> Markdown version of [/jobs/ext/2855329-cybersecurity-analyst-vulnerability-attack-surface-management](https://www.wearedevelopers.com/jobs/ext/2855329-cybersecurity-analyst-vulnerability-attack-surface-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst Vulnerability & Attack Surface Management - **Company:** Harvey Nash - **Location:** Brussels Metropolitan Area, Belgium - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Data Analysis, Software System Penetration Testing, JIRA, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, Python (Programming Language), Open Web Application Security, Phishing, Software Vulnerability Management, Data Processing, Scripting, Software Security, CIS Benchmarks, Api Management, Servicenow, Vulnerability Analysis - **Published:** September 12, 2026 - **Apply:** https://www.adzuna.be/details/5879869573 ## About the Role * Proven experience as a Security Consultant within one or more of the following domains: data, infrastructure, applications, or related environments. * Demonstrated expertise in a specific area of information security, such as: * Implementing information security management processes * Conducting vulnerability assessments and penetration testing * Improving application security through cost-effective measures * Implementing Privileged Access Management (PAM) solutions * Implementing encryption solutions * Proven experience in analyzing, optimizing, and documenting security processes and governance. * Proven experience with security management techniques and frameworks, such as: * ISO 27000 series * COBIT for Security * NIST * OWASP * CIS Critical Security Controls * Demonstrable knowledge and certifications relevant to the area of expertise (e.g., CISM, CISSP, CEH). Language requirement: Native-level Dutch (CEFR C2). Skills & Requirements Must-Have * Minimum 3 years of experience as a Cybersecurity Analyst in Vulnerability Management, including: * Vulnerability identification * Validation * Risk-based prioritization * Remediation follow-up * Minimum 3 years of experience as a Security Consultant in data, infrastructure, application security, or similar environments. * Proven experience in analyzing, optimizing, and documenting security processes and governance. * Proven experience with Python scripting and automation, including: * API integrations * Data processing * Automated reporting * Minimum 3 years of experience with vulnerability scanning and exposure management solutions, including configuration, execution, and interpretation of scans. * Proven expertise in a specific information security domain. Preferred (Should-Have) * Minimum 3 years of experience translating technical findings into reports and recommendations for both technical and non-technical audiences. * Minimum 3 years of experience with ticketing and workflow systems used for vulnerability and remediation tracking, such as: * Jira * ServiceNow * Experience with security management frameworks such as ISO 27000, COBIT, NIST, OWASP, and CIS Controls. * Relevant security certifications such as CISM, CISSP, CEH, or equivalent. Nice-to-Have * Minimum 3 years of experience with cyber awareness programs and phishing simulation initiatives. ## Description As a Cybersecurity Analyst - Vulnerability & Attack Surface Management, you will support the further development, execution, and optimization of services related to vulnerability management, attack surface management, and cyber awareness. You will analyze, assess, and follow up on information regarding vulnerabilities, exposed systems, and security risks. You will validate findings, place them in the appropriate risk context, and translate them into concrete recommendations. In doing so, you will support our client's entities and local authorities in prioritizing and tracking remediation actions. Automation is an essential part of the role. Given the large volume of sources, data, and stakeholders involved, you will develop and maintain scripts, primarily in Python, as well as integrations that support the collection, enrichment, correlation, follow-up, and reporting of vulnerability information. You will work closely with internal teams, external service providers, and representatives of our client's entities and local authorities. Your objective is to ensure vulnerabilities and exposed systems are identified and communicated in a timely manner, together with actionable recommendations, enabling organizations to effectively remediate identified risks. In addition, you will support initiatives related to cyber awareness and phishing simulations. This is primarily an operational and support-oriented role, combining technical expertise with a strong hands-on focus. Besides analyzing and following up on cases, you will play an active role in the day-to-day delivery of the service and contribute to the further professionalization of processes, methodologies, and supporting solutions., * Analyze vulnerabilities and exposures based on a variety of information sources. * Validate findings, filter out noise and false positives, and assess the actual impact on affected organizations. * Prioritize findings based on risk, considering factors such as CVSS scores, EPSS scores, exploitation status, and organizational context. * Derive both overarching trends and organization-specific recommendations from analyzed data. * Communicate findings through existing reporting and communication channels tailored to the relevant target audiences. * Develop and maintain Python scripts and API integrations for data collection, enrichment, correlation, and reporting. * Support our client and local authorities in tracking remediation activities. * Assist in the preparation, execution, and evaluation of cyber awareness initiatives and phishing simulations. * Contribute to the documentation, standardization, and continuous improvement of processes, methodologies, and supporting solutions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [The Netherlands – Europe’s powerhouse for software development?](https://www.wearedevelopers.com/magazine/31-the-netherlands-europe-s-powerhouse-for-software-development) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam)