Skip to content
HumanInTech
All jobs
FreelanceFull-time Brussels, hybrid

Senior Cybersecurity Architect

A Belgian public-sector organisation

What you will do

You will occupy a cross-functional role between security governance, IT architecture and technical teams. You will analyse the existing environment, define target architectures, assess risks and impacts, compare options and formulate recommendations that can be applied in a complex, highly interconnected IT environment.

You will apply principles such as Security by Design, Security by Default, Zero Trust, least privilege, defence in depth, segmentation and resilience. You will seek a balance between security, availability, business needs, maintainability and operational constraints.

Your responsibilities include:

  • Analysing the existing cybersecurity architecture and formulating recommendations for evolution in line with the overall IT architecture and the organisation's requirements
  • Identifying and documenting risks, dependencies, vulnerabilities and weaknesses, then proposing prioritised improvements for decision
  • Conducting or contributing to security architecture reviews for new projects, migrations or significant changes, and delivering findings, risks and recommendations
  • Proposing and documenting principles for segmentation, flow control, access, resilience and defence in depth in collaboration with internal IT teams
  • Analysing needs related to identity, access, authentication, privileged accounts and trust mechanisms, and formulating corresponding architecture recommendations
  • Advising teams on logging, monitoring, detection, traceability and integration with security supervision capabilities
  • Proposing and formalising security standards, patterns, hardening principles and reusable technical requirements with IT teams
  • Analysing and constructively challenging technical proposals from vendors, integrators or partners, identifying impacts, dependencies, risks and alternatives
  • Providing expertise during technical analyses related to major incidents, resilience, continuity or recovery
  • Maintaining technology and regulatory watch and presenting relevant developments with justification, benefits, risks and impacts
  • Supporting IT teams in analysing, understanding and, when requested, preparing the implementation of approved recommendations
  • Actively sharing knowledge and expertise with internal teams to foster their autonomy and avoid excessive dependency on consultants or vendors

You will work in an advisory capacity. All significant proposals must be documented and submitted for validation before implementation. You will respect the organisation's change management processes and work collaboratively with internal teams rather than in isolation.

What we are looking for

Experience and profile

  • Minimum 10 years of experience in complex enterprise IT environments, including at least 7 years in cybersecurity and at least 5 years of demonstrable experience in a Security Architect or Cybersecurity Architect role
  • Your architecture experience must be directly related to designing, reviewing and evolving complex cybersecurity architectures; experience limited to administration, operations, SOC, security engineering or product expertise cannot be considered equivalent to architect experience
  • Proven experience in designing, reviewing and evolving security architectures covering multiple domains: network and connectivity, datacentre, identity and access, perimeter security, remote access, cloud/hybrid and security monitoring
  • Ability to produce and maintain high-level and detailed architectures, flow diagrams, communication matrices, segmentation principles, architecture decisions and security requirements
  • Excellent understanding of enterprise security technologies and ability to reason independently of vendors and suppliers
  • Strong grasp of identity and access architectures: IAM, MFA, privileged accounts, PKI, certificates, strong authentication and PAM principles
  • Good understanding of network architectures, segmentation, routing, high availability, interconnections, remote access and flow control mechanisms
  • Good understanding of systems environments, virtualisation, datacentre, cloud/hybrid as well as continuity and resilience challenges
  • Experience with logging architectures, SIEM/SOC and security monitoring: collection, correlation, detection, retention and traceability
  • Ability to conduct technical risk analyses, challenge vendor proposals and formulate proportionate, actionable and documented recommendations
  • Ability to translate regulatory, governance and risk requirements into concrete controls and architecture decisions

Standards, frameworks and certifications

  • Mastery of ISO/IEC 27001:2022 requirements and principles and ability to translate them into architecture requirements and technical controls
  • Good command of ISO/IEC 27002:2022 and ISO/IEC 27005:2022, particularly for selecting security measures and managing risks related to architecture choices
  • Good knowledge of NIS2, GDPR and the main cybersecurity frameworks applicable to a public or regulated environment
  • Mastery of the CyberFundamentals (CyFun) Framework of the Belgian Centre for Cybersecurity in its current version, its assurance levels and associated requirements, with ability to translate them into architecture requirements and technical controls and to articulate them with NIS2 and ISO/IEC 27001
  • Practical knowledge of complementary frameworks such as NIST Cybersecurity Framework and CIS Controls; knowledge of continuity, incident management and cloud security frameworks is an asset

To confirm the expected level of seniority, you must hold at least one recognised senior-level cybersecurity certification and demonstrate real competence in architecture. The following certifications are particularly relevant:

  • CISSP (ISC2) or comparable senior-level certification: strongly expected
  • ISSAP (ISC2) and/or SABSA: highly valued to demonstrate specific competence in security architecture
  • ISO/IEC 27001 Lead Implementer or Lead Auditor: valued; an ISO/IEC 27005 / Risk Manager certification is also an asset
  • TOGAF Enterprise Architecture Practitioner or CCSP: complementary assets depending on your experience and scope

Certifications do not replace experience. You must be able to demonstrate, through concrete achievements, your ability to design, argue, document and evolve complex cybersecurity architectures.

Professional attitude

  • Client orientation: understand needs, constraints and priorities before proposing a solution; seek a secure, proportionate, workable and maintainable response
  • Listening and collaboration: work in a spirit of partnership and value the environmental knowledge held by internal teams
  • Communication and teaching: explain complex subjects clearly to technical or non-technical audiences and adapt the level of detail to the audience
  • Constructive critical thinking: know how to challenge a solution without imposing an answer; argue on the basis of risks, facts and good practices and propose alternatives
  • Pragmatism: avoid theoretical or over-engineered architectures and seek the best balance between security, availability, costs, operations and business needs
  • Transparency and integrity: communicate assumptions, limitations, risks and uncertainties and promptly flag any decision requiring arbitration
  • Rigour: work in a structured, traceable and documented manner, with particular attention to the quality of deliverables and the follow-up of decisions
  • Responsible autonomy: conduct analyses autonomously while respecting responsibilities, validation processes and decisions
  • Knowledge transfer: actively share your know-how and contribute to the progressive autonomy of internal teams
  • Technological neutrality: advise in the organisation's interest and objectively evaluate several options when relevant

Education

Master's degree in Computer Science, Cybersecurity, Information Systems Security, Networks and Telecommunications, Engineering Sciences or equivalent.

Particularly significant and demonstrable professional experience in cybersecurity architecture may be considered equivalent, provided you meet the expected level of expertise and seniority.

Languages

  • French: native or fluent
  • English: good passive knowledge
  • Dutch: passive knowledge is an asset

The setting

This is a freelance assignment for 12 months, starting in January 2027. The role is based in Brussels with a hybrid working arrangement. You will work closely with the IT teams of a Belgian public-sector organisation in a collaborative, advisory capacity focused on knowledge transfer and co-construction.

Job alerts

Hear about the positions that fit you.

Tell us what you're interested in. You get a weekly overview of matching open positions, and, if you like, we reach out directly when something comes up for your profile. No account, one click to confirm, one click to leave.

What are you interested in?

Domains

Technologies

How may we keep you posted?

You confirm your subscription with one click in the e-mail we send you. Every message contains a link to change or stop this. We only use your details for this purpose. See the privacy policy.