A public-sector organisation is strengthening its information security management system (ISMS) and governance. Reporting to the CISO, the senior IT Risk and Compliance Officer assesses IT, cloud, OT and information assets, then turns findings into a prioritised improvement roadmap aligned with ISO 27001, CyFun and NIST.
The mission
The assignment provides an objective asset management assessment across IT, cloud, OT and information assets. It covers the AS-IS state, coverage rates, maturity, risk exposure and highest-priority improvements. You review existing inventories, asset registers, the CMDB, discovery tools and processes.
Your analysis produces a risk and priority matrix for assets that are unmanaged, poorly known, obsolete or unpatched. It supports a concrete roadmap for discovery, classification, ownership and lifecycle management, alongside an executive summary for the CISO and management. The short scope requires autonomous expert advice from the start, while final follow-up and decisions remain with the CISO.
Your responsibilities
- Map the current management of hardware, software, data, cloud and OT assets.
- Evaluate asset registers, CMDB and discovery tools for completeness and currency.
- Run interviews and workshops with infrastructure, application management and security stakeholders.
- Benchmark asset management against ISO 27001 Annex A 5.9-5.14, CyFun and NIST SP 800-53.
- Analyse and prioritise risks from unmanaged, obsolete or unpatched assets.
- Build a roadmap for asset discovery, classification, ownership and lifecycle management.
- Present findings to the CISO and management, then transfer knowledge to the information security team.
Your profile
Essential skills
- Senior expertise in IT asset management assessments covering inventory, classification, ownership and lifecycle management.
- Experience assessing IT, cloud, OT and information assets.
- Knowledge of asset discovery and classification, including shadow IT detection.
- Experience evaluating asset registers, CMDB and discovery tools, including ServiceNow, Lansweeper, Tanium or equivalent.
- Ability to analyse risks linked to unmanaged, obsolete or unpatched assets.
- Ability to benchmark controls against ISO 27001 Annex A 5.9-5.14, CyFun and NIST SP 800-53.
- Clear, convincing reporting to management and the CISO.
- Ability to provide authoritative advice under broad direction, equivalent to SFIA level 5, Ensure, advise.
- Ability to work autonomously from the start of a short assignment.
Preferred skills
- Certification such as ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, CISM or CDPSE.
Languages
- English, B2, required.
- Dutch, B2.
- French, B2.
- Dutch and French bilingualism is an advantage.
Education
- Master's degree, or equivalent confirmed relevant experience.
Working context
- Reports to the CISO and collaborates with IT infrastructure, application management and security teams.
- Uses interviews and workshops to work with varied audiences, from management to IT administrators.
- Transfers knowledge to the information security team at the end of the assignment.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

