Chief Information Security Officer (CISO)

Yields Employee working in office

We are looking for an experienced Chief Information Security Officer to lead and evolve our Information Security Management System (ISMS) and represent Yields’ security posture to clients, regulators, and partners. This is a position with direct impact on our commercial growth, compliance programme, and product trust.

Location
Antwerp, Belgium
Contract
Part-time

How you'll make an impact

Client Engagement & Security Representation

  • Serve as Yields’ primary security contact in meetings with clients and prospects across pre-sales, onboarding, and periodic reviews.
  • Provide clear, authoritative explanations of our ISMS, compliance posture, and security controls to technical and non-technical audiences.
  • Support contract negotiations and due diligence processes from a security and risk perspective.

Questionnaire & RFP Management

  • Lead responses to security questionnaires, vendor risk assessments, and RFPs in alignment with ISO 27001 controls.
  • Coordinate inputs across Product, Engineering, and Customer Success to ensure accuracy and completeness.
  • Maintain and continuously improve a knowledge base of standard answers and supporting evidence.

ISMS Maintenance & Operations

  • Oversee core ISMS activities including access rights reviews, policy versioning, KPI tracking, and risk register management.
  • Ensure continuous compliance with ISO 27001:2022 and evolving regulatory requirements.
  • Coordinate management reviews and maintain audit-ready documentation.

Team & Cross-functional Leadership

  • Manage and mentor the internal security team (currently one Security Engineer), including defining a clear development path and growth trajectory for the role.
  • Coordinate with Engineering and Product on CVE management processes, secure development principles, and secure DevOps practices.
  • Advise the Customer Success team on security best practices.
  • Act as a mandatory stakeholder in change management processes across product, infrastructure, and vendor decisions.
  • Provide risk-based security recommendations and evaluate control adequacy for proposed changes.
  • Escalate high-impact risks to the appropriate C-level stakeholder.

Incident Management & Client Follow-Up

  • Lead investigation, coordination, and resolution of security incidents.
  • Ensure timely, structured, and compliant communication with affected clients.
  • Supervise root cause analysis, post-incident reviews, and risk treatment actions.

Security Awareness & Training

  • Design, deliver, and evaluate the company-wide information security awareness programme.
  • Monitor participation and training effectiveness; align content to evolving threats and compliance obligations.
  • Ensure role-specific training is current and appropriately targeted.

ISMS Leadership Responsibilities

As CISO, you hold overarching accountability for the ISMS, including:

  • Ensuring compliance with applicable local and global regulations (privacy, security, administrative).
  • Defining and disseminating information security policies, procedures, and guidelines.
  • Leading the organisation’s response to actual or suspected breaches in confidentiality, integrity, or availability.
  • Reporting to the Management Review and Executive Committee on security matters, on a regular and ad-hoc basis.
  • Advising on ISMS implementation requirements across the business.
  • Monitoring and measurement of security processes, controls, and objectives.
  • Identifying, reviewing, and following up on information security risks.

What we're looking for

  • Proven experience in an information security leadership role, ideally within a regulated industry B2B SaaS industry (financial services, fintech, or SaaS).
  • Strong working knowledge of ISO 27001:2022 and experience maintaining and achieving certification.
  • Experience managing a security team.
  • Track record of representing security to enterprise clients, including during audits, due diligence, and RFP processes.
  • Comfortable operating across technical and executive audiences.
  • Familiarity with cloud and on-premise deployment environments; understanding of software development and infrastructure security.
  • Excellent written and verbal communication skills in English; French or Dutch is a plus.
  • Experience with EU regulatory frameworks (GDPR, DORA, NIS2, or similar) is advantageous.

About Yields

Yields is a fast-growing tech company at the forefront of Model Risk Management and AI Governance. Our SaaS platform helps organizations govern and monitor algorithms with transparency and compliance, from traditional risk models to modern AI systems. Trusted by leading firms worldwide, we empower teams to reduce risk, accelerate innovation, and stay ahead of evolving regulations like the EU AI Act.

How to apply?

If you’re interested, please fill out the application form below. The role will be filled as soon as we find the right candidate.

Why work for Yields

Autonomy

Lots of autonomy and the opportunity to significantly contribute to a fast-growing tech company.

Flexible working

Work from home or from our office in Antwerp (Berchem), with a minimum of 2 days per week required in the office to stay connected in person.

Dynamic and open culture

A dynamic and open company culture with a flexible and remote-friendly work environment.

Competitive salary

Competitive salary + extras like eco cheques, hospitalization insurance, meal vouchers, etc.

Personal development budget

Personal development budget to support your growth.

The right tools

The right tools to do your job (Mac or Dell – your choice!).

Supply of energy

Cookies, candy & fruit in the office, because energy matters.

Application Form