Cybersecurity Analyst Vulnerability & Attack Surface Management

Harvey Nash

Brussel Hoofdstad

Sur place

EUR 60 000 - 90 000

Plein temps

Il y a 4 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’il recherche.

Passez les filtres ATS

Résumé du poste

Harvey Nash is seeking a Cybersecurity Analyst focusing on Vulnerability Management and Attack Surface Management. The role emphasizes analyzing vulnerabilities, validating findings, and delivering actionable remediation guidance.

You will automate data collection using Python and integrate systems to streamline reporting. The position involves working with internal teams, external providers, and local authorities to ensure timely communication of risks and effective remediation actions.

Qualifications

  • Minimum 3 years as Cybersecurity Analyst in Vulnerability Management.
  • Experience translating technical findings for technical and non-technical audiences.

Responsabilités

  • Analyze vulnerabilities and exposures from multiple sources.
  • Validate findings, filter noise, and assess actual impact.
  • Prioritize findings based on risk, CVSS/EPSS, and context.
  • Develop and maintain Python scripts and API integrations for data collection and reporting.
  • Support remediation tracking for client and local authorities.
  • Contribute to cyber awareness initiatives and phishing simulations.
  • Document processes and continually improve methodologies.

Connaissances

Python scripting
Automation
Vulnerability management
Risk assessment
Security governance

Outils

Jira
ServiceNow

Description du poste

Cybersecurity Analyst - Vulnerability & Attack Surface Management
Description

As a Cybersecurity Analyst - Vulnerability & Attack Surface Management, you will support the further development, execution, and optimization of services related to vulnerability management, attack surface management, and cyber awareness.

You will analyze, assess, and follow up on information regarding vulnerabilities, exposed systems, and security risks. You will validate findings, place them in the appropriate risk context, and translate them into concrete recommendations. In doing so, you will support our client's entities and local authorities in prioritizing and tracking remediation actions.

Automation is an essential part of the role. Given the large volume of sources, data, and stakeholders involved, you will develop and maintain scripts, primarily in Python, as well as integrations that support the collection, enrichment, correlation, follow-up, and reporting of vulnerability information.

You will work closely with internal teams, external service providers, and representatives of our client's entities and local authorities. Your objective is to ensure vulnerabilities and exposed systems are identified and communicated in a timely manner, together with actionable recommendations, enabling organizations to effectively remediate identified risks.

In addition, you will support initiatives related to cyber awareness and phishing simulations.

This is primarily an operational and support-oriented role, combining technical expertise with a strong hands-on focus. Besides analyzing and following up on cases, you will play an active role in the day-to-day delivery of the service and contribute to the further professionalization of processes, methodologies, and supporting solutions.

Key Responsibilities
  • Analyze vulnerabilities and exposures based on a variety of information sources.
  • Validate findings, filter out noise and false positives, and assess the actual impact on affected organizations.
  • Prioritize findings based on risk, considering factors such as CVSS scores, EPSS scores, exploitation status, and organizational context.
  • Derive both overarching trends and organization-specific recommendations from analyzed data.
  • Communicate findings through existing reporting and communication channels tailored to the relevant target audiences.
  • Develop and maintain Python scripts and API integrations for data collection, enrichment, correlation, and reporting.
  • Support our client and local authorities in tracking remediation activities.
  • Assist in the preparation, execution, and evaluation of cyber awareness initiatives and phishing simulations.
  • Contribute to the documentation, standardization, and continuous improvement of processes, methodologies, and supporting solutions.
Required Experience and Qualifications
  • Proven experience as a Security Consultant within one or more of the following domains: data, infrastructure, applications, or related environments.
  • Demonstrated expertise in a specific area of information security, such as:
  • Implementing information security management processes
  • Conducting vulnerability assessments and penetration testing
  • Improving application security through cost-effective measures
  • Implementing Privileged Access Management (PAM) solutions
  • Implementing encryption solutions
  • Proven experience in analyzing, optimizing, and documenting security processes and governance.
  • Proven experience with security management techniques and frameworks, such as:
  • ISO 27000 series
  • COBIT for Security
  • NIST
  • OWASP
  • CIS Critical Security Controls
  • Demonstrable knowledge and certifications relevant to the area of expertise (e.g., CISM, CISSP, CEH).
Language requirement:

Native-level Dutch (CEFR C2).

Skills & Requirements
Must-Have
  • Minimum 3 years of experience as a Cybersecurity Analyst in Vulnerability Management, including:
  • Vulnerability identification
  • Validation
  • Risk-based prioritization
  • Remediation follow-up
  • Minimum 3 years of experience as a Security Consultant in data, infrastructure, application security, or similar environments.
  • Proven experience in analyzing, optimizing, and documenting security processes and governance.
  • Proven experience with Python scripting and automation, including:
  • API integrations
  • Data processing
  • Automated reporting
  • Minimum 3 years of experience with vulnerability scanning and exposure management solutions, including configuration, execution, and interpretation of scans.
  • Proven expertise in a specific information security domain.
Preferred (Should-Have)
  • Minimum 3 years of experience translating technical findings into reports and recommendations for both technical and non-technical audiences.
  • Minimum 3 years of experience with ticketing and workflow systems used for vulnerability and remediation tracking, such as:
  • Jira
  • ServiceNow
  • Experience with security management frameworks such as ISO 27000, COBIT, NIST, OWASP, and CIS Controls.
  • Relevant security certifications such as CISM, CISSP, CEH, or equivalent.
Nice-to-Have
  • Minimum 3 years of experience with cyber awareness programs and phishing simulation initiatives.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Cybersecurity Analyst Vulnerability & Attack Surface Management
Cybersecurity Analyst Vulnerability & Attack Surface Management

Harvey Nash • Brussel

Sur place
EUR 70 000 - 90 000
Cyber Security Analyst
Cyber Security Analyst

OneSource Consulting • Brussel Hoofdstad

Sur place
EUR 55 000 - 90 000
Cybersecurity Analyst – Python & Vulnerability Management
Cybersecurity Analyst – Python & Vulnerability Management

Pauwels Consulting • Brussel

Hybride
EUR 55 000 - 80 000
Vulnerability & Attack Surface Analyst (Cyber Defense)
Vulnerability & Attack Surface Analyst (Cyber Defense)

OneSource Consulting • Brussel Hoofdstad

Sur place
EUR 55 000 - 90 000
Team Lead – Vulnerability Management Expert
Team Lead – Vulnerability Management Expert

afarax • Brussel

Sur place
EUR 90 000 - 130 000
Junior Functional Security Analyst
Junior Functional Security Analyst

Nexeo • Brussel Hoofdstad

Sur place
EUR 30 000 - 42 000
Cybersecurity Analyst Vulnerability Management & Attack Surface (Freelance mogelijk)
Cybersecurity Analyst Vulnerability Management & Attack Surface (Freelance mogelijk)

EngiFlex BV • Brussel Hoofdstad

Hybride
EUR 60 000 - 90 000
Bedrijfswagen
Extralegale voordelen
IT Security Analyst
IT Security Analyst

Source Technology Limited • Antwerpen

Hybride
EUR 27 675 000 - 33 210 000
Junior Functional Security Analyst
Junior Functional Security Analyst

Nexeo • Brussel

Sur place
EUR 38 000 - 52 000
Vulnerability Management Analyst — Remediation Tracking for NATO with security clearance
Vulnerability Management Analyst — Remediation Tracking for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 90 000