Cyber Security Analyst
Onesource Consulting
Brussel, Belgium
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
Dutch
Job source
Tech stack
JIRA
Control Objectives for Information and Related Technology (COBIT)
Cyber Security
Information Security Management
Python (Programming Language)
Open Web Application Security
Phishing
Software Vulnerability Management
Web Platforms
Data Processing
Cloud Platform System
Software Security
+4 more
Cyber Warfare
Api Management
Servicenow
Vulnerability Analysis
Job description
- You will work within the Flemish Centre for Digital Security (VCDV), part of Client. The VCDV acts as the central expertise centre for digital security within the Flemish government and supports both Flemish entities and local authorities with expertise, services and coordination on cybersecurity.
- Within this context, a structural service is being developed, with the aim of identifying vulnerabilities in a timely manner and supporting organisations within the Flemish government and local authorities in strengthening their digital security.
TECHNICAL CONTEXT:
- The technical environment in which these services are offered is very diverse and includes a variety of technologies, platforms and architectures that are used within the Flemish government and by local authorities. The service must therefore be applicable to a wide spectrum of applications, infrastructures, cloud environments and digital platforms.
- Given this variety of solutions and the size of the data volumes and target groups to be processed, maximum integration and automation of the work processes is essential. You are therefore expected to be able to independently set up and maintain automation solutions.
- As a Cybersecurity Analyst Vulnerability & Attack Surface Management, you will support the further development, implementation and optimisation of the services related to vulnerability management, attack surface management and cyber awareness within the Flemish government.
- You analyze, assess and follow up on information about vulnerabilities, exposed systems and security risks. You validate findings, place them in their risk context and translate them into concrete recommendations. In doing so, you will support Flemish entities and local authorities in prioritising and following up on remediation actions.
- Automation is an essential part of the job. Given the volume of sources, data, and audiences, you’ll develop and maintain scripts - primarily in Python - and integrations that support the collection, enrichment, correlation, follow-up, and reporting of vulnerability information.
- You will work closely with internal teams, external service providers and representatives of Flemish entities and local authorities. You provide timely insight into vulnerabilities and exposed systems and provide the corresponding recommendations, so that the organisations involved can remediate in a targeted manner.
- In addition, you also support initiatives around cyber awareness and phishing simulations.
- The position is executive and supportive in nature and combines substantive expertise with a strong operational focus. In addition to the analysis and follow-up of files, you will take an active role in the daily operation of the service and contribute to the further professionalization of processes, working methods and supporting solutions.
CORE TASKS
- Analyzing vulnerabilities and exposures based on a variety of sources.
- Validating findings, filtering noise and false positives, and estimating the real impact for the organizations involved.
- Risk-based prioritization of findings based on CVSS, EPSS, operating status and organizational context, among other things.
- Distilling overarching findings and trends as well as organization-specific recommendations from the analyzed information.
- To make this information accessible through the existing reporting and communication channels, tailored to the target groups involved.
- Developing and maintaining scripts and API integrations (Python) for data collection, enrichment, correlation and reporting.
- Supporting Flemish entities and local authorities in the follow-up of remediation actions.
- Helping to prepare, implement and discuss cyber awareness initiatives and phishing simulations.
- Contributing to the documentation, standardization and continuous improvement of processes, working methods and supporting solutions.
Requirements
- Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, …
- Demonstrable expertise in specific knowledge domain of information security (e.g. implementing information security management processes, performing vulnerability analyses and pen tests, optimizing application security through cost-effective
- Demonstrated experience in analyzing, optimizing and documenting security processes and governance
- Demonstrated experience in security management techniques and/or frameworks (e.g.: ISO27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense)
- Demonstrable knowledge and experience via certificates depending on domain of expertise (e.g. CISM, CISSP, CEH).
- Language requirement: Dutch at European CEFR - level C2.
SKILLS
MUST HAVE:
- Demonstrable experience as a cybersecurity analyst in vulnerability management: identification, validation, risk-based prioritization and follow-up of remediation.
- Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, .
- Proven experience in analyzing, optimizing and documenting security processes and governance
- Proven experience with scripting and automation in Python: API integrations, data processing, and automated reporting.
- Proven experience with vulnerability scanning and exposure management solutions, including configuration, execution and interpretation of scans.
- Demonstrable expertise in a specific knowledge domain of information security
- Upload document NDA signed.
- Language requirement: Dutch at European CEFR - level C2.
SHOULD HAVE:
- Demonstrable experience in translating technical findings into reporting and recommendations for both technical and non-technical target groups.
- Proven experience with ticketing and workflow systems for the follow-up of findings and remediation actions (e.g. Jira, ServiceNow).
- Demonstrable experience with security management techniques and/or frameworks. (bv: ISO27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense).
- Demonstrable knowledge and experience via certificates depending on domain of expertise (e.g. CISM, CISSP, CEH).
- Proven experience with cyber awareness programs and phishing simulations.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
EM
Eli McGarvie
Best Companies in the Netherlands: Top 25 Companies in 2023Â
over 3 years ago
TL
Thomas Limbüchler
How to land a developer job in Amsterdam
over 5 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
LM
Luis Minvielle
The 12 Best Jobs for Software Engineers
over 2 years ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago