IT Security Risk & Compliance Officer @ Lotus Bakeries
AMSP04484
Function
As a hands-on operational expert, the IT Security – Risk & Compliance Officer takes full ownership of the international information security compliance landscape. Operating from the Belgian headquarters, this role coordinates and aligns global efforts to safeguard both Information Technology (IT) and Operational Technology (OT) environments, while continuously challenging the technical security teams and third-party vendors.
Key responsibilities include:
- ISMS & Policy Management: Maturing and strengthening the existing Information Security Management System (ISMS) based on the ISO27001 standard. This includes writing, updating, and embedding security policies across the global organization.
- Risk Assessments: Conducting annual and project-based risk analyses. This involves collaborating closely with stakeholders (such as sitting down with maintenance and plant managers) to identify, mitigate, and follow up on digital and data risks.
- Compliance & Regulatory Monitoring: Tracking and implementing evolving international regulations, specifically spearheading the NIS2 compliance project and mapping its requirements against existing frameworks.
- Audits & Vendor Evaluations: Planning and executing internal security audits, guiding external auditors, and systematically screening and evaluating third-party suppliers (Third-Party Risk Management).
- Culture & Awareness: Designing, driving, and delivering annual security awareness programs and training sessions (e.g., around phishing and cybersecurity) to foster a strong risk-aware culture worldwide.
- Incident & Project Support: Helping to coordinate incident response procedures when necessary, and conducting security/privacy assessments on new business projects (e.g., evaluating data retention and GDPR compliance for a new factory camera system).
Profile
- Education: a Master’s degree in a relevant field of study.
- Experience: at least 5 years of proven experience in a similar information security, risk, or compliance role within a multinational environment.
- Frameworks & Standards: Possesses strong, in-depth knowledge of the ISO27001 standard and practical experience with its implementation and maintenance.
- IT & OT Alignment: Demonstrates a solid understanding of both Information Technology (IT) and Operational Technology (OT). Experience or strong affinity with production environments—including systems like SCADA, PLCs, and factory automation—is considered a major asset for visiting and auditing global production plants.
- Stakeholder & Change Management: Displays exceptional stakeholder management skills, with the ability to confidently communicate across all levels of the organization—from factory maintenance managers and engineering teams to third-party vendors and C-level executives. Strong change management skills are essential to introduce new security protocols smoothly and build a positive risk culture.
Offer
Lotus Bakeries is a BEL20 listed, international player with strong growth ambitions, but still a family business at its core, offering a wealth of challenging projects where you can make a real impact as an individual and be seen and heard.
You will be a part of an ambitious and driven team with a mix of talents, ranging from senior experts to junior high potentials.
Lotus Bakeries is well known for its company culture where passion, team spirit and open dialogue are the main drivers. The company helps people to grow and develop their talents, and strongly believes in internal mobility to allow talents to develop further.
Last but not least, the package that comes with it is also a great deal, including an attractive set of fringe benefits and a bonus plan. And off course, freshly baked cookies every day

