> Markdown version of [/jobs/ext/1922623-product-owner-cybersecurity-testing-exposure](https://www.wearedevelopers.com/jobs/ext/1922623-product-owner-cybersecurity-testing-exposure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Owner Cybersecurity Testing & Exposure - **Company:** Madello Consulting - **Location:** Brussel, Belgium - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Open Web Application Security, Software Vulnerability Management, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.vdab.be/vindeenjob/vacatures/74295060 ## About the Role * Minimum 5 years of experience as a Product Owner or in a comparable role. * Minimum 5 years of experience as a Security Consultant in application, infrastructure, data, cloud, or a related environment. * Minimum 5 years of experience with exposure-management solutions, including vulnerability scanners or attack surface management. * Minimum 5 years of experience performing or coordinating penetration tests. * Demonstrable expertise in a specialised information-security domain. * Experience analysing, optimising, and documenting security processes and governance. * Knowledge of vulnerability management and remediation processes. * Experience reviewing security-testing reports and deliverables. * Strong product vision, roadmap, and stakeholder-management capabilities. Should Have * Minimum 3 years of experience with RFI and RFP processes, including requirements, evaluation criteria, proposal assessment, and selection advice. * Minimum 3 years of experience with at least two recognised penetration-testing standards, such as OWASP, NIST, OSSTMM, or PTES. * Minimum 5 years of experience with security-management frameworks. * Minimum 3 years of experience with service governance. * SLA and KPI definition and monitoring. * Service reviews and escalation management. * Continuous service improvement. * ISO/IEC 27000 series. * COBIT for Security. * NIST. * OWASP. * CIS Critical Security Controls. * Relevant certifications such as CISM, CISSP, or CEH. * Vulnerability disclosure programmes. * Bug bounty programmes. * Attack Surface Management. * Supplier management. ## Description The consultant will be responsible for building, managing, and further professionalising services related to cybersecurity testing and exposure management for Flemish government entities and local authorities. Cybersecurity testing includes penetration testing, vulnerability disclosure programmes, bug bounty programmes, and other offensive security assessments. Exposure management includes vulnerability management, attack surface management, and related processes, methodologies, and tooling used to identify and manage security weaknesses and exposure risks. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)