> Markdown version of [/jobs/ext/1996919-product-owner](https://www.wearedevelopers.com/jobs/ext/1996919-product-owner). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Owner - **Company:** Atos - **Location:** Belgium - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, Knowledge Management, Open Web Application Security, Software Vulnerability Management, Software Security, Cyber Warfare, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.adzuna.be/details/5834320752 ## About the Role * Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, etc. * Demonstrable expertise in a specific information security knowledge domain (e.g. implementing information security management processes, conducting vulnerability analyses and penetration tests, optimizing application security through cost-effective measures, implementing Privileged Access Management, implementing encryption solutions). * Demonstrable experience analyzing, optimizing, and documenting security processes and governance. * Demonstrable experience with security management techniques and/or frameworks (e.g. ISO 27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense). * Demonstrable knowledge and experience through certifications relevant to your area of expertise (e.g. CISM, CISSP, CEH). * Language requirement: Dutch at European CEFR level C2. Skills Overview Demonstrable experience as a Product Owner (or similar) Must have- 5 years-Senior Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, etc. Must have-5 years-Senior Demonstrable experience analyzing, optimizing, and documenting security processes and governance Must have Demonstrable experience with exposure management solutions (vulnerability scanners/ASM) Must have-5 years-Senior Demonstrable experience conducting/coordinating penetration tests Must have-5 years-Senior Demonstrable expertise in a specific information security knowledge domain Must have-Yes Language requirement: Dutch at European CEFR level C2 Must have Demonstrable experience drafting and running RFI/RFP processes (requirements, evaluation criteria, bid assessment, and selection advice) Should have-3 years-Medior Demonstrable experience with at least 2 recognized penetration testing industry standards (OWASP, NIST, OSSTMM, and PTES) Should have-3 years-Medior Demonstrable experience with security management techniques and/or frameworks (e.g. ISO/IEC 27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense) Should have-5 years-Senior Demonstrable experience with service governance (SLA/KPI definition and tracking, service reviews, escalation management, and continuous improvement) Should have-3 years-Medior Demonstrable experience with security management techniques and/or frameworks Should have Demonstrable knowledge and experience through certifications relevant to area of expertise (e.g. CISM, CISSP, CEH) ## Description As Product Owner Cybersecurity Testing & Exposure Management, you are responsible for building, managing, and further developing the cybersecurity testing and exposure management services within the organization. Cybersecurity Testing includes penetration testing, vulnerability disclosure programs, bug bounty programs, and other forms of offensive security testing. Exposure Management includes vulnerability management, attack surface management (ASM), and related processes, methodologies, and solutions for managing vulnerabilities and exposure risks. You translate stakeholder needs into a clear product vision, roadmap, and concrete service offering. You ensure a sustainable, scalable, and high-quality service, monitor the quality of delivered results, and work closely with internal teams and external partners. You are responsible for the further professionalization of the service, embedding expertise within the organization, and the continuous improvement of processes, methodologies, working methods, and supporting solutions. The role combines product ownership with in-depth subject-matter expertise. In addition to developing, steering, and improving the service, you are expected to take an active role in day-to-day operations. You provide content-related support on complex cases, monitor the quality of activities and results, and actively contribute to service delivery. Knowledge Retention & Continuous Improvement You actively build expertise in cybersecurity testing and exposure management and embed this within the organization through knowledge sharing, documentation, standards, and working methods. You support the further development of internal competencies so that internal teams can, over time, take on a larger role within the service. You also actively track developments within the domain and translate these into improvements to the service, processes, methodologies, and tooling. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)