> Markdown version of [/jobs/ext/2337598-senior-grc-consultant](https://www.wearedevelopers.com/jobs/ext/2337598-senior-grc-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior GRC Consultant - **Company:** Approach Cyber - **Location:** Belgium - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management System - **Published:** August 23, 2026 - **Apply:** https://www.adzuna.be/details/5832945431 ## About the Role You are a seasoned GRC professional who thrives in complex environments and knows how to translate security challenges into business language. You are as comfortable facilitating a board-level risk conversation as you are rolling up your sleeves to implement an ISMS or guide a client through a NIS2 compliance journ ey.But beyond this expertise, what makes you stand out is your energy. You bring ideas, you challenge the status quo, and you are deeply invested in your clients' success. You want to be part of a team that is growing fast, and you want to grow with, You have a minimum of 3 years of relevant experience in GRC, information security consulting, or a similar adv * isory role.You hold (or are actively working towards) certifications in areas such as ISO 27001, NIS2/DORA/CRA compliance, Risk Management, or CISO-as-a-Service. What matters most is that you can demonstrate real, hands-on experience in t * hese areas.You think strategically: you understand senior management concerns, know how to evaluate business risks, and can translate complex security topics into clear, actionable recom * mendations.You communicate with confidence and clarity, adapting your language to your audience, whether a technical team or a C-lev * el sponsor.Language: you are fluent in Dutch (native) or French (native), with a strong command of English. The other national language is a real asset. Trilingual profiles (FR/NL/EN) are especial ## Description Dutch-speaking people: Flanders is a strategic priority for Approach Cyber. We have significant ambitions for this region and a growing pipeline of opportunities. As part of your role, you will actively contribute to developing the Flemish market: building relationships, representing Approach at events and industry forums, identifying new opportunities, and acting as a credible face of Approach Cyber with prospects and clients in the region. This is a core part of what we are looking * for.French-speaking people: Your primary focus will be client delivery. That said, your expertise and your network are valuable commercial assets. We will expect you to adopt a consultative selling approach (spotting opportunities during missions, engaging naturally with prospects, and contributing to Approach's visibility in your professional circl es). °°° Your responsibilitie s °°° As a Senior GRC Consultant, your day-to-day will revolve around three areas: Client advisory & d * eliveryPerform cybersecurity maturity assessments using our ACAM® (Approach Cybersecurity Assessment Methodology) and other recognised fram * eworks.Design and implement Information Security Management Systems (ISMS) based on ISO 27001, and support clients throughout certification pro * cesses.Guide clients through NIS2, DORA, and CRA compliance journeys (from gap analysis to operational implement * ation).Develop security roadmaps, define priorities, and translate them into actionable plans that make sense for your client's business c * ontext.Lead and coordinate security projects, driving change management and ensuring strategic decisions are turned into concrete r * esults.Deliver CISO-as-a-Service engagements: provide strategic and technical guidance, support governance structures, and help clients manage security incidents when they * arise.Build long-lasting relationships with your clients, as their go-to advisor, not just their cons ultant. Market dev * elopmentActively represent Approach Cyber in the market: attend events, participate in panels, and build a visible presence in the cybersecurity co * mmunity.Identify and develop new business opportunities, leveraging your network and your expertise as your most credible commercia * l asset.Engage with prospects in a consultative and authe * ntic wayReport field insights and market intelligence to help shape our go-to-market approach in the region. Internal contribution & te * am growthContribute to the continuous improvement of our methodologies, frameworks, and reusabl * e assets.Share knowledge with the team: market trends, regulatory evolutions, new frameworks, lessons learnt from t * he field.Support and mentor junior colleagues, helping them grow and succeed on complex eng, * uman skills Commitment and drive: you are invested in your work and in Approach Cyber's project. You go the extra mile, not because you have to, but because you care about * the outcome.Trusted Advisor mindset: you genuinely care about your clients' success. You are curious about their business, proactive in your recommendations, and honest in yo * ur guidance.Team player: you thrive in a collaborative environment and actively contribute to the team's collective success, sharing knowledge and supporting * colleagues.Integrity without compromise: you handle sensitive client and company information with full discret * ion, always.Ambassador for the professional values that are at the heart of our * philosophy:TOP-NOTCH: We strive for best-of-the-best while staying ahead o * f the curve.HUMAN-CENTRIC: We care about people in the di * gital world.NO-NONSENSE: We go for it, we work together ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Communicate efficiently with Software Architecture Diagrams](https://www.wearedevelopers.com/videos/379-communicate-efficiently-with-software-architecture-diagrams) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)