Cyber Security Operations Manager
Il y a 4 heures
Liège, Walloon Region, Belgique
EVS
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
ScopeWe are looking for a Cyber Security Operations Manager to join the IT Security team within the IT Corporate department, responsible for the operational execution and coordination of cybersecurity activities across the organization. This hands-on role acts as the primary link between IT operational teams (Infrastructure, Support, Applications) and governance/compliance (CISO Advisor), focusing on security operations, incident response, detection, vulnerability management, and remediation. The manager translates cybersecurity policies into concrete day-to-day processes, tools, and operational behaviors, working closely with all IT teams — though this is not a governance or policy-driven role, nor does it include direct administration of infrastructure components (firewalls, switches, servers), which remain with the Infrastructure & Digital Platforms teams.
The Cyber Security Operations Manager also has direct managerial responsibility over Cyber Security Analysts, overseeing their development, performance, and alignment with operational security objectives, while promoting a Shift Left approach that delegates low-complexity or repetitive tasks (e.g. basic alerts, endpoint maintenance, access requests) to first-level support where appropriate. As EVS is an NIS2 Essential Entity under Belgian law currently pursuing ISO/IEC 27001:2022 certification (target: April 2027), this role contributes directly to operational compliance, control implementation, and audit readiness.
Job Description
As part of the IT Security team, the Cyber Security Operations Manager will contribute to the following activities:Security Operations & Incident ResponseOversee day-to-day security operations, including SOC activities and threat monitoringEnsure effective detection, alert triage, escalation, and response to security incidentsCoordinate incident response efforts across IT teams and external partnersTake part in post-incident reviews and forensic analyses to strengthen organizational resilienceVulnerability & Remediation ManagementOrganize and support internal and external penetration testing engagementsTrack remediation plans and ensure proper follow-up through to closureRun and continuously refine vulnerability management processes and supporting toolsSecurity Tooling & MonitoringDeploy, operate, and fine-tune security solutions (e.g. SIEM, vulnerability scanners, EDR-related tooling)Ensure these solutions are properly calibrated, monitored, and aligned with operational needsWork with the SOC and service providers to enhance detection quality and cut down on false positivesOperational Governance & ComplianceTranslate cybersecurity policies into practice by embedding requirements into IT workflowsMaintain compliance with applicable regulations and frameworks (e.g. NIS2, CRA, ISO/IEC 27001)Keep security procedures and documentation clear, usable, and up to dateCoordination & CollaborationServe as the operational link between IT teams (Infrastructure, Support, Applications) and governance functionsPartner closely with Infrastructure (TST) and Support (SST) teams to define secure configuration baselinesLiaise with external providers (SOC, MSSP, penetration testers)People & Resource ManagementManage Cyber Security Analysts, including onboarding, task prioritization, coaching, and performance follow-upSupervise internal and external security resources based at headquarters or remote sitesSupport security awareness initiatives and technical training for IT staffReporting & Continuous ImprovementMaintain dashboards, KPIs, and indicators tracking operational security performanceSpot opportunities for improvement and quick winsHelp shape the cybersecurity roadmap from an execution-focused perspectiveProfileExperience & BackgroundProven hands-on experience in cybersecurity — SOC, SecOps, or Blue Team rolesDemonstrated ability to work autonomously, take ownership, and drive initiatives forwardExperience navigating complex IT environments (infrastructure, networks, cloud, endpoints)Initial exposure to leading or coordinating teams and activities (formal or informal leadership)Skills & MindsetStrong hands-on, execution-oriented mindsetSolid grasp of incident response, threat detection, and vulnerability managementAbility to translate security requirements into pragmatic IT practicesComfortable managing multiple stakeholders and external providersClear, structured, and pragmatic communication styleStrong sense of initiative, accountability, and ownershipRequired Hands-On ExposureCandidates must demonstrate practical experience in the following areas:Monitoring and detection tooling, such as SIEM and/or EDR platforms, including alert analysis, investigation, and tuningVulnerability management, including assessment, prioritization, remediation tracking, and follow-up with IT teamsRegulatory and security frameworks (e.g. NIS2, ISO 27K), approached from an implementation standpoint rather than a purely theoretical oneWorking alongside a SOC or m
The Cyber Security Operations Manager also has direct managerial responsibility over Cyber Security Analysts, overseeing their development, performance, and alignment with operational security objectives, while promoting a Shift Left approach that delegates low-complexity or repetitive tasks (e.g. basic alerts, endpoint maintenance, access requests) to first-level support where appropriate. As EVS is an NIS2 Essential Entity under Belgian law currently pursuing ISO/IEC 27001:2022 certification (target: April 2027), this role contributes directly to operational compliance, control implementation, and audit readiness.
Job Description
As part of the IT Security team, the Cyber Security Operations Manager will contribute to the following activities:Security Operations & Incident ResponseOversee day-to-day security operations, including SOC activities and threat monitoringEnsure effective detection, alert triage, escalation, and response to security incidentsCoordinate incident response efforts across IT teams and external partnersTake part in post-incident reviews and forensic analyses to strengthen organizational resilienceVulnerability & Remediation ManagementOrganize and support internal and external penetration testing engagementsTrack remediation plans and ensure proper follow-up through to closureRun and continuously refine vulnerability management processes and supporting toolsSecurity Tooling & MonitoringDeploy, operate, and fine-tune security solutions (e.g. SIEM, vulnerability scanners, EDR-related tooling)Ensure these solutions are properly calibrated, monitored, and aligned with operational needsWork with the SOC and service providers to enhance detection quality and cut down on false positivesOperational Governance & ComplianceTranslate cybersecurity policies into practice by embedding requirements into IT workflowsMaintain compliance with applicable regulations and frameworks (e.g. NIS2, CRA, ISO/IEC 27001)Keep security procedures and documentation clear, usable, and up to dateCoordination & CollaborationServe as the operational link between IT teams (Infrastructure, Support, Applications) and governance functionsPartner closely with Infrastructure (TST) and Support (SST) teams to define secure configuration baselinesLiaise with external providers (SOC, MSSP, penetration testers)People & Resource ManagementManage Cyber Security Analysts, including onboarding, task prioritization, coaching, and performance follow-upSupervise internal and external security resources based at headquarters or remote sitesSupport security awareness initiatives and technical training for IT staffReporting & Continuous ImprovementMaintain dashboards, KPIs, and indicators tracking operational security performanceSpot opportunities for improvement and quick winsHelp shape the cybersecurity roadmap from an execution-focused perspectiveProfileExperience & BackgroundProven hands-on experience in cybersecurity — SOC, SecOps, or Blue Team rolesDemonstrated ability to work autonomously, take ownership, and drive initiatives forwardExperience navigating complex IT environments (infrastructure, networks, cloud, endpoints)Initial exposure to leading or coordinating teams and activities (formal or informal leadership)Skills & MindsetStrong hands-on, execution-oriented mindsetSolid grasp of incident response, threat detection, and vulnerability managementAbility to translate security requirements into pragmatic IT practicesComfortable managing multiple stakeholders and external providersClear, structured, and pragmatic communication styleStrong sense of initiative, accountability, and ownershipRequired Hands-On ExposureCandidates must demonstrate practical experience in the following areas:Monitoring and detection tooling, such as SIEM and/or EDR platforms, including alert analysis, investigation, and tuningVulnerability management, including assessment, prioritization, remediation tracking, and follow-up with IT teamsRegulatory and security frameworks (e.g. NIS2, ISO 27K), approached from an implementation standpoint rather than a purely theoretical oneWorking alongside a SOC or m