Our client is looking for a Security Analyst.
The client has the status of an autonomous public institution. This means it was established by law and independently carries out the public interest tasks assigned to it by the legislator. The client, in addition to the National Bank of Belgium (NBB), supervises the Belgian financial sector.
In the context of formalizing its processes related to governance and IT security, the ICT Department is seeking an IT Security Analyst/Technical Writer.
As a public institution, the client must comply with its obligations under the European NIS2 legislation. This legislation has been transposed by the CCB into a framework: CyFun (CyberFundamentals Framework) – Essential.
The client has outsourced a significant portion of its operations to an external provider, offering all the necessary professionalism and certifications. A large portion of the process documentation is therefore with this provider and needs to be integrated and maintained in the client's documentation.
We estimate that this mission will take more than a year and could, if successful, lead to the formalization of new needs.
The objectives of the mission include:
- Analyzing the needs and the current state.
- Understanding our goals regarding governance and IT security formalization.
- Analyzing existing procedures, policies, and controls through available documentation (at the client and with suppliers).
- Formalizing processes and policies.
- Familiarizing with the chosen tool (e.g., CISO Assistant).
- Helping to define the objects to be used as a basis for configuring this tool.
- Assisting in the configuration of the tool, ensuring proper alignment with the needs.
- Identifying deliverables to be written/completed/consolidated to achieve the objectives.
- Identifying and filling in gaps in existing documentation through necessary interviews.
- Ensuring the standardization of this documentation.
- Defining maintenance and update needs for this information and integrating these updates into existing processes.
- Ensuring process consistency.
- Training teams on the tool and processes.
- Testing the validity and consistency of the documentation with the help of the client's Internal Audit.
To achieve these objectives, the consultant will be supported by:
- A competent and responsive team that knows the subject well but is available only a few hours per week.
- Points of contact with our main suppliers, who are ready to assist in this mission.
- The necessary tools (software, etc.), to be decided with the consultant.
- Unconditional support from ICT management and its executives. This project is considered a high priority.
Required Skills:
- University degree or equivalent, with a strong technical focus on IT security and systems engineering.
- Several years of experience in similar assignments.
- Extensive knowledge (as much as possible given the recent publication) of the CyFun (Essential) framework from the CCB.
- Knowledge of ISO27001, ISO27002, ISO27004, and ISO27005 standards.
- Excellent writing skills: ability to write quickly and easily, clarity and precision, adaptability to the target audience, document organization and structuring, proficiency in writing tools, and synthesis skills.
- Efficient in interdisciplinary collaboration.
- Open-mindedness to constructive feedback.
- Ability to self-manage, responsible for organizing information gathering, and willing to work toward objectives.
Languages:
The existing documentation is written in French, English, and Dutch, and interviews must be conducted in French and Dutch. Active knowledge of all three languages will be considered a plus, while passive knowledge of French or Dutch is required.
Working Conditions:
- You will work in a skilled, motivated team with a strong understanding of the subject but is very busy. Collaboration is a core value within the department. The work environment is professional and productive, but also relaxed, with a strong focus on work-life balance for both internal and external staff. The premises are very pleasant and offer all the necessary facilities (meal options, parking, flexible hours, etc.).
- This is ideally a full-time position. Remote work is allowed up to 50% of working hours, but priority will be given to achieving the mission objectives – if certain meetings can only be held on-site, they will take precedence. Mondays and Thursdays are mandatory on-site days to ensure proper team synchronization.
- You will report to the Chief Security Officer, who also holds the position of Chief Operations Officer.