Our client is looking for a Cybersecurity GRC Manager
Description
Context
Our client is the reference partner for stakeholders in the water sector in Wallonia for their digital transformation projects, supporting in particular the SWDE, the SPGE and several Approved Sanitation Organizations (OAA).
Recognized as an essential entity under the NIS2 Directive, our client is involved in the design, coordination and implementation of structuring IT projects, while also supporting its partners upstream in defining their governance strategy and information security risk management.
In this context, the Cybersecurity department wishes to engage the services of an experienced GRC Manager, responsible for structuring and managing governance, risk management and compliance initiatives (NIS2, ISO 27001) for the organization and its partners in the water sector (sanitation and drinking water).
The consultant will join the internal cybersecurity team and work closely with the CISO, teams and subcontractors.
Mission
As part of the compliance program of the organization and its partner clients regarding NIS2 regulatory requirements and the ISO 27001:2022 standard, the Cybersecurity GRC Manager will strengthen the security team led by the CISO.
He/She will be responsible for operational Governance, Risk and Compliance (GRC) activities, providing direct support to the CISO and interfacing with clients within the MSP portfolio:
- Lead and draft the Information Security Management System (ISMS) documentation: policies, procedures, risk treatment plans.
- Support clients in their ISO 27001 certification journey, from gap analysis through certification audit.
- Prepare internal and external audits, monitor non-conformities, and ensure continuous ISMS updates.
- Contribute to the implementation of NIS2 compliance for essential and important entities within the scope.
- Use and administer the CISO Assistant GRC tool (or equivalent) for monitoring controls, risks and action plans.
Skills
Soft Skills
- Document rigor: Ability to produce precise, consistent and maintainable documentation over time — policies, procedures and risk treatment plans written without ambiguity.
- Oral and written communication: Ability to communicate clearly with a variety of stakeholders (management, executive committees, technical teams, client business managers) and produce summaries and presentations for leadership bodies. Ability to adapt the level of communication to the audience — simplifying without oversimplifying.
- Active listening and interpersonal intelligence: Ability to understand real constraints faced by clients and subcontractors, reformulate their needs, and build a climate of trust conducive to co-creating security procedures and processes.
- Negotiation and influence without hierarchical authority: Ability to advance compliance topics with stakeholders outside the direct authority of the organization — partner clients, third-party providers, external IT teams. Ability to defend security requirements while remaining constructive and solution-oriented.
- Pedagogical mindset: Ability to make ISO 27001 and NIS2 requirements understandable to non-specialist operational teams, facilitate collaborative workshops (risk workshops, document reviews, awareness sessions), and engage stakeholders in the compliance journey.
- Resistance management and change management: Ability to manage organizational resistance to compliance requirements, identify the right internal champions within client organizations, and transform perceived regulatory constraints into operational improvement opportunities.
- Autonomy and proactivity: Ability to independently drive GRC workstreams while reporting regularly to the CISO and escalating blockers at the appropriate time.
- Results-oriented mindset: Focus on tangible deliverables: policies completed, audits prepared, non-conformities closed.
- Adaptability: Comfortable working in a multi-client MSP environment with strong operational responsibilities, capable of handling multiple organizational contexts and varying levels of security maturity.
Governance Competencies
- Mastery of the PDCA cycle applied to an ISMS (ISO 27001).
- Ability to draft and maintain a Statement of Applicability (SOA) with contextualized justifications.
- Knowledge of NIS2 requirements (essential/important entities, notification obligations, security measures).
- Experience conducting risk assessments (ISO 27005 or equivalent).
- Ability to interact with client CISOs and position the organization as an extended operational security team.
- Awareness of GDPR obligations and their interaction with ISO 27001 / NIS2 requirements.
Technical Competencies (Functional / Supervisory Level)
- ISO 27001:2022: mastery of the 93 controls in Annex A, clauses 4 to 10, and audit requirements.
- Documentation drafting: security policies, operational procedures, risk treatment plans, audit reports.
- Project management: compliance milestone planning, action plan follow-up, executive reporting.
- GRC tools: CISO Assistant, or any equivalent GRC platform (OneTrust, ServiceNow GRC, Archer…).
- IT and infrastructure security culture: solid understanding of fundamental information systems and network security concepts, required to assess the relevance of controls and effectively interact with technical teams.
- Knowledge of MSP environments and critical IT architectures (OT/IT, water sector or equivalent appreciated).
- Use of complementary frameworks: CIS Controls, IEC 62443, ANSSI sector-specific guidelines.
Experience
- Minimum 3 to 5 years of experience in a GRC, Information Systems Compliance or Information Security role.
- Proven experience leading or supporting ISO 27001 certification initiatives (participation in at least one complete cycle: preparation, mock audit, certification audit). An ISO 27001 Lead Implementer certification is considered a plus.
- Experience in an MSP, consulting firm or multi-client environment is appreciated.
- Exposure to regulated sectors (critical infrastructure, water, energy, healthcare, finance) is considered an asset.
- Strong written French skills (intensive documentation production); technical English is a plus.