Security Engineer NL/ENG

Il y a 8 heures

Leuven, Flanders, Belgique Collective.work Temps plein

Job description

Daily rate: 500 - 540

Context

Focus on preventive security solutions, patch and vulnerability management, application protection, and security tooling follow-up.

Missions

• Monitor and remediate security breaches
◦ Investigate suspicious activities and take remediating actions.
◦ Document, test, and monitor security breaches and assess their damage.

• Maintain security monitoring tools
◦ Secure and monitor the different systems effectively.

• Perform vulnerability and risk analysis
◦ Conduct in-depth risk assessments and vulnerability analyses.
◦ Identify and report vulnerabilities in web applications and APIs.

• Support application security
◦ Advise development teams on secure coding practices.
◦ Perform security assessments on web applications and APIs.
◦ Identify common web vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Clickjacking.

• Work on scanning and detection activities
◦ Optionally conduct and analyze SCA, SAST, and DAST scans.
◦ Analyze log data to identify anomalies and potential threats.
◦ Continuously improve monitoring and detection systems.

• Contribute to incident response and threat mitigation
◦ Develop data-driven security strategies and incident response plans.
◦ Investigate security incidents and perform forensic analysis.
◦ Advise on preventive measures based on threat intelligence and trends.

• Collaborate with stakeholders
◦ Collaborate with internal stakeholders to implement security policies and best practices.
◦ Follow up with internal stakeholders and development teams.

Organisation & Daily Work

• Usually part of the SOC (security operations center).
• Collaborate with internal stakeholders and development teams.
• Role involves cross-departmental collaboration.
• Strong analytical, decision-making, and ownership skills are expected.
• A curious and investigative nature is highlighted.

Requirements

  1. 2-5 years of experience, with a minimum of 2 years in an IT technical role, ideally within cybersecurity focusing on analysis and threat detection
  2. Strong knowledge of ICT, Agile methodology, cyber risk management, incident management, and root cause analysis
  3. Expertise in information security, vulnerability management, web security, secure coding practices, and network protocols
  4. Experience with attack techniques, cloud security, log analysis, common web vulnerabilities, forensic analysis, threat intelligence, and monitoring and detection
  5. Background in application management and familiarity with front-end and back-end development
  6. Proficiency with tools and technologies such as Python, Bash, HTML, JavaScript, CSS, Azure, AWS, GCP, RESTful APIs, SQL, browser DevTools, SCA, SAST, DAST, and VMDR
  7. Strong analytical mind and conceptual thinking with a proactive mindset and ability to take ownership
  8. Excellent communication skills, including with non-technical stakeholders, and ability to collaborate effectively as a team player
  9. Ability to perform under pressure with attention to detail, critical thinking, and a curious and investigative nature
  10. Strong process management and quality improvement mindset
  11. Fluency in Dutch and English
  12. Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Data Science, or a related field
  13. Certifications such as CISSP, CEH, OSCP, or CompTIA Security+