Freelance / Consultant Opportunity – Vulnerability Lead
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
We are currently looking for an experienced Vulnerability Lead for a consulting assignment within the CISO Office of a large Belgian organization.
Have you got the right qualifications and skills for this job Find out below, and hit apply to be considered.
Brussels / Hybrid way of working (homeworking + onsite presence)
Full-time
Initial duration: 3 months, renewable
This is a senior role with real ownership of the organisation’s enterprise Vulnerability Management programme, covering on-premise infrastructure, cloud, workplace, applications and container environments.
Your role
You will act as the central Vulnerability Lead and drive the full vulnerability lifecycle: from identification and prioritisation through remediation, verification, reporting and exception management.
Key responsibilities include:
Governance & Reporting
- Act as the Vulnerability Management SPOC towards the CISO Office
- Prepare and maintain audit-ready evidence, including NIS2-related compliance
- Produce and present monthly Vulnerability Management reporting to senior security governance
- Define and continuously evolve the scope of the VM programme
Process & SLA Ownership
- Own and continuously improve the end-to-end Vulnerability Management process
- Define and maintain the VM RACI across internal teams and external partners
- Establish risk-based prioritisation based on:
- CVSS
- Exploitability
- Threat intelligence
- Business criticality
- Define and monitor remediation SLAs for Critical, High, Medium and Low vulnerabilities
- Define and track Vulnerability Management KPIs and KRIs
Remediation & Patching Coordination
- Work closely with Infrastructure, Cloud, Workplace, Application, SOC, Incident Response and business teams
- Drive remediation commitments and SLA compliance
- Monitor remediation performance across teams and environments
- Coordinate vulnerability detection and remediation across:
- Servers
- End-user devices
- Cloud environments
- Applications
- Containers
- Manage prioritisation conflicts between vulnerability risk and delivery capacity
Verification & Exception Management
- Track vulnerabilities through verified closure and remediation scanning
- Maintain a consolidated view of coverage, SLA attainment, ageing and end-of-life risks
- Own the vulnerability exception register
- Ensure every exception has:
- Appropriate compensating controls
- A clear accountable owner
- A defined expiry date
- Prepare exception cases for Risk Management governance
Awareness & Continuous Improvement
- Promote vulnerability management best practices across the organisation
- Help mature the overall vulnerability management capability and operating model
Your profile
5+ years of experience in Vulnerability Management and/or Patch Management with direct programme ownership
Strong knowledge of the Vulnerability Management Lifecycle
Strong understanding of CVSS, exploitability analysis and threat intelligence
Good understanding of enterprise infrastructure, networking, cloud and remediation processes
Hands-on experience with Qualys, AWS Inspector and Microsoft Defender Vulnerability Management
Experience in a large enterprise or public-sector environment, ideally with significant legacy systems and technical debt
Experience with AWS and Azure
Knowledge of container security
Familiarity with NIS2
Experience integrating Vulnerability Management with ITSM tools such as Jira and ServiceNow
Strong analytical, governance and reporting skills
Strong stakeholder management skills and ability to challenge remediation teams where needed
Languages
Fluent English required
Dutch and/or French is a strong plus
We are looking for someone who can combine security expertise, governance and hands-on programme ownership - someone capable of driving remediation across multiple technical teams rather than simply producing vulnerability reports. xlxgzvr
Int