Cyber threats don't stand still. Neither do we. Deloitte Belgium is looking for a CISO who can lead from the front, protecting a 5,500-person firm while shaping the security strategy that keeps us ahead of the curve. This is a rare opportunity to own security end-to-end, not just as a technical function, but as a firm-wide service that directly enables the business to operate with confidence.
As CISO, you'll be the firm's most senior security leader, reporting directly to the CIO and accountable for the security posture, risk management, and compliance obligations of Deloitte Belgium. You'll lead three specialist teams: our Governance, Risk & Compliance (GRC) function, our Security Operations Centre (SOC), and our Application Compliance Assessment team.
This isn't a purely technical role, nor is it purely strategic. It's both. You'll need to be equally comfortable presenting cyber risk to the Executive Committee and reviewing SOC playbooks with your incident response team, with everything in between.
As CISO, you will hold full service ownership of our Security, Governance & Risk domains where you will be accountable for outcomes, not just processes.
Security Operations
Lead our SOC, SIEM, ISMS, and incident response capability. Drive MTTD and MTTR improvements and ensure the firm is always one step ahead of emerging threats.
Risk & Compliance
Own our GRC framework, regulatory compliance (NIS2, GDPR, DORA, EU AI Act, Internal Deloitte controls), and audit management — reporting directly to ExCo on our risk posture.
Own the firm's security risk register and represent cyber risk at ExCo and governance forums.
Application Security
Ensure our Secure SDLC framework is embedded across all development activity. Make security a shared engineering value — not a late-stage gate.
Strategy & Leadership
Set and execute the firm's information security strategy from policy to operations to culture.
Manage team capacity, performance, skills development, and succession planning across the security function, with teams covering GRC, SOC, and application compliance.
Oversee the use of managed security service providers and third-party partners, ensuring performance and value.
Act as the CIO's trusted advisor — and the business's — on all things security.