IT Security Officer

Il y a 1 semaine

Leuven Flemish Region, VLG, Belgique OneSource Consulting Temps plein
Job Title: Medior IT Security Officer

Location:
Leuven, Belgium Duration: ASAP-End of 2026 with Possible Extension Mode of work: Hybrid (2 days onsite per week) Languages: Dutch, French and English

Job Description
- Roles and Responsibilities
Your responsibilities
- Daily triage and risk-based prioritization of vulnerabilities.
- Tracking remediation actions in collaboration with the relevant IT teams.
- Monitoring deadlines, open findings, and remediation progress.
- Preparing operational and management reports.
- Conducting cybersecurity risk analyses and supporting risk acceptance processes.
- Assisting with the analysis and follow-up of security incidents.
- Monitoring relevant threats and security advisories.
- Contributing to security monitoring, system hardening, and the further development of Cyber Defense processes.
- Collaborating closely with IT teams, Security Officers, and external vendors. Your technical background
- Strong knowledge of Vulnerability Management: triage, prioritization, remediation tracking, and reporting.
- Experience with vulnerability scanning tools such as Tenable, Qualys, or similar solutions.
- Good knowledge of CVE, CVSS, CWE, EPSS, and CISA KEV.
- Experience conducting cybersecurity risk analyses and assessing residual risk.
- Knowledge of security incident triage, investigation, and remediation.
- Experience with Cyber Defense technologies such as SIEM, EDR/XDR, and NDR.
- Solid understanding of infrastructure, network, endpoint, application, and cloud security.
- Knowledge of security hardening, patch management, and CIS Benchmarks.
- Experience with security reporting and developing KPIs/KRIs and dashboards.
- Familiarity with NIST, ISO 27001/27002, and MITRE ATT&CK. Your strengths
- Strong analytical and solution-oriented mindset.
- Well-organized, with a keen eye for setting priorities.
- Strong sense of responsibility and ownership.
- Clear communication skills, addressing both technical and non-technical stakeholders.
- Strong stakeholder management and collaboration skills.
- Ability to work independently and see tasks through to completion.
- Structured, pragmatic, and precise working style.
- Remains calm and focused during critical vulnerabilities or security incidents.