18 hours, 31 minutes ago

Business project manager – ICT – Security & Compliance (NIS2)

CONTEXT:

The European NIS2 Directive (Network and Information Security Directive 2) aims to substantially increase the cyber resilience of vital and essential organizations within the EU. The directive obliges member states and organizations to take adequate technical and organizational measures to guarantee the continuity and security of essential services and digital infrastructures. Government organizations are considered “essential entities” and are subject to the obligations of this directive. This means they must be able to demonstrate that their processes, policies, technology, and governance align with the NIS2 obligations, including:

  • Policy and governance: clear responsibilities, oversight, and reporting on cyber resilience;
  • Risk management: a structured approach to risks in information and network security;
  • Security measures: technical and organizational controls according to the state of the art;
  • Incident management and notification requirement: detection, reporting, and follow-up of security incidents;
  • Supplier management: measures regarding supply chain and vendor risks;
  • Continuity and recovery: resilience against disruptions, including business continuity and disaster recovery.

To achieve this, a program has been launched within the FPS Social Security with the aim of structurally organizing the organization according to the requirements of NIS2 and thereby sustainably strengthening digital resilience. This requires not only technical measures but also organizational embedding, governance, risk awareness, change, etc.

The program consists of multiple phases and several projects, established based on the CyFun framework [1] from the CCB.

In the realization phase, the identified measures are effectively implemented, grouped into projects per CyFun function. For two priority projects, we are seeking additional support:

NIS2 – Asset Management – CyFun Function: IDENTIFY [ID.AM]

Identification and management of systems, people, assets, data, and processes as a basis for risk-based cybersecurity decisions.

NIS2 – Data & Platform Security – CyFun Function: PROTECT [PR.DS / PR.PS]

Technical safeguarding of the confidentiality, integrity, and availability of citizen data and social security systems via data security and platform security.

[1] https://cyfun.eu/en

DESCRIPTION OF THE ASSIGNMENT

The Business project manager supports the business lead and NIS2 expert in the organizational and substantive coordination of the two aforementioned projects. The focus is on the organizational dimension of implementation: impact on the business, governance, follow-up, reporting, and the description of processes, policies, and procedures.

The assignment includes the following main tasks:

1.1 Organizational support & business impact

  • Supporting the business lead NIS2 in translating technical requirements into organizational measures.
  • Analyzing and describing the impact of the two projects on the involved business domains, processes, and stakeholders.
  • Facilitating workshops and work sessions with internal stakeholders (ICT, business, data owners, CISO function).
  • Contributing to change management and communication towards the relevant departments.

1.2 Project coordination & follow-up

  • Monitoring the project planning, milestones, and deliverables for Asset Management and Data & Platform Security.
  • Drafting and maintaining project sheets, status reports, and progress overviews.
  • Organizing and following up on steering committees, workgroups, and review moments.
  • Signaling risks, dependencies, and bottlenecks and escalating where necessary.
  • Maintaining a structured project file (decisions, actions, documentation).

1.3 Description of processes, policies & procedures

  • Mapping and describing the current and desired processes regarding asset management and data & platform management.
  • Collaborating on drafting and validating policies and procedures in accordance with NIS2 / CyFun requirements.
  • Contributing to the preparation of work instructions, process descriptions, and governance documentation.
  • Ensuring alignment between technical measures and organizational procedures.

1.4 Reporting & communication

  • Preparing clear management reports and progress updates for the program manager and management.
  • Ensuring a consistent and correct flow of documentation within the program.
  • Contributing to the preparation of steering committee materials and audit requirements (CCB, NIS2 supervision).

COLLABORATION & POSITIONING

The NIS2 Implementation Analyst / Project Coordinator works in close consultation with:

  • NIS2 Program Manager: Reporting, prioritization, and program alignment
  • Business lead / NIS2 expert: Direct support; substantive direction of the projects
  • ICT Security Team: Technical input, validation of measures
  • Business data owners & process owners: Determining scope, impact, and requirements
  • External security supplier (Proximus / Smals): Coordination of SecaaS 2 / IAP+ implementations

Required knowledge & experience (mandatory)

  • Bachelor’s or Master’s in computer science, business administration, public administration, or equivalent through relevant experience.
  • At least 4 years of demonstrable experience in project coordination or management within an IT or security context.
  • At least 3 years of experience with describing processes, drafting policies, and procedures in a regulated environment.
  • Knowledge of the CyFun framework (CCB) and/or related frameworks (ISO 27001, NIST CSF, CIS Controls).
  • At least 3 years of experience with stakeholder management and facilitating multidisciplinary workgroups.

Assets

  • Experience within a federal government service or comparable public organization.
  • Experience with NIS2 implementation projects or prior involvement in cybersecurity programs.
  • Certifications such as PMP, Prince2, CISM, or ISO 27001 Foundation/Lead Implementer.
  • Familiarity with asset management tools or CMDB concepts (for the IDENTIFY project).
  • Knowledge of platform security principles or data categorization (for the PROTECT project).

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration