Product Owner

Atos
Belgium
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
Dutch
Job source

Tech stack

Software System Penetration Testing Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Security Management Knowledge Management Open Web Application Security Software Vulnerability Management Software Security Cyber Warfare Vulnerability Analysis

Job description

As Product Owner Cybersecurity Testing & Exposure Management, you are responsible for building, managing, and further developing the cybersecurity testing and exposure management services within the organization.

Cybersecurity Testing includes penetration testing, vulnerability disclosure programs, bug bounty programs, and other forms of offensive security testing.

Exposure Management includes vulnerability management, attack surface management (ASM), and related processes, methodologies, and solutions for managing vulnerabilities and exposure risks.

You translate stakeholder needs into a clear product vision, roadmap, and concrete service offering. You ensure a sustainable, scalable, and high-quality service, monitor the quality of delivered results, and work closely with internal teams and external partners. You are responsible for the further professionalization of the service, embedding expertise within the organization, and the continuous improvement of processes, methodologies, working methods, and supporting solutions.

The role combines product ownership with in-depth subject-matter expertise. In addition to developing, steering, and improving the service, you are expected to take an active role in day-to-day operations. You provide content-related support on complex cases, monitor the quality of activities and results, and actively contribute to service delivery.

Knowledge Retention & Continuous Improvement

You actively build expertise in cybersecurity testing and exposure management and embed this within the organization through knowledge sharing, documentation, standards, and working methods. You support the further development of internal competencies so that internal teams can, over time, take on a larger role within the service. You also actively track developments within the domain and translate these into improvements to the service, processes, methodologies, and tooling.

Requirements

  • Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, etc.
  • Demonstrable expertise in a specific information security knowledge domain (e.g. implementing information security management processes, conducting vulnerability analyses and penetration tests, optimizing application security through cost-effective measures, implementing Privileged Access Management, implementing encryption solutions).
  • Demonstrable experience analyzing, optimizing, and documenting security processes and governance.
  • Demonstrable experience with security management techniques and/or frameworks (e.g. ISO 27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense).
  • Demonstrable knowledge and experience through certifications relevant to your area of expertise (e.g. CISM, CISSP, CEH).
  • Language requirement: Dutch at European CEFR level C2.

Skills Overview

Demonstrable experience as a Product Owner (or similar)

Must have- 5 years-Senior

Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, etc.

Must have-5 years-Senior

Demonstrable experience analyzing, optimizing, and documenting security processes and governance

Must have

Demonstrable experience with exposure management solutions (vulnerability scanners/ASM)

Must have-5 years-Senior

Demonstrable experience conducting/coordinating penetration tests

Must have-5 years-Senior

Demonstrable expertise in a specific information security knowledge domain

Must have-Yes

Language requirement: Dutch at European CEFR level C2

Must have

Demonstrable experience drafting and running RFI/RFP processes (requirements, evaluation criteria, bid assessment, and selection advice)

Should have-3 years-Medior

Demonstrable experience with at least 2 recognized penetration testing industry standards (OWASP, NIST, OSSTMM, and PTES)

Should have-3 years-Medior

Demonstrable experience with security management techniques and/or frameworks (e.g. ISO/IEC 27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense)

Should have-5 years-Senior

Demonstrable experience with service governance (SLA/KPI definition and tracking, service reviews, escalation management, and continuous improvement)

Should have-3 years-Medior

Demonstrable experience with security management techniques and/or frameworks

Should have

Demonstrable knowledge and experience through certifications relevant to area of expertise (e.g. CISM, CISSP, CEH)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann +2 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

Videos

See all

Related articles

See all