Cyber Security Analyst

Il y a 2 heures

Brussels, Brussels, Belgique OneSource Consulting Temps plein

JOB TITLE: CYBERSECURITY ANALYST VULNERABILITY & ATTACK SURFACE MANAGEMENT
LOCATION: BRUSSELS, BELGIUM
DURATION: 01/10/2026 - 15/07/2027 PLUS POSSIBLE OF EXTENSION
LANGUAGES: FRENCH, DUTCH AND ENGLISH
WORK REGIME: 100% (FULL-TIME AND HYBRID 2(OR)3 DAYS ONSITE)

JOB DESCRIPTION
BUSINESS CONTEXT:
You will work within the Flemish Centre for Digital Security (VCDV), part of Client. The VCDV acts as the central expertise centre for digital security within the Flemish government and supports both Flemish entities and local authorities with expertise, services and coordination on cybersecurity.
Within this context, a structural service is being developed, with the aim of identifying vulnerabilities in a timely manner and supporting organisations within the Flemish government and local authorities in strengthening their digital security.

TECHNICAL CONTEXT:
The technical environment in which these services are offered is very diverse and includes a variety of technologies, platforms and architectures that are used within the Flemish government and by local authorities. The service must therefore be applicable to a wide spectrum of applications, infrastructures, cloud environments and digital platforms.
Given this variety of solutions and the size of the data volumes and target groups to be processed, maximum integration and automation of the work processes is essential. You are therefore expected to be able to independently set up and maintain automation solutions.
As a Cybersecurity Analyst Vulnerability & Attack Surface Management, you will support the further development, implementation and optimisation of the services related to vulnerability management, attack surface management and cyber awareness within the Flemish government.
You analyze, assess and follow up on information about vulnerabilities, exposed systems and security risks. You validate findings, place them in their risk context and translate them into concrete recommendations. In doing so, you will support Flemish entities and local authorities in prioritising and following up on remediation actions.
Automation is an essential part of the job. Given the volume of sources, data, and audiences, you'll develop and maintain scripts — primarily in Python — and integrations that support the collection, enrichment, correlation, follow-up, and reporting of vulnerability information.
You will work closely with internal teams, external service providers and representatives of Flemish entities and local authorities. You provide timely insight into vulnerabilities and exposed systems and provide the corresponding recommendations, so that the organisations involved can remediate in a targeted manner.
In addition, you also support initiatives around cyber awareness and phishing simulations.
The position is executive and supportive in nature and combines substantive expertise with a strong operational focus. In addition to the analysis and follow-up of files, you will take an active role in the daily operation of the service and contribute to the further professionalization of processes, working methods and supporting solutions.

CORE TASKS
Analyzing vulnerabilities and exposures based on a variety of sources.
Validating findings, filtering noise and false positives, and estimating the real impact for the organizations involved.
Risk-based prioritization of findings based on CVSS, EPSS, operating status and organizational context, among other things.
Distilling overarching findings and trends as well as organization-specific recommendations from the analyzed information.
To make this information accessible through the existing reporting and communication channels, tailored to the target groups involved.
Developing and maintaining scripts and API integrations (Python) for data collection, enrichment, correlation and reporting.
Supporting Flemish entities and local authorities in the follow-up of remediation actions.
Helping to prepare, implement and discuss cyber awareness initiatives and phishing simulations.
Contributing to the documentation, standardization and continuous improvement of processes, working methods and supporting solutions.
Demonstrable experience as a Security Consultant within one of the following environments: data, infrastructure, applications, ...
Demonstrable expertise in specific knowledge domain of information security (e.g. implementing information security management processes, performing vulnerability analyses and pen tests, optimizing application security through cost-effective
Demonstrated experience in analyzing, optimizing and documenting security processes and governance
Demonstrated experience in security management techniques and/or frameworks (e.g.: ISO27000 series, COBIT for Security, NIST, OWASP, CIS Critical Security Controls for Effective Cyber Defense)
Demonstrable knowledge and experience v