Cyber Security Engineer

Il y a 5 heures

Arrondissement of BrusselsCapital, Brussels, Belgique Tata Consultancy Services Temps plein
ppbLocation: /b Brussels, Belgium /p pbCompany: /b Tata Consultancy Services (TCS) Belgium /p pbEmployment Type: /b Full-time /p h3bNature of the tasks /b /h3 ul liDevelop and implement security policies and procedures. /li liDefine, implement and monitor security plans. /li liGuide development teams throughout the Software Development Lifecycle (SDLC) to build and operate software securely, following EC standards and industry best practices (e.g., OWASP Top 10). /li liConduct security inspections, code reviews, and risk assessments for internally developed as well as SaaS (Software-as-a-Service) applications. /li liMonitor systems for security breaches and incidents. /li liAnalyse and respond to security threats and vulnerabilities, including managing the remediation process through to closure. /li liDesign and deploy security solutions and technologies for internal EC Data Centre and Cloud environments. /li liCollaborate with IT and business teams to ensure compliance with security standards. /li liEnsure data protection and privacy through encryption and access controls. /li liConduct security training and awareness programs for staff. /li liPrepare incident response plans and conduct simulations. /li liStay updated on the latest security trends and emerging threats. /li liPerform regular vulnerability assessments and penetration tests using automated tools and manual techniques to identify and prioritize security weaknesses. /li liManage and configure security tools, including SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), firewalls, and intrusion detection/prevention systems. /li liLead the response to security incidents, including containment, eradication, recovery, and post-incident analysis and reporting. /li /ul h3bSpecific expertise and technologies /b /h3 ul liProficiency in cybersecurity domains (network, application, endpoint, cloud). /li liExperience with integrating security into DevSecOps pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and software supply chain security tools. /li liUnderstanding of secure coding practices in languages (Java, Python, JavaScript) and knowledge of common vulnerabilities (e.g., OWASP Top 10). /li liKnowledge of encryption protocols and technologies (e.g., TLS/SSL, IPSec, AES, RSA, PKI). /li liExperience with SIEM platforms (e.g., Splunk, ELK, Microsoft Sentinel). /li liExpertise in vulnerability assessment and penetration testing methodologies and tools (e.g., Nessus, Qualys, Burp Suite, Metasploit, OWASP ZAP). /li liKnowledge of IAM/IGA platforms (e.g., Okta, Azure AD, SailPoint), MFA and SSO. /li liExperience with cloud security architectures and controls. /li liFamiliarity with regulatory compliance standards like GDPR, HIPAA, and PCI-DSS. /li liProficiency in scripting or programming languages for automation and monitoring. /li liKnowledge of ISO/IEC 27001 and ISO/IEC 27005 standards. /li liExperience with endpoint detection and response (EDR) tools and network security monitoring (NSM). /li liKnowledge of threat intelligence platforms and threat modelling methodologies. /li /ul h3bMinimum level of expertise /b /h3 h3bNormal /b /h3 h3bMandatory for ‘Normal’ level: /b /h3 ul liOne of the following or an equivalent certification: /li liCISSP (Certified Information Systems Security Professional) /li liCISM /li liCCSP /li /ul h3bOptional for ‘Normal’ level: /b /h3 ul liCloud and vendor-specific certifications. /li /ul h3bSenior /b /h3 h3bMandatory for ‘Senior’ level: /b /h3 ul liOne of the following or an equivalent certification: /li liCISSP-ISSAP /li liGIAC advanced credential (e.g., GCIH, GCIA) /li liOSCP (Offensive Security Certified Professional) /li /ul h3bOptional for ‘Senior’ level: /b /h3 ul liCloud expert certifications. /li /ul h3bSkills /b /h3 ul liAbility to analyse complex and design effective solutions. /li liTalent for attention to detail in code correctness, error handling, and documentation. /li liAbility to anticipate future threats and evaluate trends. /li liEthical judgment and integrity. /li liContinuous learning and adaptability to emerging security trends. /li liCapability to educate and train others on security practices. /li liAbility to participate in multilingual meetings. /li liAbility to understand, speak and write English, optionally French as an additional asset. /li liExcellent interpersonal and communication skills. /li liAbility to work in a team as well as autonomously. /li liResults-oriented mindset, focused on delivering results. /li /ul /p