As the Risk Expert at YPTO, you will be responsible for overseeing the organization's risk management process, providing guidance to the Risk team, and ensuring continuous improvement. Additionally, you will act as an authority in developing, implementing, and maintaining the risk management framework in alignment with academic theories, industry standards, and legal requirements. Your role will also involve promoting cybersecurity awareness and best practices within the organization.
Develop the Risk Management Process :
- Develop a repeatable and quantitative risk management process based on academic theories, industry standards, and models.
- Identify improvements to enhance the efficiency and consistency of the Risk Management Process through tooling.
- Ensure prioritization and quality assurance of tasks within the Risk team.
- Provide coaching and guidance to the Risk team as needed.
- Assist in the selection of new team members with the requisite qualifications and skills.
Improve and Maintain the Risk Management Process :
- Enhance and maintain the Risk team's capabilities and services.
- Align the Risk Management Process with other YPTO Risk Management Programs.
- Manage all aspects of the lifecycle management of capabilities and services, including designing, implementing KPIs/KRIs, documenting procedures, identifying and addressing operational and quality risks, and monitoring external suppliers.
- Report to internal stakeholders on KPIs, planning, capacity, and quality.
Knowledge Transfer :
- Collaborate with other leads of the GRC Team to enable synergies.
- Assist colleagues within the CISO office and Ypto in understanding information security and risk management.
- Mentor junior Risk security officers to facilitate their professional development.
Requirements
- 10 years of relevant experience in information security management.
- Certifications such as CISSP, CISA, CISM, ISO27001 lead implementer or auditor, CRISC are considered advantageous.
- Master's degree or higher, preferably with a background in statistics and econometrics.
- Proficiency in Dutch or/and French (C2) and English (C1).
- Expert knowledge of cybersecurity and privacy standards, frameworks, policies, regulations, and best practices.
- Proven track record of implementing Risk management programs for large organizations.
- Experience with Risk tooling (e.g., B-wise, ServiceNow GRC, OneTrust) is a plus.
- Strong network and active participation within the Risk Community is preferred.
Our offer
Within our open corporate culture, you contribute to the digital transformation of SNCB. You will have a job with social impact and ample opportunity to make your own contribution. In addition to a good work-life balance and a competitive salary, you will receive the following benefits:
- the possibility to work remotely + flexible working hours;
- 35 days of leave;
- a company car + a public transport season ticket;
- a target bonus;
- a comprehensive insurance package (affiliation without own contribution, excl. outpatient costs for family members);
- hospitalisation and dental care for the whole family;
- outpatient costs (= medical costs separate from hospitalisation);
- group insurance: supplementary pension, work disability and death (cafeteria plan);
- accidents at work (extralegal);
- meal vouchers and eco-vouchers;
- net allowances for remote working and carwash + internet budget.
Apply for this job