Incident Responder

il y a 2 semaines


Brussels, Belgique Vector Synergy Temps plein

**Location**:
Brussels, Belgium

**Security Clearance**:
EU Secret

**Introduction**:
Security Incident Handling aims at providing a safe communications and information infrastructure for the Contracting EU Institutions' (EU-Is’) user community and information systems by detecting, analysing, and responding to cyber-attacks and security incidents.

This service involves security incident detection, containment, eradication, and recovery by taking action to protect systems and networks affected or threatened by intruder activity, providing solutions and mitigation strategies from relevant advisories or alerts, and defining and executing responses plans and playbook entries. It also encompasses the set of standards, processes, tools, technology, and skilled staff to detect in the earliest stage and to efficiently respond to cyber-attacks and security incidents.

**Skills, knowledge, experience required**:

- At least 1 certification in the field of incident handling:

- GCIH (GIAC Certified Incident Handler);
- GCIA (GIAC Certified Intrusion Analyst);
- ECIH (EC-Council Certified Incident Handler);
- CSIH (SEI Certified Computer Security Incident Handler);
- SCPO (SABSA Certified Security Operations and Service Management Practitioner);
- Minimum 2 years’ experience in networking (TCP/IP, SNMP, DNS, Syslog-ng, etc.);
- Sound knowledge of and minimum 1 year of experience with IT security issues;
- Sound background and minimum 1 year of experience in the following areas:

- Operating system security and working with multiple operating systems;
- Anti-virus technologies;
- Network security:

- Practical level understanding of common TCP/IP-based services and protocols such as DNS, DHCP, HTTP, FTP, SSH, and SMTP;
- Firewall theory;
- Proxies and reverse proxies;
- Intrusion detection systems (IDS) and intrusion prevention systems (IPS);
- Full packet capture analysis;
- Vulnerability assessment and handling;
- Malware reverse engineering;
- Handling malicious code incidents;
- System (file and memory) and network forensics analysis with tools such as:

- Forensic Toolkit (FTK);
- EnCase Enterprise;
- Knowledge of development and scripting languages such as:

- Python;
- C/C++;
- Java;
- JavaScript;
- Perl or Ruby;
- Regular expressions;
- Linux shell/bash;
- MS Windows PowerShell;
- Minimum 1 year of experience with:

- EnCase Enterprise and EnCase Cybersecurity or FTK/AccessData (AD) Enterprise or Mandiant Intelligent Response (MIR);
- Volatility framework;
- SIFT Workstation or The Sleuth Kit (TSK).

**Desirable**:

- At least 1 certification among the following:

- GPEN (GIAC Certified Penetration Tester);
- GCED (GIAC Certified Enterprise Defender);
- GPPA (GIAC Certified Perimeter Protection Analyst);
- GCFE (GIAC Certified Forensic Examiner);
- GCFA (GIAC Certified Forensic Analyst);
- GNFA (GIAC Certified Network Forensic Analyst);
- CFCE (IACIS Certified Forensic Computer Examiner);
- CCFP (Certified Cyber Forensics Professional);
- SCMO (SABSA Certified Security Operations and Service Management Specialist);
- Minimum 1 year of experience with STIX (Structured Threat Information Expression) with a particular focus on the following related standards:

- CybOX (cyber observables);
- CAPEC (attack patterns);
- MAEC (malware);
- TAXII (threat information exchange).

**Duties/role**:

- Collecting from and correlating with information sources;
- Assessing incoming incident reports and performing efficient triage;
- Acknowledging alerts from/to the reporter;
- Confirming and classifying the incidents;
- Opening the incidents in the workflow system, identifying the stakeholders and notifying them;
- Assigning the case to the appropriate incident handlers and initiating the incident handling process;
- Providing continuous improvement of incident response plans and playbook entries;
- Defining and carrying out security incident identification measures;
- Overseeing the ongoing analysis activities (forensics or reverse engineering) and analysing data in order to build a comprehensive view of the incident;
- Maintaining and sharing incident documentation:

- Elaborating the map of the attacks/incidents with tools such as MS Visio and Maltego;
- Building a reliable timeline of the incident;
- Maintaining a situation report using relevant information sharing tool (i.e. web portal, wiki);
- Defining response strategy and presenting it to Management for approval:

- Identification, data collection and analysis;
- Containment;
- Eradication;
- Recovery;
- Defining and carrying out containment, eradication, and recovery measures;
- Providing technical assistance to all stakeholders;
- Coordinating incident response;
- Participating in cyber-crisis management and coordination:

- Preparing and maintaining action plans;
- Drafting meeting minutes and reports;
- Following up on the execution of actions decided by the Crisis Committee;
- Arranging crisis logistics, including meetings;
- Examining available information a


  • Incident Responder

    il y a 1 semaine


    Brussels, Belgique Vector Synergy Temps plein

    **Location**: Brussels, Belgium **Introduction**: Security Incident Handling aims at providing a safe communications and information infrastructure for the Contracting EU Institutions' (EU-Is’) user community and information systems by detecting, analysing, and responding to cyber-attacks and security incidents. This service involves security incident...

  • Incident Responder

    il y a 2 semaines


    Brussels, Belgique NRB Temps plein

    **Trasys International** offers IT Consulting jobs at the **European Institutions** and** International Organizations.** Your main responsibilities: - Collection from and correlation with information sources - Assess incoming incident reports and perform efficient triage. Acknowledge alerts from/to reporter - Confirm and classify the incidents; - Open an...

  • Incident Responder

    il y a 1 semaine


    Brussels, Belgique WDS Global Limited Temps plein

    **Job Type: Contract** **Job Location: Brussels** **Contract Rate: Euro 550 per day** **Contract Length: 12 Months with Multiple extensions** Job description: - 3 Years Incident Response experience - CSIRT Experience - Forensics experience - Conduct threat intelligence related tasks. Review existing threat intelligence reports and extract the relevant...

  • Incident Manager

    il y a 1 semaine


    Brussels, Belgique NVISO Temps plein

    Already experienced in the world of cyber security? New to it all, but genuinely interested? Well, at NVISO we might be looking for you and we’d love to have a chat! Who are we? **It all starts with the mission**: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private...

  • Cyber Security

    il y a 2 semaines


    Brussels, Belgique Proximus Group Temps plein

    A job at Proximus? You’ll find that everything revolves around the idea ‘Think Possible’. This means: we always assume that something is possible, even if it seems impossible. Well, especially so, actually. Call it a way of thinking that involves being open to a world of digital solutions that make our lives easier. And our way of working...

  • SOC Analyst

    il y a 2 semaines


    Brussels, Belgique Proximus Group Temps plein

    **Role description** The Cyber Security Incident Response Team is a centralized security service, responsible for managing cyber security incidents within the Proximus Group. The team is responsible for delivering all relevant services to mitigate an incident as quickly and efficient as possible and to keep (higher) management updated on the progress. As a...

  • SOC Analyst

    il y a 2 semaines


    Brussels, Belgique HNM Solution Temps plein

    **Description**: - We are currently looking for a motivated Junior SOC Analyst to join our team. - As a Junior SOC Analyst you will work with our experienced team of cybersecurity professionals to ensure the security of our systems. You are partly responsible for monitoring and analyzing security incidents, and taking the correct measures to prevent...

  • SOC Analyst

    il y a 2 semaines


    Brussels, Belgique Proximus Group Temps plein

    Join Proximus Ada ! Within this Proximus’ newly created center of excellence for AI and Cybersecurity, the mission of the Security Management and CSIRT teams is to protect Proximus, its customers, its business, its operations and reputation against external and internal threats. You will be fascinated by a highly dynamic environment, the strong...

  • Security Operations Engineer

    il y a 4 semaines


    Brussels, Belgique In4Matic Temps plein

    FunctionWe’re looking for a skilled security engineer to join our client’s team, where you'll play a key role in securing their infrastructure and optimizing security operations. If you have a passion for operational security, monitoring, and incident response, this is your chance to make a real impact!Your RoleYou’ll be responsible for installing,...

  • Cloud Security Officer

    il y a 1 semaine


    Brussels, Belgique Proximus Group Temps plein

    **Key Responsibilities** - **Cloud Security Strategy**: Develop and implement a comprehensive security strategy for major public cloud services (Azure, Google Cloud, AWS, etc.). - **Risk Assessment**: Conduct regular security assessments and risk analyses of cloud environments to identify vulnerabilities and recommend mitigation strategies. - **Compliance...

  • Service Desk Agent M/w/x

    il y a 1 semaine


    Brussels, Belgique CRONOS ITS Temps plein

    **Description de la fonction **Main tasks**: - Respond to requests for assistance received from end users by phone, mail or via other interactive platforms - for example : chat tools - etc (Fist-line customer liaison). - Diagnose and resolve technical hardware and software issues - Make an initial assessment of incidents, attempting to resolve them (Remote...

  • First Line Support

    il y a 1 semaine


    Brussels, Belgique Cronos Europa Temps plein

    **Main tasks**: - Respond to requests for assistance received from end users by phone, mail or via other interactive platforms - for example : chat tools - etc (Fist-line customer liaison). - Diagnose and resolve technical hardware and software issues - Make an initial assessment of incidents, attempting to resolve them (Remote user assistance) within...

  • Cybersecurity Specialist

    il y a 2 semaines


    Brussels, Belgique Uni Systems Temps plein

    Contribute to Security Management activities: - Draft policies, standards, guidelines - Contribute to performing market reviews, products analyses, studies - Contribute to user awareness programs - Contribute to defining architectures for security systems - Implement Security settings on various kinds of IT components Be an actor of the operational...


  • Brussels, Belgique Hamilton Barnes Associates Limited Temps plein

    Be part of a fast-growing data center company with a strong reputation for high-quality infrastructure and customer-focused services. Locally anchored but globally active, the organization connects seamlessly with software, locations, and suppliers, ensuring smooth operations without delay. Backed by a listed investment company focused on sustainable...

  • Security Operations Analyst

    il y a 4 semaines


    Brussels, Belgique Luminus Temps plein

    Are you ready to take on the challenge of protecting critical digital assets in an ever-evolving cybersecurity landscape? At Luminus, we’re looking for a proactive Security Operations Analyst to monitor, respond to, and prevent cybersecurity threats while driving innovation and collaboration. What You'll Do Monitor and respond to security events,...

  • Internal Support IT Engineer

    il y a 4 semaines


    Brussels, Belgique Select Human Resources n.v Temps plein

    IT Support Career OpportunityAs an Internal Support IT Engineer, you are the essential link ensuring the smooth operation of our dynamic IT organization. Join our team and contribute to the success of the company as a key member of the Level 1 ServiceDesk.Key Responsibilities:Level 1 ServiceDesk:Provide effective technical support to resolve IT...

  • Information Security Officer

    il y a 3 semaines


    Brussels, Belgique Luminus Temps plein

    **What will your mission be?** The Information Security Officer is responsible for assisting the implementation, operation, monitoring and administration of a variety of tools and processes to protect company information in accordance with the Information Security Program and related policies. **Which tasks will you be working on?** - Develops Information...


  • Brussels, Belgique Canonical - Jobs Temps plein

    This CISO role is for a global cybersecurity leader with a passion for Linux and open source to help define the way Canonical secures its corporate infrastructure, designs its products and assures regulatory compliance. This role will be responsible for the end to end definition and implementation of the cybersecurity and compliance program. They will...

  • Security Operations Analyst

    il y a 3 semaines


    Brussels, Belgique Luminus Temps plein

    Publicatiedatum: 22 augustus 2024 - Brussels - Contract open-end In today's landscape of escalating digital complexity and cybersecurity threats, a Security Operations Analyst plays a crucial role in safeguarding Luminus assets. The Security Operations Analyst is responsible for cyber incident response and the operations, monitoring and administration of a...


  • Brussels, Belgique Leonardo Belgium Temps plein

    On behalf of **ESA**, (the European Space Agency) **Leonardo Belgium** (LBe) is looking for a **Solutions Architect & Delivery Manager** that will have the **unique and exciting** opportunity to join **ESA**’s new Security Operations Centre (SOC) and contribute to the development of the** Cyber & Security Division** in the **Space & International Agencies...