Dexia - werving, vacatures, indienen cvLogo Dexia
Gepubliceerd op 16 september 2026 - Referentie:2026-467

Deputy Chief Information Security Officer M/F

CourbevoieContract van onbepaalde duurSécurité des SI Continuité d'Act

Taken van de functie

The Deputy CISO assists the CISO in defining, implementing, steering and monitoring the Dexia Group’s information systems security and business continuity framework.

He or she contributes both operationally and strategically to IS/BCP governance, the management of cyber and ICT risks, the handling of security incidents, as well as the monitoring of transformation projects and critical service providers within the scope of cybersecurity and crisis management.

Principal tasks
Governance, risks and compliance
·      Contributing to the definition and updating of policies, procedures and frameworks relating to Information Systems Security (ISS) and Business Continuity Planning (BCP).
·       Participating in the assessment and monitoring of ISS/BCP risks (risk mapping, Cyber RCSA (Risk & Control Self-Assessment), key risk indicators (KRIs)).
·       Coordinating and monitoring remediation plans relating to cyber and business continuity risks.
·      Coordinating the various stakeholders (suppliers, service providers, partners, etc.) involved in Dexia’s cybersecurity.
·      Contributing to interactions with internal audit, compliance, ongoing control and supervisory authorities (ACPR, AMF, etc.) where applicable.

Operational security management
·       Helping to integrate security into projects (risk analyses, security questionnaires, architecture committees).
·       Monitoring security controls: identity and access management (IAM), authorisations, logical access, and recurring checks.
·       Contributing to the analysis, management and monitoring of security and business continuity incidents.
·       Leading the development of security indicators (KRIs, information security/business continuity management dashboards) for management and governance bodies.
·       Overseeing projects to strengthen cyber security and the dedicated teams.

Business continuity and crisis management
·            Helping to define, update and test Business Continuity Plans and Disaster Recovery Plans (BCP/DRP).
·            Supporting business departments in defining their continuity requirements (RTO, RPO, process criticality).
·            Participating in the preparation of crisis scenarios and associated exercises (please specify which ones…).

Coordination and representation
·       Participating in internal IS Security/BCP steering committees (CPSSI) and security committees with external service providers and partners.

·       Contributing to strategic transformation projects from an information security and business continuity perspective.

·  Monitoring methodological, regulatory and technological developments in cybersecurity (DORA, AI Act, NIST, ISO 27001 standards, etc.).

·       Acting as backup to the Chief Information Security Officer (CISO) in their absence.

Training
·       Higher education qualification (Engineering degree, Master’s degree) in Information Systems or Cyber Security.
·       Recognised professional certification in cyber security: CISSP, CISM or equivalent.
·       Desirable certifications: CCSP, ISO/IEC 27001 Lead Implementer or Lead Auditor.

Experience
·       Substantial experience in information systems security (10 to 15 years), gained in a regulated environment (banking, insurance, the financial sector) or at a specialist consultancy firm.
Technical and functional skills
·       A solid grasp of information security concepts, cyber risks and business continuity.
·   Knowledge of frameworks and standards (ISO 27001/27002, NIST, cyber best practices).
·       Ability to manage risks, indicators and action plans.
·      Understanding of IAM issues, access management, infrastructure security and service provider security.

Additional skills
·       Strong analytical and summarising skills.
·       Intellectual rigour, organisational skills and reliability.
·      Excellent communication and influencing skills when dealing with a wide range of stakeholders (management, business units, IT department, partners, regulators, etc.).
·      Ability to work across departments with stakeholders from business units, IT and internal audit.

Languages
·       Fluent to professional-level English (spoken and written) is essential.

Key aspects of the post
·       Direct contribution to the Group’s cyber risk management and business continuity.

·       A key role in information security governance and operational resilience.

·       Acting as stand-in for the CISO during their absence.

Op 31 december 2023 zal de Dexia Groep ongeveer 500 personeelsleden tellen. Naast Brussel en Parijs heeft de Groep een beperkte internationale aanwezigheid in Ierland, Italië en de Verenigde Staten.
De Dexia Groep is als bank in ordelijke afwikkeling tot 31 december 2023. In juli 2023 diende de Groep een aanvraag in voor de intrekking van de bank- en beleggingsvergunningen van Dexia (voorheen Dexia Crédit Local), die in december 2023 werd goedgekeurd door de Europese Centrale Bank, met als implementatiedatum 1 januari 2024.
Sinds 1 januari 2024 zet Dexia (het vroegere Dexia Crédit Local) zijn ordelijke afwikkeling als niet-bank dus voort.
Dexia biedt een grote diversiteit en een echte transversaliteit van activiteiten en opdrachten die de professionele ervaring van zijn medewerkers verrijken.

Werken bij Dexia is een belofte om te evolueren in een dynamische omgeving en je carrière te stimuleren door nieuwe vaardigheden te ontwikkelen!

Wervingsproces

1

Interesse in een vacature? Stuur ons uw CV

2

We bellen je voor een HR pre-kwalificatiegesprek

3

We ontmoeten elkaar voor een sollicitatiegesprek en een HR-gesprek

4

We nemen binnen twee weken telefonisch contact met je op

Solliciteer met één klik

Ben je geïnteresseerd in deze vacature? Solliciteer hier.

Solliciteer voor deze baan