> Markdown version of [/jobs/ext/2869971-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/2869971-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - **Company:** Onesource Consulting - **Location:** Brussel, Belgium - **Contract:** Permanent contract - **Skills:** JIRA, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, Python (Programming Language), Open Web Application Security, Phishing, Software Vulnerability Management, Web Platforms, Data Processing, Cloud Platform System, Software Security, Cyber Warfare, Api Management, Servicenow, Vulnerability Analysis - **Published:** September 13, 2026 - **Apply:** https://www.adzuna.be/details/5881106318 ## About the Role * Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, ... * Demonstrable expertise in specific knowledge domain of information security (e.g. implementing information security management processes, performing vulnerability analyses and pen tests, optimizing application security through cost-effective * Demonstrated experience in analyzing, optimizing and documenting security processes and governance * Demonstrated experience in security management techniques and/or frameworks (e.g.: ISO27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense) * Demonstrable knowledge and experience via certificates depending on domain of expertise (e.g. CISM, CISSP, CEH). * Language requirement: Dutch at European CEFR - level C2. SKILLS MUST HAVE: * Demonstrable experience as a cybersecurity analyst in vulnerability management: identification, validation, risk-based prioritization and follow-up of remediation. * Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, . * Proven experience in analyzing, optimizing and documenting security processes and governance * Proven experience with scripting and automation in Python: API integrations, data processing, and automated reporting. * Proven experience with vulnerability scanning and exposure management solutions, including configuration, execution and interpretation of scans. * Demonstrable expertise in a specific knowledge domain of information security * Upload document NDA signed. * Language requirement: Dutch at European CEFR - level C2. SHOULD HAVE: * Demonstrable experience in translating technical findings into reporting and recommendations for both technical and non-technical target groups. * Proven experience with ticketing and workflow systems for the follow-up of findings and remediation actions (e.g. Jira, ServiceNow). * Demonstrable experience with security management techniques and/or frameworks. (bv: ISO27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense). * Demonstrable knowledge and experience via certificates depending on domain of expertise (e.g. CISM, CISSP, CEH). * Proven experience with cyber awareness programs and phishing simulations. ## Description * You will work within the Flemish Centre for Digital Security (VCDV), part of Client. The VCDV acts as the central expertise centre for digital security within the Flemish government and supports both Flemish entities and local authorities with expertise, services and coordination on cybersecurity. * Within this context, a structural service is being developed, with the aim of identifying vulnerabilities in a timely manner and supporting organisations within the Flemish government and local authorities in strengthening their digital security. TECHNICAL CONTEXT: * The technical environment in which these services are offered is very diverse and includes a variety of technologies, platforms and architectures that are used within the Flemish government and by local authorities. The service must therefore be applicable to a wide spectrum of applications, infrastructures, cloud environments and digital platforms. * Given this variety of solutions and the size of the data volumes and target groups to be processed, maximum integration and automation of the work processes is essential. You are therefore expected to be able to independently set up and maintain automation solutions. * As a Cybersecurity Analyst Vulnerability & Attack Surface Management, you will support the further development, implementation and optimisation of the services related to vulnerability management, attack surface management and cyber awareness within the Flemish government. * You analyze, assess and follow up on information about vulnerabilities, exposed systems and security risks. You validate findings, place them in their risk context and translate them into concrete recommendations. In doing so, you will support Flemish entities and local authorities in prioritising and following up on remediation actions. * Automation is an essential part of the job. Given the volume of sources, data, and audiences, you'll develop and maintain scripts - primarily in Python - and integrations that support the collection, enrichment, correlation, follow-up, and reporting of vulnerability information. * You will work closely with internal teams, external service providers and representatives of Flemish entities and local authorities. You provide timely insight into vulnerabilities and exposed systems and provide the corresponding recommendations, so that the organisations involved can remediate in a targeted manner. * In addition, you also support initiatives around cyber awareness and phishing simulations. * The position is executive and supportive in nature and combines substantive expertise with a strong operational focus. In addition to the analysis and follow-up of files, you will take an active role in the daily operation of the service and contribute to the further professionalization of processes, working methods and supporting solutions. CORE TASKS * Analyzing vulnerabilities and exposures based on a variety of sources. * Validating findings, filtering noise and false positives, and estimating the real impact for the organizations involved. * Risk-based prioritization of findings based on CVSS, EPSS, operating status and organizational context, among other things. * Distilling overarching findings and trends as well as organization-specific recommendations from the analyzed information. * To make this information accessible through the existing reporting and communication channels, tailored to the target groups involved. * Developing and maintaining scripts and API integrations (Python) for data collection, enrichment, correlation and reporting. * Supporting Flemish entities and local authorities in the follow-up of remediation actions. * Helping to prepare, implement and discuss cyber awareness initiatives and phishing simulations. * Contributing to the documentation, standardization and continuous improvement of processes, working methods and supporting solutions. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)