Senior IT Security Program Manager
--Bruxelles--
-
Duration: 5 months
- Remote options: HYBRID
As part of compliance with the NIS2 Directive (Network and Information Security Directive 2), which introduces enhanced cybersecurity requirements for essential and important entities, we are looking for an experienced Senior Cybersecurity Program Manager to lead our NIS2 roadmap.
MAIN MISSION
The Senior Cybersecurity Program Manager will be responsible for the design, implementation, and monitoring of the NIS2 compliance strategy within the organization. He/She will lead the cybersecurity transformation program end-to-end, ensuring alignment with European and national regulatory requirements.
KEY RESPONSIBILITIES
NIS2 Strategy & Planning
- Develop and maintain the NIS2 strategic compliance roadmap
- Conduct gap analysis between the current state and NIS2 requirements
- Define program priorities, milestones, and deliverables
- Establish program budget and required resources
Governance & Program Management
- Manage the NIS2 program end-to-end (Agile / Waterfall)
- Coordinate multidisciplinary teams (IT, Legal, Compliance, Business)
- Ensure regular reporting to Executive Management and competent authorities
- Manage program risks, dependencies, and issues
Compliance & Technical Implementation
- Oversee the implementation of NIS2-required cybersecurity measures
- Develop and review security policies, procedures, and frameworks
- Ensure integration of NIS2 requirements into existing processes (ISO 27001, GDPR)
- Coordinate with technical teams for control deployment
Risk Management & Incident Response
- Establish and maintain the cybersecurity risk register
- Improve incident detection, response, and recovery capabilities
- Define notification procedures towards authorities (CSIRT / CERT)
- Lead crisis simulations and continuity testing exercises
Third-Party & Supply Chain Security
- Assess and manage cybersecurity risks of critical suppliers
- Implement due diligence processes for the supply chain
- Ensure vendor compliance with NIS2 requirements
Communication & Training
- Raise awareness and train stakeholders on NIS2 requirements
- Foster a strong cybersecurity culture across the organization
- Communicate with regulators and supervisory authorities
Required Profile
- 7–10+ years of experience in cybersecurity and program management
- Proven experience implementing regulatory compliance programs (NIS2, GDPR, DORA, etc.)
- Strong knowledge of security frameworks (ISO 27001/27002, NIST, CIS Controls)
- Experience managing complex projects in regulated environments
- Excellent leadership, communication, and stakeholder management skills
- Experience in Belgian or European public sector is a strong asset
- Ability to work autonomously and manage multiple priorities
Work Environment
- Hybrid work model: minimum 3 days/week on-site (Brussels)
- Collaboration with multidisciplinary and international teams
- Direct reporting to the CISO or Executive Management
Skills
- Agile • Waterfall • Cybersecurity Program Management
- Risk Management & Assessment • Incident Response Management • Security Governance & Policy Development
- Executive Stakeholder Management • GDPR & EU Regulatory Compliance • NIS2 Directive Implementation
Languages
- Dutch: Elementary proficiency
- English: Full professional proficiency
- French: Full professional proficiency