Information Security Analyst
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
We connect people with people, water with technology. We stay ahead of change and work towards a living environment in harmony with water. We do this through water purification and sewerage, but also through innovation and the energy transition.
We contribute every day to better water quality and a healthy living environment. We realize infrastructure projects that collect and purify domestic wastewater and continuously work on optimizing our existing networks and facilities. In doing so, we support the ambition to achieve the ecological objectives for our waterways.
About those job:
- As an Information Security Analyst (Second Line) , you support the NIS2 implementation and the preparations for the audit for our organization (essential).
- In this second-line role, you independently assess the quality of documentation and implementation evidence provided by the domains (first line) based on CyFun guidance.
- Additionally, you validate that the evidence supports the scores and is not based on assumptions, ensuring they will pass the external auditor's review.
- You provide feedback to the domain owners, formulating concrete points for improvement that they can work on.
- In addition, you build a file , including a register of evidence, which can be presented to the auditor without reworking.
- We are first working towards the important level, and you will continue to provide support after April 2027 in preparation for the Essential level.
- You have 3 to 6 years of experience in information security, compliance, or IT audit. You are familiar with control frameworks such as CyFun, ISO 27001, and/or CIST CSF.
- You are able to interpret and assess technical evidence such as configuration exports, log files, tickets, remediation, and scan reports.
- Your role is in the second line and does not include operational tasks such as pentesting, SOC activities, or engineering.
- The position reports to the CISO and requires a critical, analytical, and independent attitude. The CISO supports you in cases of doubt, methodology, and escalation.
- The first line is responsible for self-evaluation, providing evidence, and remediation.