Senior Cybersecurity Expert Consultant

Il y a 4 heures

Brussels, Brussels, Belgique Keystone Solutions Temps plein
Mission Overview: As part of the ongoing enhancement of its cybersecurity posture, our client seeks to engage the services of a Senior Cybersecurity Expert Consultant to provide independent expertise in assessing the security of its information system and to support IT teams in sustainably improving their level of protection. This position is a consultancy mission at a client site representing Keystone Solutions.

Objectives of the Mission: The consultant will have the following objectives:

Evaluate the actual security level of the information system.

Identify technical and organizational vulnerabilities that could be exploited.

Conduct internal and external penetration tests.

Assess the security of Microsoft, Microsoft Entra ID, Azure, Linux, and network infrastructures.

Analyze attack paths that could compromise the information system.

Verify the effectiveness of existing security measures.

Evaluate the compliance of infrastructures with the security standards adopted by the company and industry best practices.

Assist technical teams in defining and prioritizing corrective measures.

Provide independent expertise in infrastructure evolution projects.

Contribute to the continuous improvement of the company's cybersecurity posture.

Main Responsibilities: A. Security Evaluation

Conduct internal and external penetration tests.

Perform Active Directory audits.

Evaluate the security of Microsoft Windows, Linux, Microsoft Entra ID, and Azure environments.

Analyze the security of networks, authentication mechanisms, exposed services, and privileged access.

Review security configurations and identify gaps against best practices.

Validate the effectiveness of existing protection measures.

Identify exploitable technical vulnerabilities and assess their impact.

B. Offensive Analysis

Simulate attack scenarios representative of current threats.

Analyze compromise chains and attack paths.

Identify privilege escalation and lateral movement opportunities.

Evaluate network segmentation and security mechanisms.

Analyze the security of identities, privileges, delegations, and authentication mechanisms.

Identify technical risks that could affect the confidentiality, integrity, or availability of the information system.

C. Consulting, Architecture, and Support

Act as the technical reference for all cybersecurity-related questions.

Advise IT teams on technical choices impacting security.

Participate in architecture reviews from a cybersecurity perspective.

Evaluate the impacts of new projects on the company's security posture.

Formulate technical recommendations to reduce risks while considering operational constraints.

Participate in technical risk analyses.

Support teams in implementing remediation measures and in the continuous improvement of security.

D. Documentation and Knowledge Transfer

Produce detailed technical reports and executive summaries for management.

Prioritize recommendations based on their criticality, exploitability, and feasibility.

Document findings, analyses, security architectures, and remediation measures.

Develop best practice guides and contribute to the standardization of security practices.

Ensure knowledge transfer and contribute to the skill enhancement of internal teams.

Present mission results to both technical audiences and management, adapting the level of discourse and formulating clear, reasoned, and pragmatic recommendations.

Technical Skills Required: Cybersecurity

Internal and external penetration testing.

Active Directory audits.

Securing Microsoft environments.

Securing Microsoft Entra ID and Azure.

Securing Linux environments.

Identity and Access Management (IAM).

Privilege and authentication mechanism analysis.

Attack path analysis.

Security architecture evaluation.

Configuration review and hardening of systems.

Vulnerability analysis and remediation recommendations.

Infrastructures

Microsoft Windows Server.

Active Directory.

Microsoft Entra ID.

Microsoft Azure.

Microsoft 365.

Linux (Debian, Ubuntu, or equivalent distributions).

TCP/IP networks.

Switching, routing, and VLAN.

Enterprise Wi-Fi infrastructures.

Firewalls and VPNs.

Knowledge of virtualized environments (VMware, Hyper‑V, or equivalents) to assess their security level.

Methodologies

OWASP Testing Guide.

OWASP Top 10.

MITRE ATT&CK.

NIST Cybersecurity Framework.

CIS Benchmarks.

Documentation