Find a jobRecruiters

GRC Technical Expert (Senior)

Exclusive opportunity

Hybrid

GRC Technical Expert (Senior)

Sparagus

GRC Technical Expert (Senior)

Skills

GRCGCP

5 days ago

Quick apply

Share this opportunity

Share this opportunity to other talents of your network:
✓ Offer them a visibility boost with clients.
✓ Help your contacts find their next job.

Important information


Contract type:

Freelance / Contract

Daily rate:

Salary according to profile

Location:

Brussels, Belgium

Work mode:

Hybrid

Published on:

29 September 2026

What they need


Start Date: ASAP
Workload: Part-time (3 days per week)
Location: Zaventem (Hybrid: Minimum 2 days on-site required)

Mission Context

We are seeking a Senior GRC Technical Expert to secure critical projects by identifying, analyzing, and mitigating IT and cyber risks from the design phase. The mission is to bridge the gap between complex technical architectures and Governance, Risk, and Compliance (GRC) requirements, ensuring all high-impact initiatives are resilient and compliant.

Scope of Work

  • Portfolio: 100% of projects classified as "Critical" or "High Impact."

  • Work Rhythm: Part-time (3 days/week).

  • On-site Presence: Minimum of 2 days per week on-site to facilitate technical deep-dives and face-to-face stakeholder alignment.

  • Impact: Direct influence on reducing the organization's cyber-exposure through proactive remediation tracking.

Key Responsibilities

  • Technical Risk Decomposition: Deconstruct complex project architectures and data flows to identify underlying security vulnerabilities. This involves applying OWASP Risk Rating Methodology for application-level threats alongside ISO 27005 for systemic IT risks.

  • Cross-Functional Collaboration: Partner with Architects and DevOps teams to integrate security controls without stalling delivery velocity.

  • Compliance Oversight: Ensure strict adherence to internal security policies and mandatory regulations, including GDPR and NIS2, throughout the project lifecycle.

  • Architecture Deep-Dives: Analyze software design (APIs, micro-services) to detect flaws such as those listed in the OWASP Top 10, ensuring security is baked into the design.

  • Third-Party Security: Conduct security reviews of external contracts and technical assessments of critical service providers.

  • On-site Stakeholder Engagement: Lead in-person workshops with Architects and Product Owners to translate regulatory requirements into technical controls.

  • Reporting: Translate technical risks into clear, actionable business insights for management and steering committees.

Key Performance Indicators (KPIs)

  • Assessment Coverage: Percentage of critical projects analyzed before the production "Go-Live."

  • Remediation Rate: Percentage of high-risk findings successfully addressed or formally accepted by stakeholders.

  • Risk Prediction Reliability: Zero major security vulnerabilities discovered in production that were not previously identified during the GRC assessment phase.

  • Turnaround Time: Average duration between project intake and the finalization of the security risk report.

Profile wanted


Skills & Requirements

  • Availability & Location: Ability to commit to a 3-day work week, with a mandatory presence on-site in Zaventem for at least 2 of those days.

  • Framework Mastery: Expert knowledge of Cyber frameworks (ISO 27001/27002/27005, NIST) and the NIS2 directive.

  • Technical Risk Expertise: Proven ability to apply OWASP Risk Rating Methodology and perform technical architecture reviews (Cloud/GCP environment).

  • Analytical Mindset: A "hunter" mentality for risks, capable of digging into technical documentation to find hidden gaps.

  • Communication: Fluency in English, with the ability to simplify complex security issues for non-technical stakeholders.

  • Experience: 5+ years in Cyber Security, specifically in a GRC or Security Architecture role.

Other offers great for you!

These companies are also looking for great profiles

Futurwork

Consultant GRC FR/EN

Freelance

Charleroi, Belgium

Hybrid

Skills

Information security risk managementEBIOS Risk ManagerISO 27001Information security governanceInformation security complianceThird-party risk management

3 days ago

Quick apply

Anderson RH

Expert Sécurité IT Senior – Microsoft Security

Freelance

Paris, France

Hybrid

Skills

Microsoft SecurityMicrosoft DefenderMicrosoft SentinelEndpoint Detection and Response (EDR)QualysVulnerability ManagementExpert Sécurité IT Senior – Microsoft Security

9 hours ago

Quick apply

Anderson RH

Ingénieur DevOps - Expert Ansible - Banque

Freelance

Paris, France

Hybrid

Skills

AnsibleKubernetesTerraformGitLab CI/CDArgo CDDynatraceIngénieur DevOps - Expert Ansible

7 hours ago

Quick apply

The best place to find your next move

© 2026. All Rights Reserved.

Talents

Find a job

Create a profile

Solutions and tools