Information Security Engineer
Il y a 6 heures
Liège, Walloon Region, Belgique
EVS
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
ScopeWe're looking for an Information Security Engineer to join the IT Security team within IT Corporate.
In this hands-on role, you'll drive operational cybersecurity: vulnerability management, security monitoring, incident response support, security assessments, and ongoing improvement of our controls. You'll work closely with Infrastructure and Workplace teams to strengthen our security posture and help execute the security roadmap.
EVS is an NIS2 Essential Entity under Belgian law, currently working toward ISO/IEC 27001:2022 certification (target: April 2027). You'll play a direct role in this programme : implementing controls, producing evidence, and ensuring audit readiness across the IT Corporate perimeter.
Job Description
As part of the IT Security team, the Information Security Engineer will contribute to the following activities:Security Operations & MonitoringMonitor and investigate alerts across multiple platformsTake part in incident response efforts and help coordinate investigationsHelp refine and tune detection capabilities and monitoring use casesSupport the development and upkeep of operational procedures and playbooksConduct operational reviews and related follow-up workVulnerability & Exposure ManagementOrganize scanning activities and ensure findings are reviewed and prioritized appropriatelyLiaise with infrastructure, platform, application and support teams on remediation actionsTrack remediation progress and escalate overdue items when neededArrange external penetration tests and other assessmentsEnsure findings from these engagements are documented, tracked, and resolvedSecurity Assessments & Risk ManagementAssess applications, services and technical solutions from a security standpointContribute to risk evaluations for new projects, technologies and providersExamine configurations and flag areas for improvementHelp identify and manage risks across the IT environmentSecurity Governance & ReportingMaintain and track operational KPIs and dashboardsAssist with reporting on vulnerabilities, incidents, posture and remediation effortsParticipate in periodic access reviews, including privileged accounts and controlsSupport compliance efforts and implementation of requirements under ISO/IEC 27001:2022 and NIS2Produce and maintain auditable evidence of control operation in line with ISO 27001:2022 (logs, reports, review records, remediation closure evidence)Improvement & AutomationSpot opportunities to strengthen controls and streamline processesContribute to automation initiatives that reduce manual effortMake use of available tooling — including built-in analytics and automation features — to enhance detection quality and efficiencyKeep documentation and procedures up to dateCollaboration & AdvisoryOffer guidance to IT teams and project stakeholdersPartner with Infrastructure and Workplace teams to strengthen overall postureChampion best practices and support awareness initiativesKeep up with emerging threats, vulnerabilities and industry trendsProfileExperienceMinimum 3 years in cybersecurity, security operations, vulnerability management, or a related technical security roleBackground in security monitoring, incident handling, or vulnerability managementPractical exposure to security tools and operational processesTechnical KnowledgeSolid grasp of security monitoring and incident response principlesKnowledge of vulnerability management processes and risk-based remediation prioritization — combining CVSS scores with asset criticality, exploitability context, and compensating controlsHands-on experience with the Microsoft Defender XDR suite: Defender for Endpoint (EDR), Defender for Office 365 / Exchange Online Protection, Defender for IdentityExposure to Microsoft Sentinel (SIEM/SOAR) or an equivalent platform — deployment experience is a strong assetGrasp of Entra ID governance: Conditional Access, Identity Protection, Privileged Identity Management (PIM)Working knowledge of Microsoft Intune (MDM, endpoint compliance policies) and Microsoft Purview (DLP, compliance)Command of network security fundamentals: firewall management (Palo Alto / FortiGate), log forwarding, network segmentation principlesAwareness of common frameworks and industry best practices (ISO/IEC 27001, NIST CSF, CIS Controls)Personal SkillsStrong analytical and problem-solving mindsetOrganized, structured, and detail-orientedAble to work independently while collaborating effectively across teamsCurious, with a drive to keep learning new technologies and trendsProactive, with a continuous-improvement mindsetStrong communication and coordination abilitiesTeam player with a practical, solution-oriented approachLanguagesFluent in French (working language of the IT team)Professional English required — all security tooling, vendor documentation, and ISO/IEC 27001 programme materials are in EnglishCertifications (Nice to Have)SC-200 — Microsoft Security Operations Analyst (strongly preferred given the EVS tooling stack)SC-300 — Mic
In this hands-on role, you'll drive operational cybersecurity: vulnerability management, security monitoring, incident response support, security assessments, and ongoing improvement of our controls. You'll work closely with Infrastructure and Workplace teams to strengthen our security posture and help execute the security roadmap.
EVS is an NIS2 Essential Entity under Belgian law, currently working toward ISO/IEC 27001:2022 certification (target: April 2027). You'll play a direct role in this programme : implementing controls, producing evidence, and ensuring audit readiness across the IT Corporate perimeter.
Job Description
As part of the IT Security team, the Information Security Engineer will contribute to the following activities:Security Operations & MonitoringMonitor and investigate alerts across multiple platformsTake part in incident response efforts and help coordinate investigationsHelp refine and tune detection capabilities and monitoring use casesSupport the development and upkeep of operational procedures and playbooksConduct operational reviews and related follow-up workVulnerability & Exposure ManagementOrganize scanning activities and ensure findings are reviewed and prioritized appropriatelyLiaise with infrastructure, platform, application and support teams on remediation actionsTrack remediation progress and escalate overdue items when neededArrange external penetration tests and other assessmentsEnsure findings from these engagements are documented, tracked, and resolvedSecurity Assessments & Risk ManagementAssess applications, services and technical solutions from a security standpointContribute to risk evaluations for new projects, technologies and providersExamine configurations and flag areas for improvementHelp identify and manage risks across the IT environmentSecurity Governance & ReportingMaintain and track operational KPIs and dashboardsAssist with reporting on vulnerabilities, incidents, posture and remediation effortsParticipate in periodic access reviews, including privileged accounts and controlsSupport compliance efforts and implementation of requirements under ISO/IEC 27001:2022 and NIS2Produce and maintain auditable evidence of control operation in line with ISO 27001:2022 (logs, reports, review records, remediation closure evidence)Improvement & AutomationSpot opportunities to strengthen controls and streamline processesContribute to automation initiatives that reduce manual effortMake use of available tooling — including built-in analytics and automation features — to enhance detection quality and efficiencyKeep documentation and procedures up to dateCollaboration & AdvisoryOffer guidance to IT teams and project stakeholdersPartner with Infrastructure and Workplace teams to strengthen overall postureChampion best practices and support awareness initiativesKeep up with emerging threats, vulnerabilities and industry trendsProfileExperienceMinimum 3 years in cybersecurity, security operations, vulnerability management, or a related technical security roleBackground in security monitoring, incident handling, or vulnerability managementPractical exposure to security tools and operational processesTechnical KnowledgeSolid grasp of security monitoring and incident response principlesKnowledge of vulnerability management processes and risk-based remediation prioritization — combining CVSS scores with asset criticality, exploitability context, and compensating controlsHands-on experience with the Microsoft Defender XDR suite: Defender for Endpoint (EDR), Defender for Office 365 / Exchange Online Protection, Defender for IdentityExposure to Microsoft Sentinel (SIEM/SOAR) or an equivalent platform — deployment experience is a strong assetGrasp of Entra ID governance: Conditional Access, Identity Protection, Privileged Identity Management (PIM)Working knowledge of Microsoft Intune (MDM, endpoint compliance policies) and Microsoft Purview (DLP, compliance)Command of network security fundamentals: firewall management (Palo Alto / FortiGate), log forwarding, network segmentation principlesAwareness of common frameworks and industry best practices (ISO/IEC 27001, NIST CSF, CIS Controls)Personal SkillsStrong analytical and problem-solving mindsetOrganized, structured, and detail-orientedAble to work independently while collaborating effectively across teamsCurious, with a drive to keep learning new technologies and trendsProactive, with a continuous-improvement mindsetStrong communication and coordination abilitiesTeam player with a practical, solution-oriented approachLanguagesFluent in French (working language of the IT team)Professional English required — all security tooling, vendor documentation, and ISO/IEC 27001 programme materials are in EnglishCertifications (Nice to Have)SC-200 — Microsoft Security Operations Analyst (strongly preferred given the EVS tooling stack)SC-300 — Mic