Cybersecurity Analyst Vulnerability & Attack Surface Management

Harvey Nash
Brussels Metropolitan Area, Belgium
2 days ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Languages
Dutch
Job source

Tech stack

Data Analysis Software System Penetration Testing JIRA Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Security Management Python (Programming Language) Open Web Application Security Phishing Software Vulnerability Management Data Processing Scripting
+5 more
Software Security CIS Benchmarks Api Management Servicenow Vulnerability Analysis

Job description

As a Cybersecurity Analyst - Vulnerability & Attack Surface Management, you will support the further development, execution, and optimization of services related to vulnerability management, attack surface management, and cyber awareness.

You will analyze, assess, and follow up on information regarding vulnerabilities, exposed systems, and security risks. You will validate findings, place them in the appropriate risk context, and translate them into concrete recommendations. In doing so, you will support our client’s entities and local authorities in prioritizing and tracking remediation actions.

Automation is an essential part of the role. Given the large volume of sources, data, and stakeholders involved, you will develop and maintain scripts, primarily in Python, as well as integrations that support the collection, enrichment, correlation, follow-up, and reporting of vulnerability information.

You will work closely with internal teams, external service providers, and representatives of our client’s entities and local authorities. Your objective is to ensure vulnerabilities and exposed systems are identified and communicated in a timely manner, together with actionable recommendations, enabling organizations to effectively remediate identified risks.

In addition, you will support initiatives related to cyber awareness and phishing simulations.

This is primarily an operational and support-oriented role, combining technical expertise with a strong hands-on focus. Besides analyzing and following up on cases, you will play an active role in the day-to-day delivery of the service and contribute to the further professionalization of processes, methodologies, and supporting solutions., * Analyze vulnerabilities and exposures based on a variety of information sources.

  • Validate findings, filter out noise and false positives, and assess the actual impact on affected organizations.
  • Prioritize findings based on risk, considering factors such as CVSS scores, EPSS scores, exploitation status, and organizational context.
  • Derive both overarching trends and organization-specific recommendations from analyzed data.
  • Communicate findings through existing reporting and communication channels tailored to the relevant target audiences.
  • Develop and maintain Python scripts and API integrations for data collection, enrichment, correlation, and reporting.
  • Support our client and local authorities in tracking remediation activities.
  • Assist in the preparation, execution, and evaluation of cyber awareness initiatives and phishing simulations.
  • Contribute to the documentation, standardization, and continuous improvement of processes, methodologies, and supporting solutions.

Requirements

  • Proven experience as a Security Consultant within one or more of the following domains: data, infrastructure, applications, or related environments.
  • Demonstrated expertise in a specific area of information security, such as:
  • Implementing information security management processes
  • Conducting vulnerability assessments and penetration testing
  • Improving application security through cost-effective measures
  • Implementing Privileged Access Management (PAM) solutions
  • Implementing encryption solutions
  • Proven experience in analyzing, optimizing, and documenting security processes and governance.
  • Proven experience with security management techniques and frameworks, such as:
  • ISO 27000 series
  • COBIT for Security
  • NIST
  • OWASP
  • CIS Critical Security Controls
  • Demonstrable knowledge and certifications relevant to the area of expertise (e.g., CISM, CISSP, CEH).

Language requirement: Native-level Dutch (CEFR C2).

Skills & Requirements

Must-Have

  • Minimum 3 years of experience as a Cybersecurity Analyst in Vulnerability Management, including:
  • Vulnerability identification
  • Validation
  • Risk-based prioritization
  • Remediation follow-up
  • Minimum 3 years of experience as a Security Consultant in data, infrastructure, application security, or similar environments.
  • Proven experience in analyzing, optimizing, and documenting security processes and governance.
  • Proven experience with Python scripting and automation, including:
  • API integrations
  • Data processing
  • Automated reporting
  • Minimum 3 years of experience with vulnerability scanning and exposure management solutions, including configuration, execution, and interpretation of scans.
  • Proven expertise in a specific information security domain.

Preferred (Should-Have)

  • Minimum 3 years of experience translating technical findings into reports and recommendations for both technical and non-technical audiences.
  • Minimum 3 years of experience with ticketing and workflow systems used for vulnerability and remediation tracking, such as:
  • Jira
  • ServiceNow
  • Experience with security management frameworks such as ISO 27000, COBIT, NIST, OWASP, and CIS Controls.
  • Relevant security certifications such as CISM, CISSP, CEH, or equivalent.

Nice-to-Have

  • Minimum 3 years of experience with cyber awareness programs and phishing simulation initiatives.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all