A federal public service is reviewing its cybersecurity awareness approach within an information security management system aligned with ISO 27001. Reporting to the CISO, this senior specialist assesses current maturity and shapes a practical security awareness programme centred on behaviour change, phishing simulations, training and clear communication.
The mission
This short assignment provides an objective review of the existing security awareness strategy, programmes and resources. You will benchmark maturity against ISO 27001 Annex A, NIST and ENISA, identify gaps, and turn the findings into a realistic improvement plan.
You will work with HR, internal communications, ICT and business stakeholders through interviews and workshops. Your outputs will include an assessment report, a renewed strategy, programme recommendations, an action plan and an executive summary for the CISO and management. The assignment lasts approximately two months, while final follow-up, deployment and decision-making remain with the CISO.
Your responsibilities
- Assess the existing cybersecurity awareness strategy, programmes and delivery resources.
- Benchmark awareness maturity against ISO 27001 Annex A, NIST and ENISA guidance.
- Conduct interviews and workshops with HR, internal communications, ICT and business stakeholders.
- Identify target audiences, risky behaviours and their security awareness needs.
- Develop a renewed strategy and practical improvement plan.
- Recommend campaigns, phishing simulations, training and communication activities.
- Present findings to the CISO and management, then transfer knowledge to CISO colleagues.
Your profile
Essential skills
- Senior expertise in security awareness, behaviour change and communication strategies.
- Experience evaluating and redeveloping cybersecurity awareness strategies and programmes.
- Ability to benchmark practices against ISO 27001 Annex A, NIST SP 800-50/53 and ENISA guidance.
- Experience designing awareness campaigns, phishing simulations, training and communication content.
- Knowledge of phishing simulation and training platforms.
- Understanding of NIS 2 and GDPR awareness obligations.
- Clear, convincing communication with management, the CISO and end users.
- Autonomous delivery at SFIA level 5, Ensure, advise, during a short assignment.
Preferred skills
- CISM, SANS MGT433/SSAP or CIPM certification.
Languages
- Dutch, B2.
- French, B2.
- English, B2.
Education
- Master’s degree, or equivalent confirmed relevant experience.
Working context
- Reports to the CISO, with final follow-up and deployment decisions retained there.
- Works under broad direction and provides authoritative advice at SFIA level 5, Ensure, advise.
- Collaborates with HR, internal communications, ICT and business stakeholders.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

