Product Owner Cybersecurity Testing & Exposure

Madello Consulting
Brussel, Belgium
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
Dutch
Job source

Tech stack

Software System Penetration Testing Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Open Web Application Security Software Vulnerability Management Vulnerability Analysis

Job description

The consultant will be responsible for building, managing, and further professionalising services related to cybersecurity testing and exposure management for Flemish government entities and local authorities.

Cybersecurity testing includes penetration testing, vulnerability disclosure programmes, bug bounty programmes, and other offensive security assessments. Exposure management includes vulnerability management, attack surface management, and related processes, methodologies, and tooling used to identify and manage security weaknesses and exposure risks.

Requirements

  • Minimum 5 years of experience as a Product Owner or in a comparable role.
  • Minimum 5 years of experience as a Security Consultant in application, infrastructure, data, cloud, or a related environment.
  • Minimum 5 years of experience with exposure-management solutions, including vulnerability scanners or attack surface management.
  • Minimum 5 years of experience performing or coordinating penetration tests.
  • Demonstrable expertise in a specialised information-security domain.
  • Experience analysing, optimising, and documenting security processes and governance.
  • Knowledge of vulnerability management and remediation processes.
  • Experience reviewing security-testing reports and deliverables.
  • Strong product vision, roadmap, and stakeholder-management capabilities.

Should Have

  • Minimum 3 years of experience with RFI and RFP processes, including requirements, evaluation criteria, proposal assessment, and selection advice.
  • Minimum 3 years of experience with at least two recognised penetration-testing standards, such as OWASP, NIST, OSSTMM, or PTES.
  • Minimum 5 years of experience with security-management frameworks.
  • Minimum 3 years of experience with service governance.
  • SLA and KPI definition and monitoring.
  • Service reviews and escalation management.
  • Continuous service improvement.
  • ISO/IEC 27000 series.
  • COBIT for Security.
  • NIST.
  • OWASP.
  • CIS Critical Security Controls.
  • Relevant certifications such as CISM, CISSP, or CEH.
  • Vulnerability disclosure programmes.
  • Bug bounty programmes.
  • Attack Surface Management.
  • Supplier management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.vdab.be

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:32 min

Mandatory vulnerability reporting and secure product design requirements

Matthew Brady Matthew Brady · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

3:17 min

Embedding automated vulnerability analysis within CircleCI workflows

Milecia Mcgregor · LIVE

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all