> Markdown version of [/jobs/ext/3180955-security-engineer](https://www.wearedevelopers.com/jobs/ext/3180955-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** onetowin cvba - **Location:** Brussel, Belgium - **Contract:** Temporary contract - **Skills:** Active Directory, Software Documentation, Identity and Access Management, Microsoft Security Essentials, Windows Servers, Windows PowerShell, Role-Based Access Control, Splunk - **Published:** September 30, 2026 - **Apply:** https://onetowin.catsone.nl/careers/398/jobs/1050907-Security-Engineer/apply ## About the Role * Proven experience in Active Directory architecture, security, and hardening. * Strong expertise in Privileged Access Management (PAM) and Microsoft Tiering Model. * Proficiency with PowerShell, PingCastle, ADManager, and Splunk. * Familiarity with Privileged Access Workstations (PAWs), RBAC, and IAM integration. * Solid understanding of service account security and least privilege enforcement. Soft Skills: * Strong collaboration skills within multidisciplinary teams. * High documentation standards and structured working approach. * Analytical mindset, attention to detail, and communication clarity. * Ability to lead or participate in workshops (RBAC, PAM, governance design). ## Description * The mission covers all Active Directory forests and domains, as well as all processes and tools related to privileged access and identity governance. * Improve the PingCastle security score. * Support in selecting and Implementing new PAM Solution Main purposes 1. Active Directory Hardening * Assess and enhance the current security posture of Active Directory. * Identify and remediate key technical weaknesses detected by PingCastle. * Eliminate legacy components and protocols (e.g., Windows Server 2003/2008, DES-enabled accounts, NTLMv1, LM). * Implement secure authentication and password policies. * Review and clean up GPOs, apply least privilege principles, and align configurations with Microsoft security baselines. 2. Privileged Access Management (PAM) * Implement a structured PAM framework. * Enforce the Principle of Least Privilege (PoLP) and Role-Based Privilege Assignment. Implement Access Isolation. * Establish Periodic Access Reviews (e.g., quarterly). * Define and implement an Authorization Process (standardized, auditable approval workflow). * Implement Just-in-Time (JIT) Access for temporary privilege elevation. * Enforce the Four-Eyes Principle for critical privileged actions. 3. Documentation, Reporting, and Governance * Develop a detailed remediation and implementation roadmap (AD + PAM). * Document all technical actions (initial state, final configuration, scripts/tools used). * Deliver regular progress reports (weekly or bi-weekly). * Produce a final report summarizing actions, residual risks, and recommendations. Collaboration: The expert will operate as part of the Security Team, collaborating closely with AD administrators, IAM specialists, and infrastructure engineers. (Presence required 3 days on site and 2 days remote). Key Performance indicators * Achievement and improvement of the target PingCastle security score for Active Directory. * Successful and complete implementation and governance of the PAM framework components (e.g., PoLP, JIT, Four-Eyes Principle). * On-time delivery of AD/PAM remediation documentation and reports. * Contribution to the analysis and implementation of the Microsoft Tiering Model. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [MCP Mashups: How AI Agents are Reviving the Programmable Web](https://www.wearedevelopers.com/videos/1392-mcp-mashups-how-ai-agents-are-reviving-the-programmable-web) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Introducing Digital Samba Embedded Video Conferencing API MCP Server](https://www.wearedevelopers.com/videos/1640-introducing-digital-samba-embedded-video-conferencing-api-mcp-server) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)