Expert in DevSecOps
il y a 12 heures
DESCRIPTION OF THE TASKS
The following tasks shall be covered by the service contract: Advise and Support as a subject Matter Expert in the field of DevSecOps. On top of this task, the candidate will contribute to: Security services development: Participate in the efforts towards developing and improving the service in its growing scope and coverage among DG CONNECT;
Perform analysis, design and implementation of the workflows and organisational processes for the functioning of the Security Team, the service delivery to DG CONNECT and the interaction with the related services within or outside of the DG; Analyse the requirements resulting from the IT security policy framework in force and from the IT security threat landscape, taking into account the expectations of the business owners; Assessment of the level of the implementation of security processes on the corporate level, contribution to defining associated indicators and dashboards and contribution to reporting; Contribution to the initiatives facilitating the adoption and implementation of the processes and methodologies among the stakeholders (presentations, targeted consultancy sessions, case-specific hands- on assistance sessions); Interfacing with IT security stakeholders, monitoring and advice in the implementation of security processes and measures (including the DevSecOps pipelines and associated processes).
Security Advisory and Support
Initiation and follow up of IT security risk assessment and security plans of information systems; Advice regarding IT security related issues, including vulnerability management; Reporting on a regular basis to the hierarchy regarding IT security, shortfalls identified and ideas for improvement.
Training and awareness raising
Initiation and promotion of specific IT security related awareness-raising and training programmes; Promote Cyber Aware programme and the related educational material.
Key Responsibilities
• Lead cybersecurity advisory services, including security by design, vulnerability management, security testing, incident management, and continuous improvement.
• Engage with business/systems owners and hierarchy, delivering strategic insights on cybersecurity risks and mitigation strategies.
• Perform IT Security Risk Management and Treatment, including identification of assets, business impact assessments, risk identification, risk calculations and implementation of defined treatment measures
• Draft IT security plans and follow implementation actions
• Develop and implement IT security services, including architecture design, GRC compliance strategies, and policy development.
• Contribute to the design and execution of cybersecurity frameworks in alignment with NIST CSF, ISO 27001, CIS Controls, and NIS2 Directive.
• Perform cybersecurity risk assessments, incident management, and continuous improvement activities.
• Contribute to the implementation of GRC and Policy Compliance in ServiceNow environments.
• Deliver cybersecurity awareness sessions to improve security culture across diverse stakeholder groups.
• Lead and integrate DevSecOps practices into security architecture, ensuring security is embedded in every phase of the software development lifecycle.
• Design and implement secure CI/CD pipelines, automate security testing, and promote security as code principles.
• Support on the data goverance and data security in collaboration with the Data Protection Coordinator
• Work with third-party suppliers to ensure penetration testing, vulnerability assessments, IAM and operational resilience testing meet relevant standards.
• Collaborate with the business to embed security-by-design into processes of buidling new systems
• Apply industry-standard threat modeling methodologies to analyze system architectures, detect security weaknesses, and enhance overall risk management strategies.
LEVEL OF EDUCATION
As stated in the Article 2.6.3.1. of DIGIT-TM II Service requirements, a minimum educational qualification for lot 3 is: Level of education corresponding to Level 7 of the European Qualification Framework which typically corresponds to a master degree.
KNOWLEDGE AND SKILLS
Following skills and knowledge are required for the performance of the above listed tasks:
• Minimum 7 years experience in Cybersecurity Strategy: define objectives and build roadmaps.
• Minimum 7 years experience in architecting Cloud, Application or Network solutions.
• Minimum 7 years experience risk identification and Risk management Methodologies, such as ITSRM², ISO27005.
• Minimum 5 Governance, Risk and Compliance (GRC) and tools such as ServiceNow.
• Good knowledge about the European cyber regulations, such as GDPR, NIS2, cybersecurity strategy, EU Cybersecurity Act.
• Good knowledge of framework: ISO27001, ISO 27005, NIST SCF, NIST 800-53, CIS Controls…
• Previous experience as Business development manager or product manager.
• Experience in managing risk from a 3rd party service provider, including cloud vendors.
• Strong drafting and communication skills in English both orally and in writing (level C1);
• Self-motivated and autonomous, with ability to manage and follow up on multiple tasks simultaneously;
• Proven ability to communicate complex cybersecurity issues effectively to senior management, supporting informed decision-making and strategic risk management.
• Expertise in creating executive-level cybersecurity reports, highlighting key risk indicators, compliance status, and security performance metrics.
• Strong analytical skills, ability to approach problems from multiple angles and find creative solutions;
• Ability to produce mature executive summaries, presentations and to engage with stakeholders at any levels, from operational staff to senior management;
• Proven capacity to analyse complex information, to consider options in a clear and structured way, to propose and implement recommendations and to make sound decisions;
• Ability to work effectively both with team members and with customers;
• Ability to work under pressure and with tight deadlines, to make timely decisions, to reprioritize tasks responding to changes in a rapidly evolving work environment;
• Ability to develop and set up processes and structures across various fields of activities; Strong ability to learn and apply new/emerging technologies.
SPECIFIC EXPERTISE
Following specific expertise is mandatory for the performance of tasks:
• Client operating systems, Windows, Linux
• Experience with large, enterprise-level multi-user Information Systems, network and application security
• Good knowledge with DevOps container or serverless /orchestration tools (ie: Docker, Ansible, Containers, Kubernetes, etc.)
• Experience with Fortify, SonarQube, GitLab etc
• Good knowledge with cloud security architecture and security requirements
• Good knowledge with Threat Modelling in cloud environment
• Good knowledge with Cloud governance and compliance: AWS, Azure, and SaaS
• Good knowledge with Security and Privacy by design, in the cloud.
• Good knowledge with Monitoring tools (Splunk, Dynatrace, etc.)
• Good knowledge in the Cloud (Aws, Azure, Google, etc.)
• Good knowledge with designing cloud security architecture best practices.
• Good knowledge with Designing and implementing the organization's cloud usage practices, including rules and standards
• Good knowledge with applying cloud service providers security practices, compliance.
• Knowledge on Enterprise Architectures methodology: such as TOGAF or SABSA
• Experience with Digital Transformation activities
• at least 4 years of specific expertise in providing cybersecurity advisory to international organizations.
• at least 5 years of specific expertise in in a relevant position within Cybersecurity security, risk management, IT consultancy or IT audit.
CERTIFICATIONS & STANDARDS
Following certificates & standards are required for the performance of tasks:
Minimum mandatory number of months of experience per area of expertise
Information Security Certifications such as CISM = 40
Risk Management certification, such as CRISC, ISO 27005 RM = 40
Cloud Security certification such as CCSP, GCLD, = 30
Cybersecurity Certification: Ethical Hacker C|EH, GCIH = 30
ISO27005 12 Governance Framework, such as COBIT = 12
Following certificates & standards would be advantageous for the performance of tasks:
Minimum mandatory number of months of experience per area of expertise
Network Security certification, Such as CCNP, CCSP = 48
-
Expert in Devsecops
il y a 4 jours
Brussels, Belgique Sword Technologies S.A. Temps plein**Key Responsibilities**: - Operate and maintain the Business Rule service within the **Compass Corporate** environments. - Provide expert advice to business developers on writing and optimizing business rules. - Define technical recommendations for real-time business rule use cases. - Offer expertise in **CI/CD pipeline** configuration and Business Rule...
-
Devsecops Specialist
il y a 1 jour
Brussels, Belgique WESTPOLE Belgium Temps pleinWESTPOLE is looking for Experts in DevSecOps of all different levels to work on different projects of the most renown European Institution in Belgium. **As a IT Consultant and specialist, you will**: Plan, implement, upgrade DevSecOps pipelines Promote the usage of DevSecOps methodologies for IT projects. Architect and design API Security, Container...
-
Devsecops Expert
il y a 4 semaines
Brussels, Belgique EUROPEAN DYNAMICS Temps plein**Your tasks**: - Plan, implement, upgrade DevSecOps pipelines; - Design DevSecOps API Security, Container Security and/or Cloud Security; - Understanding of the integration strategies and patterns in cloud environments; - Define configuration management and deployment strategies for Cloud resources; - Develop, and design software automation and scripts to...
-
Expert in Devsecops
il y a 1 semaine
Brussels, Belgique Seidor Temps pleinWe are on the lookout for a**Expert in**DevSecOps** (DSO)**to join our team for working with European Institutions based in** Brussels** in an **on site** position**.** **Get to know us - SEIDOR** At SEIDOR, we drive client transformation and competitiveness with cutting-edge technology and innovation, with a relentless focus on the human element and a...
-
Devsecops Expert
il y a 4 semaines
Brussels, Belgique Leonardo Belgium Temps plein**Leonardo Belgium** is seeking a talented **DevSecOps Expert**to join our team in delivering essential services under a framework contract. This opportunity is designed for professionals who are eager to contribute to** impactful projects**that enhance digital **security solutions** within the context of **European institutions.** **Job Specifications** -...
-
Expert in Devsecops
il y a 4 semaines
Brussels, Belgique The White Team Temps plein**Duties & Role**: - Plan, implement, upgrade DevSecOps pipelines - Promote the usage of DevSecOps methodologies for IT projects - Architect and design API Security, Container Security, Cloud Security **Skill, Knowledge & Experience**: - Relevant experience in years/months: 7-10. - Rapid self-starting capability and experience in team working. - Excellent...
-
Devsecops Expert
il y a 4 semaines
Brussels, Belgique EUROPEAN DYNAMICS Temps plein**Your tasks** - Manage deployments in Acceptance (ACC) and Production (PROD) environments; - Work closely with Development, QA, and DevSecOps teams to ensure smooth deployments; - Monitor system performance and proactively address potential issues; - Manage server, storage, and network configurations; - Maintain an incident log and prepare incident...
-
Expert in Devsecops
il y a 4 semaines
Brussels, Belgique Seidor Temps pleinWe are on the lookout for a/an** Expert in DevSecOps** **to join our team for working with European Institutions based in** **Brussels** in an **near site** position**.** **Get to know us - SEIDOR** At SEIDOR, we drive client transformation and competitiveness with cutting-edge technology and innovation, with a relentless focus on the human element and a...
-
Expert DevSecOps
il y a 2 semaines
Brussels, Belgique Talan Temps pleinExpert DevSecOps - European InstitutionsTalan is an international consulting and technology expertise group that accelerates its clients' transformation through innovation, technology, and data. For over 20 years, Talan has been advising and supporting companies and public institutions in implementing their transformation and innovation projects in France...
-
Expert Java Securite Informatique
il y a 1 jour
Brussels, Belgique EMGS CONSULTING Temps pleinMise en ?uvre de pratiques sécuriséesSensibilisation et formation: Sensibiliser les équipes aux bonnes pratiques de sécurité applicative. Former les développeurs à identifier et corriger les vulnérabilités de sécurité. **Intégration d?outils de sécurité**: Intégrer des outils de détection de vulnérabilités (SAST, DAST, etc.) dans les...
-
Senior .Net developer DevSecOps
il y a 3 semaines
Brussels, Belgique Infrabel Temps pleinAls senior .Net developer zal je deel uitmaken van het team verantwoordelijk voor het implementeren van DevSecOps en Lean IT principes in de levenscyclus van onze ICT-oplossingen. De focus ligt op het Cyber-weerbaarder maken van onze ICT oplossingen, het automatiseren, het elimineren van activiteiten met weinig tot geen toegevoegde waarde en het samenbrengen...
-
Senior .Net developer DevSecOps
il y a 3 semaines
Brussels, Belgique Infrabel Temps pleinStudieniveau: Bachelor-niveau of gelijkwaardigAls senior .Net developer zal je deel uitmaken van het team verantwoordelijk voor het implementeren van DevSecOps en Lean IT principes in de levenscyclus van onze ICT-oplossingen. De focus ligt op het Cyber-weerbaarder maken van onze ICT oplossingen, het automatiseren, het elimineren van activiteiten met weinig...
-
Security DevOps Expert
il y a 2 jours
Brussels, Belgique Penguin Formula Temps pleinCompany Description We Cook iT is an international software house that delivers software development to its corporate customers by providing highly skilled, communicative IT professionals to build their customized products through outsourcing, nearshoring and turn-key projects’ solutions. How do we differentiate ourselves? By investing in the...
-
Security DevOps Expert
Il y a 53 minutes
Brussels, Belgique Penguin Formula Temps pleinCompany Description We Cook iT is an international software house that delivers software development to its corporate customers by providing highly skilled, communicative IT professionals to build their customized products through outsourcing, nearshoring and turn-key projects’ solutions. How do we differentiate ourselves? By investing in the...
-
Full-Stack Java/Angular Developer
il y a 7 jours
Brussels Metropolitan Area, Belgique Indra Temps pleinFull-Stack Java/Angular Developer for European InstitutionsFor the European Institutions, we are currently looking for an experienced Full-Stack Java/Angular Developer to join their team on a freelance basis. This role involves supporting complex projects with a focus on both frontend and backend solutions, particularly in Java and Angular, with an emphasis...
-
Devsecops Online Since: 06-07-2022 Nr. 2361
il y a 4 semaines
Brussels, Belgique Harvey Nash Temps pleinYou will work in in the DEVSECOPS team which focuses on the automation of the software delivery chain with security embedded What you'll do - Prepare the procedures and automation for deployment of software (own development, operating systems, utility software etc.) including the necessary tools to monitor the install base. - Prepare the procedures and...
-
IT Consultant, Devsecops Specialist
il y a 4 semaines
Brussels, Belgique The White Team Temps plein**Job requirements (Hybrid position)**: - Shall possess at least Bachelor Degree in computer science (or a closely related topic), or 5 years of professional experience; (LA2.9) - Shall be fluent in English (oral and written); (LA2.9) - Shall have at least two years of experience in providing consultancy or trainings in the Agile/DevSecOps domains;...
-
Regional Manager-Cloud Advisory
il y a 12 heures
Brussels Metropolitan Area, Belgique Tata Consultancy Services Temps pleinTata Consultancy Services (TCS) is a global leader in IT services, digital, and business solutions that partners with its clients to simplify, strengthen and transform their businesses. We ensure the highest levels of certainty and satisfaction through a deep-set commitment to our clients, comprehensive industry expertise, and a global network of innovation...
-
Regional Manager-Cloud Advisory
il y a 3 jours
Brussels Metropolitan Area, Belgique Tata Consultancy Services Temps pleinTata Consultancy Services (TCS) is a global leader in IT services, digital, and business solutions that partners with its clients to simplify, strengthen and transform their businesses. We ensure the highest levels of certainty and satisfaction through a deep-set commitment to our clients, comprehensive industry expertise, and a global network of innovation...
-
Freelance Data Kwaliteit Expert
il y a 2 semaines
Brussels Metropolitan Area, Belgique Cegeka Temps pleinVacature: Freelance Data Kwaliteit Expert @ VDABVoor VDAB zijn we op zoek naar een ervaren Data Kwaliteit Expert die een overkoepelende visie, strategie en framework kan uitwerken rond datakwaliteit.Jouw verantwoordelijkheden:Ontwikkelen van een strategische visie en doelarchitectuur waarin datakwaliteit centraal staat.Opstellen van een meerjaren roadmap met...