Cyber Risk & Control Architect (CISO)

bpost
Brussel, Belgium
15 days ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Languages
Dutch, English, French
Job source

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Cyber Threat Analysis Cybercrime

Job description

Bnode is strengthening its Group CISO Office and is looking for a senior Cyber Risk & Control Architect to help shape how cybersecurity risk is governed across our international organisation.

In this role, you will design and continuously evolve the Group Cyber Risk & Control Framework, providing a common approach to cyber risk, controls, compliance and reporting across more than 20 entities.

Working closely with the Group CISO and Cyber Program Management Lead, you will translate evolving cyber threats, regulatory requirements, audit findings and business priorities into clear risks, controls and actions. You will combine strategic thinking with practical implementation, helping senior leaders make informed, risk-based decisions and strengthening cyber governance across Bnode.

Shape our Group Cyber Risk & Control Framework

  • Own and continuously improve the Group Cyber Risk & Control Framework.
  • Define cyber risk scenarios, control objectives, KRIs and maturity criteria.
  • Translate emerging threats, regulatory requirements, audit findings and maturity assessments into clear cyber priorities.
  • Support risk appetite discussions and risk-based decision-making at Executive Committee and Board level.

Strengthen governance, compliance and reporting

  • Define and maintain the methodology supporting the Group Cyber Plan.
  • Create clear traceability between cyber risks, controls, regulatory requirements, remediation plans and strategic initiatives.
  • Develop integrated reporting covering cyber risk, programme delivery, control effectiveness and NIS2 compliance.
  • Support reporting to senior management, the Board and the Audit & Risk Committee.

Develop our cyber data, processes and tooling

  • Design scalable processes to collect, validate and consolidate cyber data across more than 20 entities.
  • Establish reporting cycles, responsibilities and data-quality standards.
  • Develop the data model connecting risks, controls, compliance obligations, action plans and reporting.
  • Lead the selection and evolution of GRC and related cyber governance tooling.
  • Drive greater automation and standardisation across cyber risk, compliance and reporting.

Drive continuous improvement

  • Ensure the framework evolves with the threat landscape, regulation, audit findings and changing business priorities.
  • Promote greater consistency and maturity across the Group while recognising the needs of different entities.
  • Identify opportunities to improve control effectiveness, risk visibility and the quality of cyber reporting.

Requirements

You are an experienced cybersecurity professional who can combine strong GRC expertise with the ability to influence at senior level.

You bring:

  • Around 10+ years of experience in cybersecurity governance, cyber risk, compliance, audit or cybersecurity consulting.
  • Strong expertise in cyber risk management, control frameworks and regulatory compliance.
  • Experience working within large, complex and preferably international organisations.
  • Proven experience designing governance frameworks, operating models and reporting processes.
  • Experience implementing or managing GRC, risk-management or compliance tooling.
  • Strong knowledge of frameworks and regulations such as CyFun, NIS2, ISO 27001, NIST CSF and DORA.
  • Strong analytical and conceptual skills, with the ability to turn complex cyber risks into clear priorities and actions.
  • The confidence and communication skills to engage, influence and challenge stakeholders from operational teams through to Board level.
  • Fluency in English. Dutch and/or French is an asset.

Benefits & conditions

Like a long-awaited parcel, we want to make you feel welcome and valued. Our offer includes a competitive monthly salary, that goes without saying. On top of that, you can count on:

  • Meal vouchers of €8 per working day
  • Hospitalization-, group- and disability insurances
  • A phone subscription, including 25GB data
  • A flexible renumeration plan, which allows you to customize your own benefits. A company car, bike leasing, public transportation, extra days off,… the choice is yours
  • Possibility to enter the Federal Mobility plan
  • Work/life balance, thanks to flexible working hours and the possibility to work from home
  • 20 days of statutory leave and 7 additional extralegal days off
  • An end-of-year and performance-based bonus and double holiday pay
  • Many benefits from more than 100 Bpost-partners

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

3:29 min

Forecasting organizational cybersecurity risks through public employee reviews

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:06 min

Implementing runtime threat event frameworks for attack telemetry

Tom Tovar · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all