CISO Security Architect – OT Security Expert
Job Details
Hiring Process
Time to Answer
2 open days
Process
1 Phone Call
1 Onsite Interview
Days to get an Offer
4 Days after Interview
Overview
CISO Security Architect – OT Security Expert with 10+ years of experience in cybersecurity, including 3+ years in critical infrastructure/defense and OT hybrid environments. Designs secure architectures across network, application, data, SAP, ICAM, cloud, SIEM, and PKI domains. Strong expertise in ISO 27001, IEC 62443, NIST frameworks, and EU/Belgian compliance.
Job Responsibilities
- Design secure network solutions and architectures to protect against cyber threats, in line with enterprise architecture methodology, principles, guardrails, and standards.
- Support other architects to ensure security controls are embedded in system designs and architecture.
- Review architecture proposals and provide feedback on residual risks to project managers and lead architects.
- Participate in architecture councils and autonomously decide whether or not to allow a project to pass the “gate” in the development lifecycle.
- Conduct security risk assessments and oversee the execution of penetration tests to identify vulnerabilities.
- Develop risk mitigation strategies and recommend appropriate security controls.
- Monitor and evaluate emerging threats to adjust security strategies accordingly.
- Report existing vulnerabilities to the GRC Risk Team for proper registration in the risk register and risk reporting to the Risk Office.
- Understand and provide guidance for compliance with relevant security standards (e.g., ISO 27001, NIST).
- Develop and enforce security policies and standards across the organization, reporting to the CISO Management.
- Work with regulatory bodies to ensure understanding of and adherence to legal and compliance requirements.
- Collaborate with IT and business units to integrate security requirements into all aspects of IT projects.
- Work with IT teams, compliance officers, risk management, and other stakeholders to ensure security objectives are met.
- Communicate security risks and solutions to management and stakeholders.
- Provide guidance and training to IT staff on security best practices and policies.
- Support the response to security incidents and breaches.
- Conduct investigations and post-incident analysis.
- Propose action plans for timely resolution of security issues and implementation of corrective measures.
- Evaluate and recommend security products and technologies.
- Stay up to date with emerging security technologies and industry trends.
- Oversee the deployment and configuration of security systems and tools.
- Evaluate and select security technologies and tools that meet the organization’s needs.
- Create and implement a threat modeling methodology to further improve the existing risk management process.
- Perform threat modeling for new and existing solutions across the IT landscape.
- Provide advice during the design phase of projects on security requirements.
- Support the CISO management team with the creation, implementation, and maintenance of CISO capabilities, services, and processes.
- Help define and prioritize security initiatives and projects.
Must Have Skills
- Master’s degree in Cybersecurity, Computer Science, Mathematics, Physics, or Engineering.
- Minimum 10 years of experience in the Cybersecurity domain, including at least 3 years in critical infrastructure or defense.
- Minimum 3 years of experience in OT within complex hybrid environments (IT, OT, IoT, Cloud, ERP).
- Trained in ISO 27001 Lead Auditor, IEC 62443, or NIS2 Cyber Fundamentals.
- Willingness to work on-site when needed.
- Proven track record in developing and maintaining security processes, policies, and standards aligned with business objectives and applicable regulatory frameworks, including European Union and Belgian laws, as well as ISO 27001, IEC 62443, and the NIST SP series.
- Proven track record in designing and implementing security architecture across network, application, and data domains (including network security, SAP, ICAM, authentication and authorisation protocols, PKI, XDR, SIEM, monitoring, auditing, AI, and cloud environments).
-
Proficiency C1 in English and C1 in either French or Dutch.
Nice to have
- Excellent problem solving and analytical skills
- Effective communication and collaboration skills
- Result-oriented, structured, and organised
What's great in the job?
- Great team of smart people, in a friendly and open culture
- Expand your knowledge of various business industries
- Create content that will help our users on a daily basis
- Real responsibilities and challenges in a fast evolving company
Work at yechte
We are an independent digital consultancy with ambitious goals and a global presence. We support a diverse range of companies, building digital teams and delivering innovative digital solutions. Our multicultural and diverse workforce, comprised of ‘Global Citizens’, reflects this inclusivity.
We care about work-life balance and meeting the expectation of a growing team, investing in people because they are our greatest asset. Our consistent growth is a testament to this commitment.
Come work at yechte, a company on the rise, offering excellent benefits, opportunities for personal development, and the chance to learn from accomplished leaders. We are always looking for exceptional professionals to join our team.
What We Offer
Each employee has a chance to see the impact of his work. You work on real digital projects and make tangible contributions to the company. We want to provide to each individual personal, professional and social growth.
Flexibility
We care about your wellbeing. At yechte we offer flexi-hours and hybrid home/office work arrangements, enhancing employee work-life balance and productivity.
Attractive Benefits
We care about your comfort. At yechte we offer cost-effective and eco-friendly mobility plans, food allowances, and comprehensive healthcare support, enhancing employee satisfaction.
Personal Development
We care about your growth. At yechte we offer to boost your personal growth through tailored IT trainings and certifications, fostering a culture of agility and tech-driven expertise.