IT & Cyber Permanent Control Officer - HQ Brussels
BNP Paribas Fortis · Brussel · 2026-07-22
Over deze functie
**YOUR JOB IN A NUTSHELL**
Join BNP Paribas Fortis as an IT Operational Permanent Control (OPC) Specialist At BNP Paribas Fortis, our Cyber Security division unites the Centre of Excellence (CoE) Security and IT Filiere Production Security BE to design, implement, and maintain robust security solutions. **Our mission?** To foster a trustworthy, secure environment for both our colleagues and clients.
We’re seeking a proactive professional to join our IT Operational Permanent Control (OPC) team, a key function within Governance, Risk, and Compliance (GRC). Here, you’ll play a pivotal role in helping IT and Business Units navigate operational risks tied to IT and Cyber Security, while reinforcing an adaptive, resilient control framework across the bank.
**AND IN DETAIL**
* **Identification and assessment of risks**: You’ll analyse data from risk systems, reports, and governance bodies, turning complex information into practical, risk-based insights. Your conclusions will help leaders make informed decisions. * **Controls Execution & Reporting**: You’ll interpret, adapt, and run control tests (compliance, fraud, outsourcing, etc.), then report findings to the CIO, ensuring controls align with IT’s strategic priorities. * **Regulatory & Internal Reporting**: You’ll prepare precise, high-impact reports for the Internal Control Committee (ExCo), regulators (NBB/BNB, ECB), and Group entities (CDF/IT Group), shaping risk discussions at the highest level. * **Procedure Governance**: As the gatekeeper for IT risk and security procedures, you’ll ensure they’re up to date, accessible, and visible, keeping our compliance framework structured and resilient. * **Governance Body Support**: Acting as NAC secretary for major IT initiatives, you’ll track stakeholder conditions (Business & Functions), driving accountability and alignment in high-impact projects. * **Risk & Control Self-Assessment** (RCSA): You’ll conduct the annual RCSA for all IT risk categories, using the RISK ORM methodology to assess risks, incidents, and recommendations, giving a full picture of IT’s risk profile, including external threats. * **Regulatory Reporting – IT Risk Questionnaire**: You’ll coordinate the bank’s response to the ECB’s IT Risk questionnaire (via Group) and the NBB’s BNP Paribas Fortis reporting, ensuring submissions are accurate, regulator-ready, and endorsed by the CISO/CIO. * **Compliance Controls Execution**: You’ll run IT-wide compliance checks (awareness, ethics, etc.), report findings to the IT Management Team, and drive remediation where needed, ensuring actions are documented and evidenced.
**WHAT WE HAVE TO OFFER**
**Sustainability and impact**
We strongly believe in the positive impact that the financial sector can have on the world. BNP Paribas Fortis offers sustainable and responsible investment products and solutions and encourages social entrepreneurship. Together with our customers, we are working towards a better future every day.
**DEVELOPMENT & CAREER PERSPECTIVES**
We offer a wide range of **training courses, workshops and webinars** to choose from depending on your availability, interests and goals.
**GOOD PLACE TO WORK**
In addition to your remuneration and benefits (meal vouchers, insurance, holidays), we offer flexible salary options, allowing you to convert part of your salary into personalised benefits (phone use, IT equipment, transport, etc.).
**OUR ENGAGEMENT**
At BNP Paribas Fortis, we want to attract and retain all talent, whatever their gender, age, background or sexual orientation, and irrespective of whether they are living with a disability, as every person has their own experiences and their own identity. All of our full-time vacancies are also open to candidates wishing to work on an 80% or 90% full-time equivalent basis.
If the function is categorized as a banking services provider function (cf. Law of 22 April 2019 establishing an oath and a disciplinary regime for the banking sector), you will also need to provide us with a 'certificate of absence of professional ban' from the FSMA confirming that you are not professionally disqualified.
Gevraagde vaardigheden
- Ingrijpen in een informaticadomein: Wetenschappen, techniek
- Superviseert en controleert de staat van de informaticasystemen Maakt back-ups en archiveert gegevens
- De operationele werkleiding superviseren (coördinatie, communicatie, ...)
- Een project leiden
- Risicobeheer van de informatiesystemen bepalen en uitvoeren (beveiliging, vertrouwelijkheid, integriteit, betrouwbaarheid, ...)
- Technische beheerprocedures, gebruiks- en veiligheidsprocedures van de informatica infrastructuur opstellen
- Controleren of het risicobeheer van de informatiesystemen van de onderneming toegepast wordt (beveiliging, vertrouwelijkheid, betrouwbaarheid, ...)
- Een integratieproject (implementering) of ontwikkelingsproject van hardware- of softwareoplossingen leiden of begeleiden
Uw volgende baan staat er al tussen.
Doorzoek actuele vacatures van duizenden werkgevers, bewaar de interessante en laat JobBob de rest in de gaten houden.