Jobs

Security Strategy & GRC Consultant

You help our clients build and run their governance, risk and compliance programmes — assessing risk, designing frameworks and controls, and guiding leadership across NIS2, ISO 27001, TISAX and NIST CSF.

  • Location · Hybrid — home, client sites and our Antwerp office
  • Employment · Full-time
  • Experience · At least 2 years in security
  • Languages · Dutch and English

Introduction

As a Security Strategy & GRC Consultant at Curios you help our clients build and run their governance, risk and compliance programmes — across NIS2, ISO 27001, TISAX and NIST CSF. You assess risk, design frameworks and controls, and guide client leadership on strategy. It is client-facing consultancy work across Belgian and international organisations, in Dutch and English.

What you’ll do

  • Lead the development and implementation of clients’ GRC and information-security programmes (NIS2, ISO 27001, TISAX, NIST CSF)
  • Conduct risk assessments and develop mitigation strategies
  • Design controls and advise on GRC best practices
  • Guide client leadership on security strategy and roadmap

What we’re looking for

Must have

  • At least 2 years in cybersecurity consulting across strategy and GRC
  • Hands-on experience with frameworks such as NIS2, ISO 27001, TISAX or NIST CSF
  • Professional certifications such as CISSP or CISM
  • Strong understanding of cybersecurity standards and trends
  • Professional working proficiency in Dutch and English — you’ll work with Belgian clients in both

Nice to have

  • A bachelor’s degree in Computer Science, Information Technology or a related field

What we offer

  • A training and certification budget. We’re a team of 48+ certifications and we intend to keep it that way — your next certification is part of the job, not something you fit around it.
  • A competitive salary with a 13th month, plus a net expense allowance on top.
  • A company car and fuel card — you’ll be moving between client sites, home and our Antwerp office.
  • Meal vouchers and eco-vouchers.
  • Hospitalisation insurance.
  • Phone and laptop.
  • A 40-hour week with 12 ADV days, on top of your statutory holiday.
  • Hybrid working — home, client sites and the Antwerp office.
  • Consultancy work with real variety — Belgian and international organisations, across strategy and hands-on technical work.

About Curios

We’ve done cybersecurity, and only cybersecurity, since 2017. We’re a Belgian firm working across Europe, with 48+ certifications across the team and published CVEs in enterprise software. Client work is delivered by senior specialists — no juniors on client engagements — pairing board-level advisory with hands-on technical depth.

How to apply

Send your CV and a short note about what you’re looking for to [email protected]. We reply to every application within 3 working days.

Need an adjustment to take part in the application or interview process? Tell us in your first email and we’ll arrange it.

How we handle your application data

Curious how we hire? See our hiring process.

Apply by email