Talent.com
Salt
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASPSalt • Brussels Region, Belgium
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP

Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP

Salt • Brussels Region, Belgium
1 dag geleden
Functieomschrijving

Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP

Location: Brussels , Paris, London or Amsterdam

Contract: Long-term contract

Working Model: Hybrid

Hiring: Multiple positions available


The Opportunity

We are looking for experienced Senior Cyber Security Risk Assessment Consultants to join a major Cyber & Information Security function within a global financial services environment.

You will provide security expertise across a broad portfolio of business and technology projects, working closely with architects, engineers, developers, project teams, risk management and business stakeholders.


A key part of the position is performing technical security risk assessments, translating identified risks into security requirements, reviewing and validating solution designs, and defining appropriate security testing requirements.

This is not a SOC or purely operational security role. We are looking for experienced security professionals who can understand complex technical solutions, identify security risks and vulnerabilities, and advise projects on the controls required to achieve Secure by Design.


Key Responsibilities

  • Perform security risk assessments across business and IT projects.
  • Identify threats, vulnerabilities, security weaknesses and potential impacts within proposed solutions.
  • Translate security architecture, policies, risks and controls into clear functional and technical security requirements.
  • Define and advise on the design, implementation and testing processes required to protect information systems and assets.
  • Embed Secure by Design principles throughout the technology delivery lifecycle.
  • Contribute to architectural and solution design discussions and validate designs against security requirements.
  • Review applications, platforms and infrastructure from a security perspective.
  • Define application security testing requirements, including appropriate use of DAST, SAST, code scanning and penetration testing.
  • Define penetration-testing scope and work closely with security-testing teams throughout execution.
  • Review security-testing and penetration-testing reports and assess whether identified risks have been appropriately addressed.
  • Apply OWASP principles and guidelines when assessing application security.
  • Identify security gaps and recommend appropriate remediation and compensating controls.
  • Produce and maintain security standards, principles, baselines and documented security requirements.
  • Recommend new or improved security services and controls.
  • Act as a Security Subject Matter Expert for project and business teams.
  • Present security risks, findings and recommendations clearly to both senior stakeholders and deep technical specialists.
  • Work closely with Business Owners, Business Analysts, Project Managers, Risk Management, Architects, Developers, Engineers and internal/external auditors.


Application Security / DAST / OWASP

We are particularly interested in candidates with strong knowledge of Application Security and experience across areas such as:

  • OWASP Top 10 and wider OWASP security principles
  • DAST / Dynamic Application Security Testing
  • SAST / Static Application Security Testing
  • Secure SDLC / Secure by Design
  • Application vulnerability assessment
  • Web application security
  • API security
  • Code scanning and security-analysis tooling
  • Penetration-testing methodology and scoping
  • Security testing and test-result validation
  • CI/CD security controls
  • DevSecOps
  • Security and compliance automation


You do not need to be a hands-on penetration tester, but you should have sufficient technical knowledge to define security-testing requirements, scope appropriate testing, challenge findings and determine whether security risks have been adequately addressed.

Broader Security Knowledge


Alongside application security, candidates should bring knowledge across one or more additional Cyber & Information Security domains, which could include:

  • Identity & Access Management / IAM / IDaaS
  • PAM, authentication, authorisation and federation
  • PKI, cryptography, encryption and key management
  • Network and DMZ security
  • WAFs and network segmentation
  • Endpoint and platform security
  • Data protection and DLP
  • Azure / AWS / Cloud Security
  • IaaS / PaaS / SaaS
  • Virtualisation
  • Windows / Linux security
  • Database and storage security
  • Infrastructure as Code
  • Infrastructure and security automation

We are not expecting candidates to be specialists across every security domain.


Your Experience

For the senior positions, we are looking for candidates with:

  • 10+ years' experience within Cyber / Information Security.
  • Proven experience performing technical security risk assessments.
  • Strong understanding of application and/or infrastructure security.
  • Experience identifying security risks and translating these into practical security requirements and controls.
  • Experience contributing to and/or validating technical and architectural solution designs.
  • Strong knowledge of OWASP and application-security principles.
  • Experience with DAST, SAST, vulnerability assessment, penetration testing or related security-testing approaches.
  • Experience defining security-testing requirements and reviewing the resulting findings.
  • Ability to understand complex applications, infrastructure and technology architectures.
  • Experience producing security documentation, standards, principles, requirements or baselines.
  • Experience translating business requirements into appropriate technical security solutions.
  • Strong analytical and critical-thinking skills.
  • Ability to take ownership of security assessments and work independently across multiple projects.
  • Excellent stakeholder-management and communication skills.
  • Ability to explain and defend security recommendations with both senior business stakeholders and highly technical IT professionals.
  • Experience working within large, complex enterprise environments.
  • Fluent English.

Experience within banking, financial services, payments, financial-market infrastructure or another highly regulated/critical environment would be particularly valuable.

Certifications

Relevant professional certifications are advantageous, including:

CISSP | GIAC | SABSA | ISO 27001 Lead Auditor / Lead Implementer


Maak een vacature-alert aan voor deze zoekopdracht

Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP • Brussels Region, Belgium

Vergelijkbare banen

Technical Specialist

Educam NVCharleroi, BE

EDUCAM est le centre de connaissance et de formation des employeurs et des (futurs) travailleurs actifs dans le secteur automobile et les secteurs connexes.Vous êtes passionné(e) par la technique e... Laat meer zien

 • Gesponsord

Consultant

Bain & Company IncBE

To view the Consultant job description for our Montreal office, click here.Imagine a role that builds on your academic and personal capabilities, providing the most interesting business challenges ... Laat meer zien

Cyber Security Engineer

Trusted AdvisorsBrussels, Belgium

As cybersecurity engineer you will join the Security Center of Expertise and together with your peers make the cyber resilience of our enterprise your 1st priority.You’re the trusted security advis... Laat meer zien

Sales Effectiveness Analyst

Amoria BondCharleroi, BE

Sales Effectiveness Analyst (Excellence) | 40 hrs/week We are looking for a proactive and analytical CRM & Salesforce Analyst to support the day-to-day operations of our Veeva CRM system — and Sal... Laat meer zien

 • Gesponsord

QA validation

Vulcain Engineering Group | BelgiumCharleroi, BE

Vulcain Engineering Belgium is looking for a QA validation Engineer to join its team.As a QA validation at Vulcain Engineering Belgium, you will work on projects in the biotech or pharmaceutical in... Laat meer zien

 • Gesponsord

SAP Senior/Lead Consultant SD

CNT Management ConsultingCharleroi, wallonia, Belgium

As a leading consulting company for SAP software, especially for SAP S/4HANA transformations and SAP Cloud solutions, CNT Management Consulting has been one of the top international consultancies f... Laat meer zien

 • Gesponsord

Senior Cybersecurity Strategy Consultant

Editxsint agatha berchem, brussel hoofdstad, Belgium

At Secamo, we help organizations build cyber resilience through strategy, controls, and continuous monitoring — across IT, OT, and cloud environments.To support our growth, we’re looking for a moti... Laat meer zien

 • Gesponsord

Spontaneous Application: Consulting Engineer (m/f/x)

agap2 BelgiumCharleroi, BE

European engineering consultancy active across various industrial sectors such as large infrastructure works, process industries (life science, food & beverage, chemistry), energy, and transport.Pr... Laat meer zien

 • Gesponsord

Conseiller - Assurances Non-Vie

Wilink InsuranceCharleroi, BE

A travers ses 13 bureaux et grâce à l’expertise de ses 220 collaborateurs, Wilink apporte des solutions adaptées aux besoins de ses 110.Que ce soit pour la protection des risques (via son pôle de c... Laat meer zien

 • Gesponsord

Test Engineer

SII Group BelgiumCharleroi, wallonia, Belgium

We are looking for an IVVQ Engineer to lead system integration, verification, validation, and qualification activities across innovative, high-impact projects.In this role, you will oversee the ful... Laat meer zien

 • Gesponsord

Cybersecurity Consultant (Medior)

CyberwiseBelgium

Cyberwise is een onafhankelijke cybersecurity consultancy die organisaties helpt om hun cybersecurity op een pragmatische en resultaatgerichte manier te versterken.We begeleiden klanten met technis... Laat meer zien

 • Gesponsord

Senior Penetration Tester/Red Team Operator

The Nippon Telegraph and Telephone Corporation (NTT), , belgium, Belgium

Senior Penetration Tester/Red Team Operator.Active Directory, Containers, Web Browsers, OT, IoT, …).Participate to client needs capture and translation into commercial proposals.Manage and guide ju... Laat meer zien

 • Gesponsord

Manager Cyber Strategy & Risk

KPMG BelgiumZaventem, flanders, Belgium

As a Manager within our Cybersecurity Strategy & Risk practice, you will lead multidisciplinary teams to help clients protect their critical assets, manage cybersecurity risks and meet evolving reg... Laat meer zien

 • Gesponsord

Clinical Software Sales Representative – Health Information Systems

Inizio EngageCharleroi, wallonia, Belgium

Clinical Software Sales Representative – Health Information Systems.Belgium | Hybrid (Diegem) | Up to 60% travel.A leading international healthcare IT company is looking for a Clinical Software Sal... Laat meer zien

 • Gesponsord

Senior Consultant – Enterprise Risk Management

BDO BelgiumZaventem, flanders, Belgium

Ready to make your career count? Lead risk management projects, mentor your junior colleagues and work for international clients as Senior Consultant in our Risk Advisory team in Zaventem!.This is ... Laat meer zien

 • Gesponsord

Senior Cybersecurity Analyst

SmalsSaint-Gilles, Bruxelles-Capitale, Belgium

Smals realiseert innovatieve ICT-projecten in e-government en e-health voor instellingen uit de sociale zekerheid en de gezondheidszorg.ICT for society' is voor Smals meer dan een slogan: alle proj... Laat meer zien

 • Gesponsord

SAP Consultant

delaware BeLuxCharleroi, wallonia, Belgium

Experienced SAP Consultant – End-to-End Transformations.At delaware, SAP is not just about systems.It's about making businesses work smarter.You'll work on transformation projects where business an... Laat meer zien

 • Gesponsord

Product Engineer

ICsenseCharleroi, wallonia, Belgium

The job location can be Leuven or Ghent.The Product Engineer is responsible for ASIC products from product development kick-off until end of life.The Product Engineer will be responsible for defini... Laat meer zien

 • Gesponsord

Egov Select - Security Operations Specialist

Egov SelectSint-Gillis, Belgium

Werkomgeving De IT-afdeling van SPF BOSA binnen het Directoraat-Generaal Interne Ondersteuningsdienst (DG SAI / IOD) is verantwoordelijk voor alle IT-technische aspecten van de interne toepassingen... Laat meer zien

 • Gesponsord

Threat Detection Engineer - Splunk Developer

InnoboBelgium, Brussels, Belgium, PL

EU-based), 8 days/month on-site in Brussels or London or Amsterdam or Paris.Interact with the different customers to capture and define requirements for the development and testing of the threat de... Laat meer zien