A federal public service is strengthening its information security governance through an ISMS and a cybersecurity assessment based on ISO 27001. Reporting to the CISO, this senior IT risk and compliance specialist independently evaluates cybersecurity posture, identifies control gaps and turns findings into a practical improvement roadmap.
The mission
The assignment provides an objective view of cybersecurity posture and ISMS maturity, supporting the CISO's prioritisation and decisions. You assess existing policies, procedures and technical controls, then document findings against ISO 27001 requirements and Annex A controls.
Your work combines risk analysis, stakeholder interviews and facilitated workshops with IT, security and business representatives. You produce an assessment report, gap analysis, risk and priority matrix, actionable recommendations and an executive summary for management, followed by knowledge transfer to the security governance team.
Your responsibilities
- Assess current cybersecurity posture and ISMS maturity against ISO 27001.
- Interview IT, security and business stakeholders through structured workshops.
- Review existing information security policies, procedures and technical controls.
- Identify and prioritise gaps against ISO 27001 Annex A controls.
- Produce a risk and priority matrix with documented findings.
- Develop a justified, practical improvement plan and actionable roadmap.
- Present recommendations clearly and transfer knowledge to the security governance team.
Your profile
Essential skills
- Senior experience analysing and managing risks within an ISMS, using methods such as ISO 27005.
- Experience conducting cybersecurity and ISMS assessments against ISO 27001 and ISO 27002, including Annex A gap analysis.
- Ability to develop evidence-based improvement plans and practical roadmaps.
- Ability to interview varied stakeholders and facilitate workshops across IT, security and business functions.
- Clear, concise reporting for the CISO and management.
- Knowledge of information security, GRC, assessment and audit methodologies.
- Working knowledge of NIS 2 and GDPR.
Preferred skills
- ISO 27001 Lead Auditor or Lead Implementer certification.
- CISSP, CISA or CISM certification.
- Experience benchmarking security posture against sector standards.
Languages
- English: B2.
- Dutch: B2.
- French: B2.
Education
- Master's degree, or equivalent confirmed experience.
Working context
- Reports to the CISO and collaborates with ICT, security and business stakeholders.
- Works at SFIA level 5, with an ensure and advise focus.
- The CISO retains final responsibility for follow-up and decisions.
- Knowledge transfer supports continuity after the assessment.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

