Cyber Security Engineer

Il y a 3 heures

Brussels, Brussels, Belgique Tata Consultancy Services Temps plein

Location: Brussels, Belgium

Company: Tata Consultancy Services (TCS) Belgium

Employment Type: Full-time


Nature of the tasks

  • Develop and implement security policies and procedures.
  • Define, implement and monitor security plans.
  • Guide development teams throughout the Software Development Lifecycle (SDLC) to build and operate software securely, following EC standards and industry best practices (e.g., OWASP Top 10).
  • Conduct security inspections, code reviews, and risk assessments for internally developed as well as SaaS (Software-as-a-Service) applications.
  • Monitor systems for security breaches and incidents.
  • Analyse and respond to security threats and vulnerabilities, including managing the remediation process through to closure.
  • Design and deploy security solutions and technologies for internal EC Data Centre and Cloud environments.
  • Collaborate with IT and business teams to ensure compliance with security standards.
  • Ensure data protection and privacy through encryption and access controls.
  • Conduct security training and awareness programs for staff.
  • Prepare incident response plans and conduct simulations.
  • Stay updated on the latest security trends and emerging threats.
  • Perform regular vulnerability assessments and penetration tests using automated tools and manual techniques to identify and prioritize security weaknesses.
  • Manage and configure security tools, including SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), firewalls, and intrusion detection/prevention systems.
  • Lead the response to security incidents, including containment, eradication, recovery, and post-incident analysis and reporting.


Specific expertise and technologies

  • Proficiency in cybersecurity domains (network, application, endpoint, cloud).
  • Experience with integrating security into DevSecOps pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and software supply chain security tools.
  • Understanding of secure coding practices in languages (Java, Python, JavaScript) and knowledge of common vulnerabilities (e.g., OWASP Top 10).
  • Knowledge of encryption protocols and technologies (e.g., TLS/SSL, IPSec, AES, RSA, PKI).
  • Experience with SIEM platforms (e.g., Splunk, ELK, Microsoft Sentinel).
  • Expertise in vulnerability assessment and penetration testing methodologies and tools (e.g., Nessus, Qualys, Burp Suite, Metasploit, OWASP ZAP).
  • Knowledge of IAM/IGA platforms (e.g., Okta, Azure AD, SailPoint), MFA and SSO.
  • Experience with cloud security architectures and controls.
  • Familiarity with regulatory compliance standards like GDPR, HIPAA, and PCI-DSS.
  • Proficiency in scripting or programming languages for automation and monitoring.
  • Knowledge of ISO/IEC 27001 and ISO/IEC 27005 standards.
  • Experience with endpoint detection and response (EDR) tools and network security monitoring (NSM).
  • Knowledge of threat intelligence platforms and threat modelling methodologies.


Minimum level of expertise

Normal

Mandatory for ‘Normal’ level:

  • One of the following or an equivalent certification:
  • CISSP (Certified Information Systems Security Professional)
  • CISM
  • CCSP


Optional for ‘Normal’ level:

  • Cloud and vendor-specific certifications.


Senior

Mandatory for ‘Senior’ level:

  • One of the following or an equivalent certification:
  • CISSP-ISSAP
  • GIAC advanced credential (e.g., GCIH, GCIA)
  • OSCP (Offensive Security Certified Professional)

Optional for ‘Senior’ level:

  • Cloud expert certifications.


Skills

  • Ability to analyse complex and design effective solutions.
  • Talent for attention to detail in code correctness, error handling, and documentation.
  • Ability to anticipate future threats and evaluate trends.
  • Ethical judgment and integrity.
  • Continuous learning and adaptability to emerging security trends.
  • Capability to educate and train others on security practices.
  • Ability to participate in multilingual meetings.
  • Ability to understand, speak and write English, optionally French as an additional asset.
  • Excellent interpersonal and communication skills.
  • Ability to work in a team as well as autonomously.
  • Results-oriented mindset, focused on delivering results.