Information Security Engineer

Il y a 3 heures

Profondeville, Wallonia, Belgique Fortegra- Temps plein
ppResponsible for safeguarding the confidentiality, integrity, and availability of data, applications, infrastructure, and AI systems across the organization. The Security Engineer leads day-to-day operations of the company’s security tooling across on-premises, cloud, and SaaS environments, drives the identification, investigation, and resolution of security events, and partners with engineering and operations teams to embed security throughout the software development and deployment lifecycle. The role also helps the organization securely adopt, deploy, and govern AI technologies. /p h3bMinimum Qualifications /b /h3 pbEducation: /b /p ul liBachelor’s degree in Computer Science, Information Security, or a related technical field, OR equivalent professional experience. /li li4+ years of experience in an information security, security engineering, or closely related role. /li /ul pbExperience: /b /p ul liWorking knowledge of common cybersecurity frameworks (NIST CSF, NIST 800‑53, ISO 27001, CIS Controls, MITRE ATTCK). /li liHands‑on experience securing at least one major cloud provider (AWS, Azure, or GCP), including identity, network, and workload controls. /li liExperience with vulnerability management, patching, and remediation across servers, endpoints, containers, and cloud workloads. /li liExperience integrating security into CI/CD pipelines (SAST, DAST, SCA, secret scanning, IaC scanning). /li liIncident response experience, including triage, containment, eradication, recovery, and post‑incident review. /li liFamiliarity with AI/LLM security concepts (prompt injection, data leakage, model and supply‑chain risks) and emerging frameworks such as the OWASP LLM Top 10, MITRE ATLAS, and the NIST AI Risk Management Framework. /li /ul pbLicensure, Certification, and/or Registration /b /p ul liOne or more of the following preferred: CISSP, CCSP, Security+, CISM, GIAC (e.g., GSEC, GCIH, CGFA, GCSA), OSCP /li liAI/ML security credentials (e.g., AI Security/Governance certifications) a plus /li /ul h3bPrimary Job Functions /b /h3 pbSecurity Operations Incident Response /b /p ul liMonitor and tune in‑place security solutions (SIEM, EDR/XDR, SOAR, email security, DLP, CSPM) for efficient and appropriate operation. /li liLead investigations into security incidents escalated beyond Tier 1, including triage, forensic analysis, containment, eradication, and recovery. /li liDevelop, maintain, and tune detections (e.g., SIEM rules, EDR custom detections) aligned to MITRE ATTCK and the organization’s threat model. /li liConduct and participate in tabletop exercises, purple‑team engagements, and incident management drills at least annually. /li liMaintain runbooks and playbooks for common incident types, including cloud, identity, ransomware, and AI/LLM‑related incidents. /li /ul pbVulnerability Threat Management /b /p ul liLead vulnerability remediation across endpoints, servers, cloud workloads, containers, and SaaS applications, working with infrastructure and engineering teams to drive risk down. /li liDesign and execute vulnerability assessments, penetration tests, red‑team exercises, and security audits; manage findings through to closure. /li liMaintain hardened, up‑to‑date baselines (CIS Benchmarks or equivalent) for workstations, servers, cloud resources, containers, and network devices. /li liConsume and operationalize threat intelligence to anticipate and defend against new attacks and threat vectors. /li liDesign, implement, and review security controls across cloud environments including IAM, network segmentation, encryption, logging, and posture management (CSPM/CNAPP). /li liAdvance the organization’s Zero Trust strategy across identity, device, network, application, and data layers. /li liReview Infrastructure‑as‑Code manifests for security misconfigurations; help maintain policy‑as‑code guardrails. /li liPartner with IT and identity teams on IAM, SSO, MFA, privileged access management, and conditional access policies. /li /ul pbApplication Software Supply Chain Security /b /p ul liPartner with the CISO and engineering leadership to enforce secure coding practices; deliver annual secure‑development training, including OWASP Top 10 and OWASP LLM Top 10 content. /li liIntegrate and tune security testing in CI/CD pipelines: SAST, DAST, SCA, secret scanning, container image scanning, and IaC scanning. /li liEstablish and maintain software supply chain controls, including SBOM generation, dependency review, and alignment with frameworks such as SLSA. /li liLead threat‑modeling sessions for new products, services, and AI‑enabled features. /li /ul pbAI Security Governance /b /p ul liHelp define and enforce policies for the safe adoption and use of AI tools within the organization, including LLM‑based assistants, agentic systems, and Model Context Protocol (MCP) or similar tool integrations. /li liAssess and mitigate risks specific to AI/ML systems the organization builds or consumes, including prompt in