Cybersecurity Analyst Vulnerability

Il y a 4 heures

Brussels, Brussels, Belgique Harvey Nash Temps plein

Cybersecurity Analyst - Vulnerability & Attack Surface Management



Are you ready to apply Make sure you understand all the responsibilities and tasks associated with this role before proceeding.

Description

As a Cybersecurity Analyst - Vulnerability & Attack Surface Management, you will support the further development, execution, and optimization of services related to vulnerability management, attack surface management, and cyber awareness.


You will analyze, assess, and follow up on information regarding vulnerabilities, exposed systems, and security risks. You will validate findings, place them in the appropriate risk context, and translate them into concrete recommendations. In doing so, you will support our client's entities and local authorities in prioritizing and tracking remediation actions.


Automation is an essential part of the role. Given the large volume of sources, data, and stakeholders involved, you will develop and maintain scripts, primarily in Python, as well as integrations that support the collection, enrichment, correlation, follow-up, and reporting of vulnerability information.

You will work closely with internal teams, external service providers, and representatives of our client's entities and local authorities. Your objective is to ensure vulnerabilities and exposed systems are identified and communicated in a timely manner, together with actionable recommendations, enabling organizations to effectively remediate identified risks.


In addition, you will support initiatives related to cyber awareness and phishing simulations.

This is primarily an operational and support-oriented role, combining technical expertise with a strong hands-on focus. Besides analyzing and following up on cases, you will play an active role in the day-to-day delivery of the service and contribute to the further professionalization of processes, methodologies, and supporting solutions.


Key Responsibilities

  • Analyze vulnerabilities and exposures based on a variety of information sources.
  • Validate findings, filter out noise and false positives, and assess the actual impact on affected organizations.
  • Prioritize findings based on risk, considering factors such as CVSS scores, EPSS scores, exploitation status, and organizational context.
  • Derive both overarching trends and organization-specific recommendations from analyzed data.
  • Communicate findings through existing reporting and communication channels tailored to the relevant target audiences.
  • Develop and maintain Python scripts and API integrations for data collection, enrichment, correlation, and reporting.
  • Support our client and local authorities in tracking remediation activities.
  • Assist in the preparation, execution, and evaluation of cyber awareness initiatives and phishing simulations.
  • Contribute to the documentation, standardization, and continuous improvement of processes, methodologies, and supporting solutions.


Required Experience and Qualifications

  • Proven experience as a Security Consultant within one or more of the following domains: data, infrastructure, applications, or related environments.
  • Demonstrated expertise in a specific area of information security, such as:
  • Implementing information security management processes
  • Conducting vulnerability assessments and penetration testing
  • Improving application security through cost-effective measures
  • Implementing Privileged Access Management (PAM) solutions
  • Implementing encryption solutions
  • Proven experience in analyzing, optimizing, and documenting security processes and governance.
  • Proven experience with security management techniques and frameworks, such as:
  • ISO 27000 series
  • COBIT for Security
  • NIST
  • OWASP
  • CIS Critical Security Controls
  • Demonstrable knowledge and certifications relevant to the area of expertise (e.g., CISM, CISSP, CEH).


Language requirement: Native-level Dutch (CEFR C2).


Skills & Requirements

Must-Have

  • Minimum 3 years of experience as a Cybersecurity Analyst in Vulnerability Management, including:
  • Vulnerability identification
  • Validation
  • Risk-based prioritization
  • Remediation follow-up
  • Minimum 3 years of experience as a Security Consultant in data, infrastructure, application security, or similar environments.
  • Proven experience in analyzing, optimizing, and documenting security pr