We are seeking an experienced Chief Information Security Officer (CISO) to lead and oversee the information security strategy for a major European Institution operating under a Managed Services and Framework Contract environment.
The successful candidate will define, implement, and govern the organization's cybersecurity strategy, ensuring protection of information assets, regulatory compliance, risk management, and cyber resilience.
This position offers full remote work within the European Union, with occasional travel required for governance meetings, workshops, audits, and strategic initiatives.
Key Responsibilities:
Cybersecurity Strategy & Governance
- Define, maintain, and execute the organization's cybersecurity strategy.
- Develop and enforce security policies, standards, and procedures.
- Establish security governance frameworks aligned with business objectives.
- Advise senior management on cybersecurity risks and strategic decisions.
- Promote a security-first culture across the organization.
Risk Management
- Lead enterprise-wide cybersecurity risk assessments.
- Identify, evaluate, and mitigate security threats and vulnerabilities.
- Maintain and report on the organization's risk posture.
- Ensure risk treatment plans are implemented and monitored.
Compliance & Regulatory Requirements
- Ensure compliance with applicable European regulations, standards, and security frameworks.
- Oversee security audits, assessments, and compliance reviews.
- Support internal and external audit activities.
- Monitor regulatory developments impacting cybersecurity and data protection.
Security Operations & Incident Management
- Oversee security monitoring, threat detection, and incident response activities.
- Lead the response to major cybersecurity incidents and crisis situations.
- Ensure appropriate business continuity and disaster recovery capabilities.
- Drive continuous improvement of security operations.
Security Architecture & Technology
- Provide strategic direction for secure architecture and infrastructure design.
- Ensure the adoption of Security by Design and Privacy by Design principles.
- Oversee cloud security, network security, endpoint protection, IAM, and data security initiatives.
- Review and approve security requirements for new projects and services.
Stakeholder & Vendor Management
- Act as the primary cybersecurity advisor to executive leadership and stakeholders.
- Collaborate with technology teams, service providers, and external partners.
- Ensure suppliers comply with contractual cybersecurity obligations.
- Participate in Framework Contract governance and security reviews.
Required Qualifications:
Mandatory:
- Master's degree or equivalent in Computer Science, Information Security, Cybersecurity, Engineering, or a related discipline.
- 10 to 20 years of professional experience in Information Security and Cybersecurity.
- Proven experience in a CISO, Deputy CISO, Head of Security, or Senior Information Security Management role.
- Strong knowledge of cybersecurity governance, risk management, and compliance.
- Experience managing cybersecurity programs in large and complex organizations.
- Excellent communication and stakeholder management skills.
- Fluent English (written and spoken).
- Citizenship of an EU Member State.
Preferred:
- Experience working with European Institutions, EU Agencies, NATO, international organizations, or government bodies.
- Experience in Managed Services and Framework Contract environments.
- Knowledge of NIS2, DORA, GDPR, ISO 27001, and other cybersecurity frameworks.
- Experience securing cloud environments such as Microsoft Azure, AWS, or Google Cloud.
Certifications:
- The following certifications are highly desirable:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- CCSP (Certified Cloud Security Professional)
- GIAC Certifications
- TOGAF (considered an asset)
Required Skills:
- Cybersecurity Governance
- Information Security Management
- Enterprise Risk Management
- Security Architecture
- Security Operations
- Incident Response
- Identity & Access Management (IAM)
- Cloud Security
- Compliance & Audit Management
- Third-Party Risk Management
- Business Continuity & Disaster Recovery
- Leadership and Team Management
- Executive Communication
Personal Competencies:
- Strategic thinker with strong leadership capabilities.
- Ability to influence senior executives and stakeholders.
- Excellent decision-making and problem-solving skills.
- Strong analytical mindset.
- Ability to operate effectively in multicultural and international environments.
- Results-oriented and resilient under pressure.
Offer:
- Rate: 450 EUR/MD
- Long-term assignment with a leading European Institution.
- Flexible work environment with occasional travel.
- Opportunity to lead strategic cybersecurity initiatives.
- International and multicultural environment.
- Exposure to large-scale, mission-critical digital transformation programs.
- Work Location: Remote within the EU with occasional travel.

