Information Security Compliance & Governance Coordinator (NIS2 / ISO 27001) (m/w/d)
everience · Brussels, Brussels, be ·
- Seniority
- Senior
- Employment
- Full time
- Category
- Security
- Experience
- 1+ years
We are an essential entity under the NIS2 Directive (as transposed in Belgium) and are building our compliance posture via the ISO/IEC 27001 framework. We are looking for a structured and assertive coordinator to join the Information Security team and keep our NIS2 / ISO 27001 compliance program on track.
You will be the operational backbone of the program: tracking policy implementation, collecting and managing evidence, maintaining reporting dashboards, and running the practical side of project governance.
Key responsibilities
- Compliance tracking and reporting
- Build and maintain Excel dashboards and PowerPoint progress reports on NIS2 / ISO 27001 compliance for the management and steering committees
- Consolidate status information, highlight gaps, delays and risks, and keep the data accurate and up to date
- Owner engagement and evidence management
- Collaborate with the owners responsible for implementing policies and controls across the organization
- Follow up with these owners, assertively and constructively, to obtain status updates and deliverables within agreed deadlines
- Collect, review for completeness, and organise evidence supporting control implementation
- Maintain a structured, audit-ready evidence repository with clear naming, versioning and traceability
- Project governance and coordination
- Organise and coordinate governance meetings (steering committees, working groups, follow-up meetings), including agendas, minutes, action logs and follow-ups
- Handle the administrative and practical aspects of project governance
- Escalate blockers and overdue actions to the CISO in a timely manner
- Audit planning
- Plan and coordinate the agendas for internal and external audits (ISO 27001 certification, surveillance audits, NIS2-related assessments)
- Schedule auditees and interviews, and make sure documentation and evidence are ready beforehand
- Track audit findings and follow up on corrective actions with the relevant owners
- Required
- Bachelor's degree or higher (information management, business administration, IT, law, or a related field)
- Working knowledge of information security governance and a good understanding of ISO/IEC 27001 (certification not required)
- Highly structured, organized and detail-oriented, with a strong sense of follow-up
- Assertive and credible communicator, comfortable chasing stakeholders at all levels
- Advanced Excel skills (formulas, pivot tables, dashboards) and strong PowerPoint skills for clear management reporting
- Strong written and spoken English and French; Dutch is a clear asset in the Belgian context
- First experience (1–3 years) in compliance, GRC, audit support, PMO/PSO or a similar role
- Nice to have
- Familiarity with NIS2 and the Belgian framework (national law, Centre for Cybersecurity Belgium, CyFun)
- Knowledge of other frameworks (ISO 27002, NIST, CIS) or GRC tools
- Foundation-level certification (e.g. ISO 27001 Foundation)
- Soft skills
- Rigor, autonomy and reliability
- Diplomacy combined with the ability to hold people to their commitments
- Good sense of priorities and deadlines
- Discretion when handling sensitive information
All our positions are open to both women and men and are, of course, open to people with disabilities.