> Markdown version of [/jobs/ext/297945-cybersecurity-grc-manager](https://www.wearedevelopers.com/jobs/ext/297945-cybersecurity-grc-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Manager - **Company:** ITS Group - **Location:** Charleroi, Belgium - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Smartsuite, Working Model 2D, Information Security Management System, Information Technology, CIS Benchmarks, Servicenow - **Published:** June 18, 2026 - **Apply:** https://be.indeed.com/viewjob?jk=1d73e4b5626dea6d ## About the Role Do you have experience in ServiceNow?, 3 to 5+ years of experience in GRC, information security compliance or IT risk management. Strong knowledge of ISO 27001:2022, including ISMS lifecycle, Annex A controls and audit requirements. Experience with NIS2 compliance or regulatory security frameworks. Experience in risk analysis methodologies such as ISO 27005, EBIOS RM or equivalent. Ability to draft high-quality documentation in French: policies, procedures, risk treatment plans, audit reports. Understanding of GDPR and its connection with information security governance. Experience preparing or supporting ISO 27001 certification is highly valued. Experience with GRC tools such as CISO Assistant, OneTrust, ServiceNow GRC or Archer is a plus. Good understanding of IT infrastructure and cybersecurity concepts. Strong communication skills with technical teams, management and business stakeholders. Ability to work autonomously and drive concrete deliverables. Nice-to-have: ISO 27001 Lead Implementer or Lead Auditor certification. Experience in MSP, consulting or multi-client environments. Experience in regulated sectors such as public sector, energy, water, healthcare, finance or critical infrastructure. Knowledge of CIS Controls, IEC 62443, ANSSI guidelines or OT/IT environments. Technical English. Practical information: Mission duration: approximately 200 days. Hybrid working model. Regular on-site presence required in Wallonia. Votre profil You have at least 3 years of professional experiences in IT If you are at least fluent in FR , EN is a + You're eager to learn, motivated and curious ## Description We are looking for an experienced Cybersecurity GRC Manager to support our client in strengthening its information security governance, risk management and compliance approach. The consultant will join the cybersecurity team and work closely with the CISO, internal teams, external partners and business stakeholders. The mission focuses on ISO 27001:2022, NIS2 compliance, risk management, audit preparation and the continuous improvement of the Information Security Management System. This role is ideal for a pragmatic GRC professional who combines strong documentation skills, security governance expertise and the ability to work in a multi-stakeholder environment. The Cybersecurity GRC Manager will contribute to the operational implementation of governance, risk and compliance activities. Main responsibilities include: Drafting and maintaining ISMS documentation, including security policies, operational procedures and risk treatment plans. Supporting ISO 27001 certification activities, from gap analysis to audit preparation. Preparing internal and external audits and following up on non-conformities. Supporting NIS2 compliance initiatives for essential and important entities. Maintaining risk registers, control follow-up and action plans. Using and administering a GRC tool such as CISO Assistant, OneTrust, ServiceNow GRC, Archer or equivalent. Facilitating workshops with IT, business and security stakeholders. Translating regulatory and security requirements into practical, actionable controls. Producing clear reports and dashboards for management and governance bodies. Supporting the CISO in structuring security governance across multiple stakeholders. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [Best Companies to Work For in Paris: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/190-best-companies-to-work-for-in-paris-top-25-companies-in-2023) - [Best Companies to Work For in France: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/189-best-companies-to-work-for-in-france-top-25-companies-in-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)