Freelance / Consultant Opportunity – Vulnerability Lead

Il y a 7 heures

Brussels, Brussels, Belgique Distinctive Advisory Temps plein
We are currently looking for an experienced Vulnerability Lead for a consulting assignment within the CISO Office of a large Belgian organization. Brussels / Hybrid way of working (homeworking + onsite presence) Full-time Initial duration: 3 months, renewable This is a senior role with real ownership of the organisation's enterprise Vulnerability Management programme, covering on-premise infrastructure, cloud, workplace, applications and container environments. Your role You will act as the central Vulnerability Lead and drive the full vulnerability lifecycle: from identification and prioritisation through remediation, verification, reporting and exception management.

Key responsibilities
include: Governance & Reporting
- Act as the Vulnerability Management SPOC towards the CISO Office
- Prepare and maintain audit-ready evidence, including NIS2-related compliance
- Produce and present monthly Vulnerability Management reporting to senior security governance
- Define and continuously evolve the scope of the VM programme Process & SLA Ownership
- Own and continuously improve the end-to-end Vulnerability Management process
- Define and maintain the VM RACI across internal teams and external partners
- Establish risk-based prioritisation based on:
- CVSS
- Exploitability
- Threat intelligence
- Business criticality
- Define and monitor remediation SLAs for Critical, High, Medium and Low vulnerabilities
- Define and track Vulnerability Management KPIs and KRIs Remediation & Patching Coordination
- Work closely with Infrastructure, Cloud, Workplace, Application, SOC, Incident Response and business teams
- Drive remediation commitments and SLA compliance
- Monitor remediation performance across teams and environments
- Coordinate vulnerability detection and remediation across:
- Servers
- End-user devices
- Cloud environments
- Applications
- Containers
- Manage prioritisation conflicts between vulnerability risk and delivery capacity Verification & Exception Management
- Track vulnerabilities through verified closure and remediation scanning
- Maintain a consolidated view of coverage, SLA attainment, ageing and end-of-life risks
- Own the vulnerability exception register
- Ensure every exception has:
- Appropriate compensating controls
- A clear accountable owner
- A defined expiry date
- Prepare exception cases for Risk Management governance Awareness & Continuous Improvement
- Promote vulnerability management best practices across the organisation
- Help mature the overall vulnerability management capability and operating model

Your profile
5+ years of experience in Vulnerability Management and/or Patch Management with direct programme ownership Strong knowledge of the Vulnerability Management Lifecycle Strong understanding of CVSS, exploitability analysis and threat intelligence Good understanding of enterprise infrastructure, networking, cloud and remediation processes Hands-on experience with Qualys, AWS Inspector and Microsoft Defender Vulnerability Management Experience in a large enterprise or public-sector environment, ideally with significant legacy systems and technical debt Experience with AWS and Azure Knowledge of container security Familiarity with NIS2 Experience integrating Vulnerability Management with ITSM tools such as Jira and ServiceNow Strong analytical, governance and reporting skills Strong stakeholder management skills and ability to challenge remediation teams where needed Languages Fluent English required Dutch and/or French is a strong plus We are looking for someone who can combine security expertise, governance and hands-on programme ownership
- someone capable of driving remediation across multiple technical teams rather than simply producing vulnerability reports. Interested, or know someone who could be a good fit? Send your CV, availability and expected daily rate.