Freelance / Consultant Opportunity – Vulnerability Lead

Il y a 5 heures

Brussels, Brussels, Belgique Distinctive Advisory Temps plein

We are currently looking for an experienced Vulnerability Lead for a consulting assignment within the CISO Office of a large Belgian organization.



Have you got the right qualifications and skills for this job Find out below, and hit apply to be considered.

Brussels / Hybrid way of working (homeworking + onsite presence)

Full-time

Initial duration: 3 months, renewable


This is a senior role with real ownership of the organisation’s enterprise Vulnerability Management programme, covering on-premise infrastructure, cloud, workplace, applications and container environments.


Your role

You will act as the central Vulnerability Lead and drive the full vulnerability lifecycle: from identification and prioritisation through remediation, verification, reporting and exception management.


Key responsibilities include:


Governance & Reporting

  • Act as the Vulnerability Management SPOC towards the CISO Office
  • Prepare and maintain audit-ready evidence, including NIS2-related compliance
  • Produce and present monthly Vulnerability Management reporting to senior security governance
  • Define and continuously evolve the scope of the VM programme


Process & SLA Ownership

  • Own and continuously improve the end-to-end Vulnerability Management process
  • Define and maintain the VM RACI across internal teams and external partners
  • Establish risk-based prioritisation based on:
  • CVSS
  • Exploitability
  • Threat intelligence
  • Business criticality
  • Define and monitor remediation SLAs for Critical, High, Medium and Low vulnerabilities
  • Define and track Vulnerability Management KPIs and KRIs


Remediation & Patching Coordination

  • Work closely with Infrastructure, Cloud, Workplace, Application, SOC, Incident Response and business teams
  • Drive remediation commitments and SLA compliance
  • Monitor remediation performance across teams and environments
  • Coordinate vulnerability detection and remediation across:
  • Servers
  • End-user devices
  • Cloud environments
  • Applications
  • Containers
  • Manage prioritisation conflicts between vulnerability risk and delivery capacity


Verification & Exception Management

  • Track vulnerabilities through verified closure and remediation scanning
  • Maintain a consolidated view of coverage, SLA attainment, ageing and end-of-life risks
  • Own the vulnerability exception register
  • Ensure every exception has:
  • Appropriate compensating controls
  • A clear accountable owner
  • A defined expiry date
  • Prepare exception cases for Risk Management governance


Awareness & Continuous Improvement

  • Promote vulnerability management best practices across the organisation
  • Help mature the overall vulnerability management capability and operating model



Your profile


5+ years of experience in Vulnerability Management and/or Patch Management with direct programme ownership

Strong knowledge of the Vulnerability Management Lifecycle

Strong understanding of CVSS, exploitability analysis and threat intelligence

Good understanding of enterprise infrastructure, networking, cloud and remediation processes

Hands-on experience with Qualys, AWS Inspector and Microsoft Defender Vulnerability Management

Experience in a large enterprise or public-sector environment, ideally with significant legacy systems and technical debt

Experience with AWS and Azure

Knowledge of container security

Familiarity with NIS2

Experience integrating Vulnerability Management with ITSM tools such as Jira and ServiceNow

Strong analytical, governance and reporting skills

Strong stakeholder management skills and ability to challenge remediation teams where needed



Languages

Fluent English required

Dutch and/or French is a strong plus


We are looking for someone who can combine security expertise, governance and hands-on programme ownership - someone capable of driving remediation across multiple technical teams rather than simply producing vulnerability reports. xlxgzvr


Int