Talent.com
LinkedIn
Senior Cyber Security Risk Assessment Consultant – Dast / Sast/ OwaspLinkedIn • Sint-Gillis, Belgium
Senior Cyber Security Risk Assessment Consultant – Dast / Sast/ Owasp

Senior Cyber Security Risk Assessment Consultant – Dast / Sast/ Owasp

LinkedIn • Sint-Gillis, Belgium
18 uur geleden
Functieomschrijving

Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP


Considering applying for this job Do not delay, scroll down and make your application as soon as possible to avoid missing out.

Location: Brussels, Paris, London or Amsterdam

Contract: Long-term contract

Working Model: Hybrid

Hiring: Multiple positions available

The Opportunity

We are looking for experienced Senior Cyber Security Risk Assessment Consultants to join a major Cyber & Information Security function within a global financial services environment.

You will provide security expertise across a broad portfolio of business and technology projects, working closely with architects, engineers, developers, project teams, risk management and business stakeholders.

A key part of the position is performing technical security risk assessments, translating identified risks into security requirements, reviewing and validating solution designs, and defining appropriate security testing requirements.

This is not a SOC or purely operational security role. We are looking for experienced security professionals who can understand complex technical solutions, identify security risks and vulnerabilities, and advise projects on the controls required to achieve Secure by Design.

Key Responsibilities

  • Perform security risk assessments across business and IT projects.
  • Identify threats, vulnerabilities, security weaknesses and potential impacts within proposed solutions.
  • Translate security architecture, policies, risks and controls into clear functional and technical security requirements.
  • Define and advise on the design, implementation and testing processes required to protect information systems and assets.
  • Embed Secure by Design principles throughout the technology delivery lifecycle.
  • Contribute to architectural and solution design discussions and validate designs against security requirements.
  • Review applications, platforms and infrastructure from a security perspective.
  • Define application security testing requirements, including appropriate use of DAST, SAST, code scanning and penetration testing.
  • Define penetration-testing scope and work closely with security-testing teams throughout execution.
  • Review security-testing and penetration-testing reports and assess whether identified risks have been appropriately addressed.
  • Apply OWASP principles and guidelines when assessing application security.
  • Identify security gaps and recommend appropriate remediation and compensating controls.
  • Produce and maintain security standards, principles, baselines and documented security requirements.
  • Recommend new or improved security services and controls.
  • Act as a Security Subject Matter Expert for project and business teams.
  • Present security risks, findings and recommendations clearly to both senior stakeholders and deep technical specialists.
  • Work closely with Business Owners, Business Analysts, Project Managers, Risk Management, Architects, Developers, Engineers and internal/external auditors.

Application Security / DAST / OWASP

We are particularly interested in candidates with strong knowledge of Application Security and experience across areas such as:

  • OWASP Top 10 and wider OWASP security principles
  • DAST / Dynamic Application Security Testing
  • SAST / Static Application Security Testing
  • Secure SDLC / Secure by Design
  • Application vulnerability assessment
  • Web application security
  • API security
  • Code scanning and security-analysis tooling
  • Penetration-testing methodology and scoping
  • Security testing and test-result validation
  • CI/CD security controls
  • DevSecOps
  • Security and compliance automation

You do not need to be a hands-on penetration tester, but you should have sufficient technical knowledge to define security-testing requirements, scope appropriate testing, challenge findings and determine whether security risks have been adequately addressed.

Broader Security Knowledge

Alongside application security, candidates should bring knowledge across one or more additional Cyber & Information Security domains, which could include:

  • Identity & Access Management / IAM / IDaaS
  • PAM, authentication, authorisation and federation
  • PKI, cryptography, encryption and key management
  • Network and DMZ security
  • WAFs and network segmentation
  • Endpoint and platform security
  • Data protection and DLP
  • Azure / AWS / Cloud Security
  • IaaS / PaaS / SaaS
  • Virtualisation
  • Windows / Linux security
  • Database and storage security
  • Infrastructure as Code
  • Infrastructure and security automation

We are not expecting candidates to be specialists across every security domain.

Your Experience

For the senior positions, we are looking for candidates with:

  • 10+ years' experience within Cyber / Information Security.
  • Proven experience performing technical security risk assessments.
  • Strong understanding of application and/or infrastructure security.
  • Experience identifying security risks and translating these into practical security requirements and controls.
  • Experience contributing to and/or validating technical and architectural solution designs.
  • Strong knowledge of OWASP and application-security principles.
  • Experience with DAST, SAST, vulnerability assessment, penetration testing or related security-testing approaches.
  • Experience defining security-testing requirements and reviewing the resulting findings.
  • Ability to understand complex applications, infrastructure and technology architectures.
  • Experience producing security documentation, standards, principles, requirements or baselines.
  • Experience translating business requirements into appropriate technical security solutions.
  • Strong analytical and critical-thinking skills.
  • Ability to take ownership of security assessments and work independently across multiple projects.
  • Excellent stakeholder-management and communication skills.
  • Ability to explain and defend security recommendations with both senior business stakeholders and highly technical IT professionals.
  • Experience working within large, complex enterprise environments.
  • Fluent English. xlxgzvr

Experience within banking, financial services, payments, financial-market infrastructure or another highly regulated/critical environment would be particularly valuable.

Certifications

Relevant professional certifications are advantageous, including:

CISSP | GIAC | SABSA | ISO 27001 Lead Auditor / Lead Implementer

Maak een vacature-alert aan voor deze zoekopdracht

Senior Cyber Security Risk Assessment Consultant – Dast / Sast/ Owasp • Sint-Gillis, Belgium

Vergelijkbare banen

Freelance Senior Information Security Consultant

CRANIUMZaventem, VLG, BE

Help organisations build security that sticks.Cybersecurity shouldn’t be a tickbox.At Cingulum, we work various critical sectors to improve resilience, reduce risk, and ensure compliance with frame... Laat meer zien

Application Security Analyst

InterEx GroupBrussels Region, Belgium, Belgium

Unique Security Analyst/ Belgium / Cybersecurity.We are working exclusively with a top partner in cyber security who is currently expanding their security presence in Belgium, due to their rapid gr... Laat meer zien

 • Gesponsord

Senior Cybersecurity Analyst M/V/X

ActirisSint-Gillis, BE

Beschrijving van de functie Smals realiseert innovatieve ICT-projecten in e-government en e-health voor instellingen uit de sociale zekerheid en de gezondheidszorg.ICT for society' is voor Smals m... Laat meer zien

 • Gesponsord

Cyber Security Engineer

Trusted AdvisorsBrussels, Belgium

As cybersecurity engineer you will join the Security Center of Expertise and together with your peers make the cyber resilience of our enterprise your 1st priority.You’re the trusted security advis... Laat meer zien

Solution Architect

Connect Consultinganderlecht, brussel hoofdstad, Belgium

Solution Architect for Physical security Network (OT) - Job Description /h3 pSolution Architect for supporting OT and IT projects regarding Physical Security.Becoming part of a Team of 14 engineer... Laat meer zien

 • Gesponsord

Senior Red Team Engineer — Penetration Testing Lead

The Nippon Telegraph and Telephone Corporation (NTT), , belgium, Belgium

The Nippon Telegraph and Telephone Corporation (NTT) is looking for a Senior Penetration Tester/Red Team Operator in Belgium.This role involves conducting security tests, managing junior colleagues... Laat meer zien

 • Gesponsord

Senior Cybersecurity Strategy Consultant

Editxsint agatha berchem, brussel hoofdstad, Belgium

At Secamo, we help organizations build cyber resilience through strategy, controls, and continuous monitoring — across IT, OT, and cloud environments.To support our growth, we’re looking for a moti... Laat meer zien

 • Gesponsord

Senior Consultant- Resilience - Digital Risk - Industries

Ernst & Young Advisory Services Sdn Bhddiegem, vlaams brabant, Belgium

Shape the Future with Confidence.EY Consulting is a fast-moving, high-growth area within EY, offering variety, challenge, responsibility and the opportunity to realize your leadership potential.Our... Laat meer zien

 • Gesponsord

Spontaneous Application: Consulting Engineer (m/f/x)

agap2 BelgiumCharleroi, BE

European engineering consultancy active across various industrial sectors such as large infrastructure works, process industries (life science, food & beverage, chemistry), energy, and transport.Pr... Laat meer zien

 • Gesponsord

Security & System Engineer

Jobataa, brussel hoofdstad, Belgium

Je komt terecht in een innovatieve industriële onderneming waar technologie een cruciale rol speelt.Binnen de IT-afdeling werk je nauw samen met een ervaren infrastructuurteam, terwijl je zelf de d... Laat meer zien

 • Gesponsord

Senior Clinical Research Associate

AL SolutionsCharleroi, wallonia, Belgium

Senior Clinical Research Associate - Belgium.Chloe O'Shea has partnered with a small, specialist clinical CRO providing tailored clinical research services across Belgium and the Benelux region.The... Laat meer zien

 • Gesponsord

Cybersecurity Consultant (Medior)

CyberwiseBelgium

Cyberwise is een onafhankelijke cybersecurity consultancy die organisaties helpt om hun cybersecurity op een pragmatische en resultaatgerichte manier te versterken.We begeleiden klanten met technis... Laat meer zien

 • Gesponsord

Junior Information Security Consultant

CRANIUMZaventem, VLG, BE

Cingulum is a dedicated information- & cybersecurity partner, born from the strong foundations of CRANIUM.We specialise in enhancing digital maturity, blending expertise in security, legal stud... Laat meer zien

Customer Experience Center Specialist - Construction Sector

BuildwiseCharleroi, BE

A PROPOS DE NOUS: En tant que centre de recherche et d’innovation fort, dynamique et en pleine croissance, nous sommes constamment à la recherche de nouveaux collègues qui souhaitent contribuer à ... Laat meer zien

 • Gesponsord

Information Security / Resilience (Senior) Manager (m/w/d)

Nviso, brussel hoofdstad, belgium, brussel hoofdstad, Belgium

Information Security / Resilience (Senior) Manager (m/w/d).It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer ... Laat meer zien

 • Gesponsord

Security & Systems Engineer – NIS2 & Hybrid Cloud

VIND! ICTaa, brussel hoofdstad, Belgium

Je combineert technische expertise met ownership in een moderne hybride IT-omgeving en werkt aan uitdagende projecten voor klanten en interne teams met ruimte voor groei en impact op lange termijn. Laat meer zien

 • Gesponsord

Information Security Risk Manager

ORESCharleroi, Belgium

Premier gestionnaire wallon de réseaux de distribution, ORES et ses plus de 2 900 collaborateurs et collaboratrices s’engagent chaque jour pour garantir la distribution de l’énergie en Wallonie.Nou... Laat meer zien

 • Gesponsord

Smals - Cybersecurity Analyst

SmalsSint-Gillis, Belgium

Uw rol Als Cybersecurity Analyst werk je actief samen met een extern team om de volledige beveiligingspositie van de organisatie te versterken en te zorgen voor continue monitoring op de systemen.M... Laat meer zien

 • Gesponsord

Cybersecurity Manager - ISMS & NIS2 Implementation (Public Sector)

KPMG BelgiumZaventem, Flemish Region, Belgium

You support public sector clients in designing, implementing, and operationalising Information Security Management Systems (ISMS) aligned with ISO 27001 and NIS2 requirements.You draft and validate... Laat meer zien

 • Gesponsord

Senior Cybersecurity Analyst

SmalsSaint-Gilles, Bruxelles-Capitale, Belgium

Smals realiseert innovatieve ICT-projecten in e-government en e-health voor instellingen uit de sociale zekerheid en de gezondheidszorg.ICT for society' is voor Smals meer dan een slogan: alle proj... Laat meer zien