Cyber Security Engineer

Tata Consultancy Services
Brussel, Belgium
1 day ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Languages
English, French
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Software System Penetration Testing Burp Suite Software as a Service Cloud Computing Cloud Computing Security Code Review Cyber Security Data Centers Cryptographic Protocols Identity and Access Management
+30 more
Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Information Systems Security Architecture Professional Python (Programming Language) Network Security Open Web Application Security PCI Data Security Standards Public Key Infrastructure Systems Development Life Cycle Azure Active Directory RSA (Cryptosystem) Secure Coding Security Information and Event Management Software Engineering Systems Integration Scripting Transport Layer Security Cloud Platform System Okta Metasploit Nessus Microsoft Sentinel SailPoint Splunk Devsecops Qualys Static Application Security Testing Vulnerability Analysis Programming Languages Dynamic Application Security Testing

Job description

  • Develop and implement security policies and procedures.
  • Define, implement and monitor security plans.
  • Guide development teams throughout the Software Development Lifecycle (SDLC) to build and operate software securely, following EC standards and industry best practices (e.g., OWASP Top 10).
  • Conduct security inspections, code reviews, and risk assessments for internally developed as well as SaaS (Software-as-a-Service) applications.
  • Monitor systems for security breaches and incidents.
  • Analyse and respond to security threats and vulnerabilities, including managing the remediation process through to closure.
  • Design and deploy security solutions and technologies for internal EC Data Centre and Cloud environments.
  • Collaborate with IT and business teams to ensure compliance with security standards.
  • Ensure data protection and privacy through encryption and access controls.
  • Conduct security training and awareness programs for staff.
  • Prepare incident response plans and conduct simulations.
  • Stay updated on the latest security trends and emerging threats.
  • Perform regular vulnerability assessments and penetration tests using automated tools and manual techniques to identify and prioritize security weaknesses.
  • Manage and configure security tools, including SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), firewalls, and intrusion detection/prevention systems.
  • Lead the response to security incidents, including containment, eradication, recovery, and post-incident analysis and reporting.

Requirements

  • Proficiency in cybersecurity domains (network, application, endpoint, cloud).
  • Experience with integrating security into DevSecOps pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and software supply chain security tools.
  • Understanding of secure coding practices in languages (Java, Python, JavaScript) and knowledge of common vulnerabilities (e.g., OWASP Top 10).
  • Knowledge of encryption protocols and technologies (e.g., TLS/SSL, IPSec, AES, RSA, PKI).
  • Experience with SIEM platforms (e.g., Splunk, ELK, Microsoft Sentinel).
  • Expertise in vulnerability assessment and penetration testing methodologies and tools (e.g., Nessus, Qualys, Burp Suite, Metasploit, OWASP ZAP).
  • Knowledge of IAM/IGA platforms (e.g., Okta, Azure AD, SailPoint), MFA and SSO.
  • Experience with cloud security architectures and controls.
  • Familiarity with regulatory compliance standards like GDPR, HIPAA, and PCI-DSS.
  • Proficiency in scripting or programming languages for automation and monitoring.
  • Knowledge of ISO/IEC 27001 and ISO/IEC 27005 standards.
  • Experience with endpoint detection and response (EDR) tools and network security monitoring (NSM).
  • Knowledge of threat intelligence platforms and threat modelling methodologies., * One of the following or an equivalent certification:
  • CISSP (Certified Information Systems Security Professional)
  • CISM
  • CCSP

Optional for ‘Normal’ level:

  • Cloud and vendor-specific certifications.

Senior

Mandatory for ‘Senior’ level:

  • One of the following or an equivalent certification:
  • CISSP-ISSAP
  • GIAC advanced credential (e.g., GCIH, GCIA)
  • OSCP (Offensive Security Certified Professional)

Optional for ‘Senior’ level:

  • Cloud expert certifications., * Ability to analyse complex and design effective solutions.
  • Talent for attention to detail in code correctness, error handling, and documentation.
  • Ability to anticipate future threats and evaluate trends.
  • Ethical judgment and integrity.
  • Continuous learning and adaptability to emerging security trends.
  • Capability to educate and train others on security practices.
  • Ability to participate in multilingual meetings.
  • Ability to understand, speak and write English, optionally French as an additional asset.
  • Excellent interpersonal and communication skills.
  • Ability to work in a team as well as autonomously.
  • Results-oriented mindset, focused on delivering results.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all