Product Owner
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
As Product Owner Cybersecurity Testing & Exposure Management, you are responsible for building, managing, and further developing the cybersecurity testing and exposure management services within the organization.
Cybersecurity Testing includes penetration testing, vulnerability disclosure programs, bug bounty programs, and other forms of offensive security testing.
Exposure Management includes vulnerability management, attack surface management (ASM), and related processes, methodologies, and solutions for managing vulnerabilities and exposure risks.
You translate stakeholder needs into a clear product vision, roadmap, and concrete service offering. You ensure a sustainable, scalable, and high-quality service, monitor the quality of delivered results, and work closely with internal teams and external partners. You are responsible for the further professionalization of the service, embedding expertise within the organization, and the continuous improvement of processes, methodologies, working methods, and supporting solutions.
The role combines product ownership with in-depth subject-matter expertise. In addition to developing, steering, and improving the service, you are expected to take an active role in day-to-day operations. You provide content-related support on complex cases, monitor the quality of activities and results, and actively contribute to service delivery.
Knowledge Retention & Continuous Improvement
You actively build expertise in cybersecurity testing and exposure management and embed this within the organization through knowledge sharing, documentation, standards, and working methods. You support the further development of internal competencies so that internal teams can, over time, take on a larger role within the service. You also actively track developments within the domain and translate these into improvements to the service, processes, methodologies, and tooling.
Requirements
- Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, etc.
- Demonstrable expertise in a specific information security knowledge domain (e.g. implementing information security management processes, conducting vulnerability analyses and penetration tests, optimizing application security through cost-effective measures, implementing Privileged Access Management, implementing encryption solutions).
- Demonstrable experience analyzing, optimizing, and documenting security processes and governance.
- Demonstrable experience with security management techniques and/or frameworks (e.g. ISO 27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense).
- Demonstrable knowledge and experience through certifications relevant to your area of expertise (e.g. CISM, CISSP, CEH).
- Language requirement: Dutch at European CEFR level C2.
Skills Overview
Demonstrable experience as a Product Owner (or similar)
Must have- 5 years-Senior
Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, etc.
Must have-5 years-Senior
Demonstrable experience analyzing, optimizing, and documenting security processes and governance
Must have
Demonstrable experience with exposure management solutions (vulnerability scanners/ASM)
Must have-5 years-Senior
Demonstrable experience conducting/coordinating penetration tests
Must have-5 years-Senior
Demonstrable expertise in a specific information security knowledge domain
Must have-Yes
Language requirement: Dutch at European CEFR level C2
Must have
Demonstrable experience drafting and running RFI/RFP processes (requirements, evaluation criteria, bid assessment, and selection advice)
Should have-3 years-Medior
Demonstrable experience with at least 2 recognized penetration testing industry standards (OWASP, NIST, OSSTMM, and PTES)
Should have-3 years-Medior
Demonstrable experience with security management techniques and/or frameworks (e.g. ISO/IEC 27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense)
Should have-5 years-Senior
Demonstrable experience with service governance (SLA/KPI definition and tracking, service reviews, escalation management, and continuous improvement)
Should have-3 years-Medior
Demonstrable experience with security management techniques and/or frameworks
Should have
Demonstrable knowledge and experience through certifications relevant to area of expertise (e.g. CISM, CISSP, CEH)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.beGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What’s the Difference between a Junior, Mid, and Senior Developer?
Best Companies in the Netherlands: Top 25 Companies in 2023Â
The 12 Best Jobs for Software Engineers
Software Developer Salary in The Netherlands [2023]