Security Process Specialist – ISRC - #46713

Bridge 351


Datum: 2 weken geleden
Stad: Evere, Brussels Hoofdstedelijk Gewest
Contracttype: Voltijd

Role

Security Process Specialist – ISRC (Information Security, Risk and Compliance)

About the Role

The Security Process Specialist will support the ISRC function within the EDP Platform program. The EDP Platform is a service‑oriented, cloud‑native, hybrid environment enabling product teams to develop, run, and operate software products with self‑service capabilities. The consultant will analyze, design, and optimize ISRC processes so they are efficient, pragmatic, scalable, and aligned with the EDP operating model. The focus is on embedding secure design, risk and compliance workflows, and governance interfaces across product lines—enabling teams rather than executing security operations directly.

Responsibilities

  • Assess current IS Risk Management, Compliance Management, Non‑Functional Requirements (NFR) Management, Architecture Review, and Security Operations processes to identify gaps and improvement opportunities
  • Design streamlined, pragmatic, and scalable processes balancing regulatory needs with operational feasibility
  • Define and refine workflows for risk identification, assessment, mitigation tracking, and reporting
  • Shape processes to interpret and implement compliance requirements, including internal standards and external frameworks
  • Establish clear mechanisms to capture, validate, and track security NFRs throughout the product lifecycle
  • Create and integrate structured, repeatable workflows for Security Architecture Design Reviews (SADR)
  • Define interfaces and handoffs with incident response and vulnerability management, including SLAs, RACI, and metrics
  • Consult on Product Release Specification (PRS) sign‑off workflows to embed verifiable security and compliance criteria
  • Ensure secure design principles and patterns are reflected in process definitions and review gates
  • Maintain mechanisms to track adoption and effectiveness of secure architecture patterns across product lines
  • Incorporate lessons learned, incidents, and audit findings into continuous process improvements and governance
  • Provide process‑related guidance for strategic decisions impacting security and compliance
  • Align ISRC processes, tools, and roles with the evolving EDP operating model; contribute via OD Coalitions
  • Integrate ISRC knowledge, processes, and tools into program‑wide enablement and communications
  • Produce clear process descriptions, workflows, RACI definitions, guidelines, and supporting materials for adoption

Mandatory Requirements

Professional Experience

  • Hands‑on exposure to security, risk, and compliance processes in larger organizations
  • Experience analyzing and improving workflows (risk management, compliance, NFRs, architecture reviews)
  • Solid grasp of enterprise security and compliance frameworks and their impact on delivery
  • Experience collaborating with technical teams, architects, and GRC stakeholders
  • Ability to understand and review technical designs without being the implementer
  • Skill in translating compliance/risk requirements into actionable steps or process changes
  • Experience contributing to roles, responsibilities, and decision structures (RACI, governance forums)
  • Experience embedding security/compliance checks into delivery processes
  • Experience supporting workshops or knowledge‑sharing activities
  • Comfortable promoting secure and compliant ways of working

Knowledge & Skills

  • Security process design and optimization (ISRC)
  • Risk management workflows (identification, assessment, treatment, reporting)
  • Compliance management processes (interpretation, control mapping, evidence, audits)
  • NFR security capture, validation, and traceability
  • Security Architecture Design Reviews: workflows, gates, criteria, and patterns
  • Interfaces with Incident Response and Vulnerability Management (handshakes, SLAs, metrics)
  • Governance artifacts: process descriptions, workflows, RACI, PRS criteria, documentation
  • Familiarity with security frameworks and standards: ISO 27001/27005, NIST CSF/800‑53/800‑171, NIS2, CIS Controls, GDPR, Zero Trust, SOC 2, CSA CCM, OWASP ASVS (as applicable)
  • Stakeholder alignment and communication across product, platform, and architecture functions
  • Metrics and continuous improvement (KRIs/KPIs, effectiveness tracking, audit feedback loops)

Languages

  • Fluent English (C1)

Location

  • Brussels

Work Model

  • Hybrid
  • Full-time

Hoe solliciteren

Om te solliciteren voor deze baan moet u inloggen op onze website. Als u nog geen account heeft, registreer dan eerst.

CV plaatsen

Vergelijkbare banen

Project Engineer kwaliteitsopvolging

BAM Interbuild, Evere, Brussels Hoofdstedelijk Gewest
1 week geleden
Word jij onze sleutelspeler in kwaliteitsopvolging op de werf? Kairos, BAM Interbuild en BAM fm vormen samen de Belgische tak onder het Nederlandse moederbedrijf Royal BAM Group. Samen, als één groot team focussen we ons op ontwikkelen, bouwen en onderhouden van toonaangevende gebouwenprojecten. BAM Interbuild is binnen België de gebouwenspecialist bij uitstek voor hoofdzakelijk het Vlaamse en het Brusselse gewest....

Demi Chef

Gresham Belson Hotel, Evere, Brussels Hoofdstedelijk Gewest
1 week geleden
Algemene omschrijving Het Gresham Belson Hotel in Evere staat aan het begin van een veelbelovende nieuwe fase. Na een grondige renovatie heropenen wij binnenkort onze deuren als een Tribute Portfolio hotel by Marriott – een karaktervol lifestylehotel waar kwaliteit, gastvrijheid en beleving centraal staan. Voor deze spannende herlancering zijn wij op zoek naar een gemotiveerde en gepassioneerde Demi Chef om...

Preventieadviseur niveau II & Facility Officer

Louyet Group, Evere, Brussels Hoofdstedelijk Gewest
2 weken geleden
Als Preventieadviseur niveau 2 & Facility Officer @ Louyet Group, horen volgende verantwoordelijkheden tot jouw takenpakket: Je treedt op als preventieadviseur niveau 2 voor een groot deel van onze concessies, waaronder alle Nederlandstalige sites en een aantal Franstalige vestigingen binnen het netwerk. Je voert regelmatige veiligheidsrondgangen en risicoanalyses uit en waakt over de naleving van de geldende welzijns- en veiligheidsvoorschriften....