the GRC and information security domain.
Technical Knowledge
- Experience with or exposure to GRC or Information Security Management (ISMS) platforms.
- Good understanding of cloud environments and SaaS governance.
- Basic knowledge of Identity & Access Management (IAM), including concepts such as RBAC, MFA, and directory services.
- Understanding of data classification and privacy principles.
- Familiarity with vulnerability management, patch management, and endpoint security concepts.
Nice to Have
- Relevant certifications such as ISO 27001 Foundation, ISO 27001 Lead Implementer, CompTIA Security+, or similar.
- Experience working in regulated environments.
- Knowledge of modern security and compliance practices.
Languages
- Fluent in French and English.
- Knowledge of Dutch is considered an asset.
What We Offer
- A challenging assignment with ownership of operational GRC activities.
- The opportunity to work closely with experienced security and compliance professionals.
- A collaborative environment with room for learning and professional growth.
- Hybrid working model with a good balance between on-site and remote work.