Sivel Labs Talents
Security & Privacy Expert
- Organization
- Sivel Labs Talents
- Location
- Remote
- Contract type
- freelance
Our client is a key organisation within the Belgian energy ecosystem and is considered an essential entity under the NIS2 framework. The Security, Privacy & Access team is seeking an experienced Security & Privacy Expert to strengthen its privacy, legal and information security capabilities. The assignment focuses on privacy-related activities, legal support, information security governance and the continued development of the organisation’s ISMS and PIMS. What we're looking for - Master’s degree in Law. - Minimum 8 years of proven experience as a legal expert in privacy and information security. - Minimum 8 years of proven experience as a Security Consultant within areas such as: Data; Infrastructure; Applications; Information security governance. - Proven professional experience in privacy management. - DPO certification or equivalent demonstrable privacy expertise. - Strong knowledge of GDPR and Belgian privacy legislation. - Proven experience implementing ISO 27001, ISO 27002 and ISO 27701. - Strong knowledge of Information Security Management and ISO 2700x standards. - Proven experience in data governance, including data classification, retention and data transfers, including cloud environments. - Proven experience drafting and reviewing contracts with customers and service providers, specifically regarding privacy and information security clauses. - Proven experience with DPIAs and privacy/security risk assessments. - Proven experience managing Records of Processing Activities and registers of data processing agreements. - Ability to work independently and proactively. - Strong communication and stakeholder-management skills within multidisciplinary environments. - English, Dutch and French at CEFR C1 level, or at minimum Dutch or French at C1 together with strong professional capability in the other required languages. - The consultant must have access to relevant external legal or specialist support where required. Nice-to-have - Experience within the Belgian energy market. - Experience working in Agile environments. - Experience in critical infrastructure or NIS2-regulated organisations. Additional details The organisation achieved ISO 27001 certification in 2026 and is now working towards ISO 27701 certification in 2027. - Provide legal expertise on privacy, data protection and information security; support interpretation and application of GDPR and Belgian privacy legislation; review and update data processing agreements; maintain and optimise the register of processing agreements; update the Record of Processing Activities, including data retention periods; define and document processes for ongoing privacy-register maintenance; and conduct and review DPIAs and privacy-related risk assessments. - Integrate security and privacy requirements into contracts with service providers and customers, review contractual clauses relating to information security, privacy, data protection and third-party risk, support contract management from a privacy and security perspective, and ensure contractual arrangements align with applicable legal, regulatory and ISO requirements. - Integrate security and privacy requirements into change management; contribute to continuous improvement and maintenance of the ISMS and PIMS; support implementation and further development of ISO 27001, ISO 27002 and ISO 27701; contribute to privacy, security and compliance governance; and support NIS2-related compliance. - Support data governance covering data classification, data retention, data transfers, cloud data governance and sensitive data handling, ensuring privacy and security requirements are embedded throughout the data lifecycle. The ideal candidate combines strong legal expertise with hands-on experience in privacy, cybersecurity and information security governance. The role involves working across legal, security, data governance, IT and business, translating regulatory requirements into practical processes, controls, contractual provisions and governance frameworks, and engaging with internal and external stakeholders in a regulated environment.