Information Security Engineer

Il y a 2 jours

Profondeville, Belgique Fortegra Temps plein
Job Summary: Minimum Qualifications: Education:
- Bachelor’s degree in Computer Science, Information Security, or a related technical field, OR equivalent professional experience.
- 4+ years of experience in an information security, security engineering, or closely related role. Experience:
- Working knowledge of common cybersecurity frameworks (NIST CSF, NIST 800‑53, ISO 27001, CIS Controls, MITRE ATT&CK).
- Hands-on experience securing at least one major cloud provider (AWS, Azure, or GCP), including identity, network, and workload controls.
- Experience with vulnerability management, patching, and remediation across servers, endpoints, containers, and cloud workloads.
- Experience integrating security into CI/CD pipelines (SAST, DAST, SCA, secret scanning, IaC scanning).
- Incident response experience, including triage, containment, eradication, recovery, and post-incident review.
- Familiarity with AI/LLM security concepts (prompt injection, data leakage, model and supply-chain risks) and emerging frameworks such as the OWASP LLM Top 10, MITRE ATLAS, and the NIST AI Risk Management Framework. Licensure, Certification, and/or Registration
- One or more of the following preferred: CISSP, CCSP, Security+, CISM, GIAC (e.g., GSEC, GCIH, CGFA, GCSA), OSCP
- AI/ML security credentials (e.g., AI Security/Governance certifications) a plus Primary Job Functions: Security Operations & Incident Response
- Lead investigations into security incidents escalated beyond Tier 1, including triage, forensic analysis, containment, eradication, and recovery.
- Develop, maintain, and tune detections (e.g., SIEM rules, EDR custom detections) aligned to MITRE ATT&CK and the organization’s threat model.
- Conduct and participate in tabletop exercises, purple-team engagements, and incident management drills at least annually.
- Maintain runbooks and playbooks for common incident types, including cloud, identity, ransomware, and AI/LLM-related incidents. Vulnerability & Threat Management
- Design and execute vulnerability assessments, penetration tests, red-team exercises, and security audits; manage findings through to closure.
- Maintain hardened, up-to-date baselines (CIS Benchmarks or equivalent) for workstations, servers, cloud resources, containers, and network devices.
- Consume and operationalize threat intelligence to anticipate and defend against new attacks and threat vectors. Cloud & Infrastructure Security
- Design, implement, and review security controls across cloud environments including IAM, network segmentation, encryption, logging, and posture management (CSPM/CNAPP).
- Review Infrastructure-as-Code manifests for security misconfigurations; help maintain policy-as-code guardrails.
- Partner with IT and identity teams on IAM, SSO, MFA, privileged access management, and conditional access policies. Application & Software Supply Chain Security
- Partner with the CISO and engineering leadership to enforce secure coding practices; deliver annual secure-development training, including OWASP Top 10 and OWASP LLM Top 10 content.
- Integrate and tune security testing in CI/CD pipelines: SAST, DAST, SCA, secret scanning, container image scanning, and IaC scanning.
- Establish and maintain software supply chain controls, including SBOM generation, dependency review, and alignment with frameworks such as SLSA.
- Lead threat-modeling sessions for new products, services, and AI-enabled features. AI Security & Governance
- Help define and enforce policies for the safe adoption and use of AI tools within the organization, including LLM-based assistants, agentic systems, and Model Context Protocol (MCP) or similar tool integrations.
- Assess and mitigate risks specific to AI/ML systems the organization builds or consumes, including prompt injection, jailbreaks, insecure output handling, training-data and model integrity, sensitive-data leakage, and model/identity supply-chain risks.
- Review AI-generated code for security vulnerabilities and licensing issues before it reaches production.
- Partner with Legal, Privacy, and Engineering on AI data handling, retention, and disclosure practices. AI-Augmented Security Operations & Tooling
- Evaluate and deploy AI-assisted security tooling (e.g., LLM-powered alert triage, log summarization, threat-intel enrichment, phishing analysis, AI-assisted code review) to improve analyst productivity and reduce mean time to detect/respond.
- Build lightweight automations and scripts (Python, PowerShell, or similar), leveraging AI coding assistants where appropriate, to streamline detection, response, and reporting workflows.
- Continuously validate the accuracy and safety of AI-driven security tooling and document its operating envelope (where it can and cannot be trusted). Compliance, Risk & Audit
- Prepare for and respond to internal and external IT audits and risk assessments (GDPR, DORA, PCI DSS, HIPAA, GDPR/CCPA, as applicable).