> Markdown version of [/jobs/ext/3174046-cyber-security-engineer-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/3174046-cyber-security-engineer-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - Vulnerability Management - **Company:** Spektrum - **Location:** Bergen, Belgium - **Experience:** Experienced - **Contract:** Contract - **Skills:** Cyber Security, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), NumPy, Windows PowerShell, Software Vulnerability Management, Data Processing, Scripting, Pandas, Tenable Nessus, Qualys, Vulnerability Analysis - **Published:** September 2, 2026 - **Apply:** https://be.indeed.com/viewjob?jk=3d87a6dc4bb08cba ## About the Role * At least 5 years of practical experience in vulnerability management, with proven experience within the last 6 months; * At least 3 years of experience in testing and validating that contracted deliveries meet the security requirements and fulfil the intended use cases; * General knowledge of cyber security principles, best practices, concepts and technology; * Knowledge of cyber security architectures, including boundary protection, encryption, identity and access management, monitoring and detection, incident response, vulnerability assessments and risk management; * Practical experience with vulnerability scanners and their output formats, such as Tenable Nessus, Qualys or OpenVAS; * Demonstrated experience in producing remediation action plans and coordinating their implementation with system administrators across multiple sites. Skills: * Ability to interpret complex technical findings and to translate them into actionable remediation guidance for system administrators; * Scripting proficiency in Python (Pandas/NumPy) or PowerShell for parsing scan results and automating data handling; * Ability to take ownership of tasks and strong motivation to accomplish them to the end, working both independently and within a team; * Very good communication, analytical and writing skills; Training/certifications: * Relevant certifications in cyber security, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or GIAC Security certifications. Desirable Skills, Experience and Certifications * Familiarity with NATO security policy and supporting directives; * Experience in working for or supporting a military or * governmental organization. Education * A minimum requirement of a Bachelor's degree at a nationally recognised/certified University in a related discipline and 3 years post-related experience, or exceptionally, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience that is/are of interest to NCIA, that is, at least 10 years extensive and progressive expertise in duties related to those in this Statement of Work. Language Proficiency * Business English, * Valid National or NATO Secret personal security clearance ## Description + Analyse the results of the vulnerability assessments when a new assessment is available. + Prepare, for every assessment report, a remediation action plan and provide it to the appropriate technical point of contact not later than two working days after release of the assessment report; + Interpret complex technical findings and provide remediation support to system administrators; + Assess the technical impact of the vulnerabilities in order to prioritise remediation, for all remediation plans being tracked; + Support vulnerability monitoring activities: review newly and publicly disclosed vulnerabilities and support the team in the preparation of NATO Security Bulletins. * Perform remediation tracking and site coordination, including but not limited to: + Act as the technical point of contact for remediation towards site administrators and system owners; + Monitor and maintain the tracking of remediation activities for all open findings; + Produce weekly and monthly progress reports for the various stakeholders; + Chair technical coordination meetings with site administrators in order to resolve remediation roadblocks. * Report on remediation status and support governance activities, including but not limited to: + Brief the monthly Enterprise Vulnerability Assessment Plan (EVAP) meeting, presenting the progress of the remediation activities; + Participate in status update meetings, activity planning meetings and other meetings as instructed, on site or via conference call capabilities; + Provide, at the end of the period of performance, a closure report summarising at high level the activities carried out. * Execute coordination and information gathering activities within NCSC, NCIA and with stakeholders at the supported NATO sites, in support of the above activities. ## Related Videos - [Vectorize all the things! Using linear algebra and NumPy to make your Python code lightning fast.](https://www.wearedevelopers.com/videos/562-vectorize-all-the-things-using-linear-algebra-and-numpy-to-make-your-python-code-lightning-fast) - [Advanced Typing in TypeScript](https://www.wearedevelopers.com/videos/496-advanced-typing-in-typescript) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to implement convenient Python bindings to C++](https://www.wearedevelopers.com/videos/618-how-to-implement-convenient-python-bindings-to-c) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)