Cyber Security Engineer
Il y a 1 jour
Brussels, Brussels Capital, Belgique
Tata Consultancy Services
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Location: Brussels, Belgium
Company: Tata Consultancy Services (TCS) Belgium
Employment Type: Full-time
Nature of the tasks
- Develop and implement security policies and procedures.
- Define, implement and monitor security plans.
- Guide development teams throughout the Software Development Lifecycle (SDLC) to build and operate software securely, following EC standards and industry best practices (e.g., OWASP Top 10).
- Conduct security inspections, code reviews, and risk assessments for internally developed as well as SaaS (Software-as-a-Service) applications.
- Monitor systems for security breaches and incidents.
- Analyse and respond to security threats and vulnerabilities, including managing the remediation process through to closure.
- Design and deploy security solutions and technologies for internal EC Data Centre and Cloud environments.
- Collaborate with IT and business teams to ensure compliance with security standards.
- Ensure data protection and privacy through encryption and access controls.
- Conduct security training and awareness programs for staff.
- Prepare incident response plans and conduct simulations.
- Stay updated on the latest security trends and emerging threats.
- Perform regular vulnerability assessments and penetration tests using automated tools and manual techniques to identify and prioritize security weaknesses.
- Manage and configure security tools, including SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), firewalls, and intrusion detection/prevention systems.
- Lead the response to security incidents, including containment, eradication, recovery, and post-incident analysis and reporting.
Specific expertise and technologies
- Proficiency in cybersecurity domains (network, application, endpoint, cloud).
- Experience with integrating security into DevSecOps pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and software supply chain security tools.
- Understanding of secure coding practices in languages (Java, Python, JavaScript) and knowledge of common vulnerabilities (e.g., OWASP Top 10).
- Knowledge of encryption protocols and technologies (e.g., TLS/SSL, IPSec, AES, RSA, PKI).
- Experience with SIEM platforms (e.g., Splunk, ELK, Microsoft Sentinel).
- Expertise in vulnerability assessment and penetration testing methodologies and tools (e.g., Nessus, Qualys, Burp Suite, Metasploit, OWASP ZAP).
- Knowledge of IAM/IGA platforms (e.g., Okta, Azure AD, SailPoint), MFA and SSO.
- Experience with cloud security architectures and controls.
- Familiarity with regulatory compliance standards like GDPR, HIPAA, and PCI-DSS.
- Proficiency in scripting or programming languages for automation and monitoring.
- Knowledge of ISO/IEC 27001 and ISO/IEC 27005 standards.
- Experience with endpoint detection and response (EDR) tools and network security monitoring (NSM).
- Knowledge of threat intelligence platforms and threat modelling methodologies.
Minimum level of expertise
Normal
Mandatory for 'Normal' level:
- One of the following or an equivalent certification:
- CISSP (Certified Information Systems Security Professional)
- CISM
- CCSP
Optional for 'Normal' level:
- Cloud and vendor-specific certifications.
Senior
Mandatory for 'Senior' level:
- One of the following or an equivalent certification:
- CISSP-ISSAP
- GIAC advanced credential (e.g., GCIH, GCIA)
- OSCP (Offensive Security Certified Professional)
Optional for 'Senior' level:
- Cloud expert certifications.
Skills
- Ability to analyse complex and design effective solutions.
- Talent for attention to detail in code correctness, error handling, and documentation.
- Ability to anticipate future threats and evaluate trends.
- Ethical judgment and integrity.
- Continuous learning and adaptability to emerging security trends.
- Capability to educate and train others on security practices.
- Ability to participate in multilingual meetings.
- Ability to understand, speak and write English, optionally French as an additional asset.
- Excellent interpersonal and communication skills.
- Ability to work in a team as well as autonomously.
- Results-oriented mindset, focused on delivering results.