Senior Security Officer

Onetowin

Brussel Hoofdstad

Hybride

EUR 90 000 - 120 000

Temps partiel

Il y a 11 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Résumé du poste

Onetowin seeks a Senior Security Officer to identify, analyze, and mitigate IT and cyber risks from design through execution, bridging complex architectures with GRC needs. The role demands collaboration with Architects and DevOps while maintaining strict regulatory alignment.

You will lead on-site workshops, assess critical projects, and drive remediation across the portfolio, delivering clarity to executives on risk and controls in a fast-moving environment.

Qualifications

  • Availability to commit to a 3‑day work week with on-site presence for at least 2 days.
  • Expert knowledge of Cyber frameworks (ISO 27001/27002/27005, NIST) and the NIS2 directive.
  • Proven ability to apply OWASP Risk Rating Methodology and perform architecture reviews (Cloud/GCP).
  • Hunter mentality to identify hidden risks by digging through technical docs.
  • Fluency in English and ability to simplify security topics for non‑tech stakeholders.
  • 5+ years in Cyber Security, specifically in a GRC or Security Architecture role.

Responsabilités

  • Technical Risk Decomposition: deconstruct architectures and data flows to identify vulnerabilities using OWASP and ISO 27005.
  • Cross-Functional Collaboration: partner with Architects and DevOps to integrate security without delaying delivery.
  • Compliance Oversight: ensure adherence to GDPR, NIS2, and internal security policies throughout projects.
  • Architecture Deep-Dives: analyze APIs and micro-services for OWASP Top 10 flaws and secure designs.
  • Third-Party Security: conduct security reviews of external contracts and providers.
  • On-site Stakeholder Engagement: lead workshops translating regulatory requirements into technical controls.
  • Reporting: translate risks into actionable business insights for management.

Connaissances

3-day week
Cyber frameworks
Technical risk reviews
Analytical mindset
Clear communication
5+ years security

Description du poste

To secure our client's critical projects by identifying, analyzing, and mitigating IT and cyber risks from the design phase. The mission is to bridge the gap between complex technical architectures and GRC requirements, ensuring all high-impact initiatives are resilient and compliant.
01 quantitative data

  • Scope: 100% of projects classified as "Critical" or "High Impact" within the company's portfolio.
  • On-site Presence: Minimum of 2 days per week on-site to facilitate technical deep-dives and face-to-face stakeholder alignment.
  • Risk Reduction: Direct impact on reducing the company's cyber-exposure through proactive remediation tracking.
Senior Security Officer

To secure our client's critical projects by identifying, analyzing, and mitigating IT and cyber risks from the design phase. The mission is to bridge the gap between complex technical architectures and GRC requirements, ensuring all high-impact initiatives are resilient and compliant.
01 quantitative data

  • Scope: 100% of projects classified as "Critical" or "High Impact" within the company's portfolio.
  • Work Rhythm: Part-time position (3 days per week).
  • On-site Presence: Minimum of 2 days per week on-site to facilitate technical deep-dives and face-to-face stakeholder alignment.
  • Risk Reduction: Direct impact on reducing the company's cyber-exposure through proactive remediation tracking.
02 Key Responsibilities
  • Technical Risk Decomposition: Deconstruct complex project architectures and data flows to identify underlying security vulnerabilities. This involves applying OWASP Risk Rating Methodology for application-level threats alongside ISO 27005 for systemic IT risks.
  • Cross-Functional Collaboration: Partner with Architects and DevOps teams to integrate security controls without stalling delivery velocity.
  • Compliance Oversight: Ensure strict adherence to internal security policies and mandatory regulations, including GDPR and NIS2, throughout the project lifecycle.
  • Architecture Deep-Dives: Analyze software design (APIs, micro-services) to detect flaws such as those listed in the OWASP Top 10, ensuring security is baked into the design.
  • Third-Party Security: Conduct security reviews of external contracts and technical assessments of critical service providers.
  • On-site Stakeholder Engagement: Lead in-person workshops with Architects and Product Owners to translate regulatory requirements into technical controls.
  • Reporting: Translate technical risks into clear, actionable business insights for management and steering committees.
03 Key Performance Indicators
  • Assessment Coverage: Percentage of critical projects analyzed before the production "Go-Live."
  • Remediation Rate: Percentage of high-risk findings successfully addressed or formally accepted by stakeholders.
  • Risk Prediction Reliability: Zero major security vulnerabilities discovered in production that were not previously identified during the GRC assessment phase.
  • Turnaround Time: Average duration between project intake and the finalization of the security risk report.
04 Skills Required
  • Availability & Location: Ability to commit to a 3-day work week, with a mandatory presence on-site for at least 2 of those days.
  • Framework Mastery: Expert knowledge of Cyber frameworks (ISO 27001/27002/27005, NIST) and the NIS2 directive.
  • Technical Risk Expertise: Proven ability to apply OWASP Risk Rating Methodology and perform technical architecture reviews (Cloud/GCP environment).
  • Analytical Mindset: A "hunter" mentality for risks, capable of digging into technical documentation to find hidden gaps.
  • Communication: Fluency in English, with the ability to simplify complex security issues for non-technical stakeholders.
  • Experience: 5+ years in Cyber Security, specifically in a GRC or Security Architecture role.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

AISB-1050 Senior Application Security Analyst (Risk-Oriented)
AISB-1050 Senior Application Security Analyst (Risk-Oriented)

Abakus IT-Solutions • Namen

Hybride
EUR 70 000 - 110 000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

keystone-solutions • Brussel

Sur place
EUR 120 000 - 150 000
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP

Salt • Brussel Hoofdstad

Hybride
EUR 90 000 - 140 000
Strategic Security Architect & GRC Lead (Hybrid)
Strategic Security Architect & GRC Lead (Hybrid)

Onetowin • Brussel Hoofdstad

Hybride
EUR 90 000 - 120 000
Consultant
Consultant

E-Resourcing Ltd - Specialist I.T. Recruitment • Brussel Hoofdstad

Sur place
EUR 90 000 - 130 000
Cybersecurity architect (focus Operational Technology)
Cybersecurity architect (focus Operational Technology)

USG Professionals Belgium • Zaventem

Sur place
EUR 90 000 - 120 000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Keystone Solutions • Brussel

Sur place
EUR 90 000 - 130 000
Senior Security Compliance Officer – NIS2 & ISO 27001
Senior Security Compliance Officer – NIS2 & ISO 27001

Pauwels Consulting • Brussel

Hybride
EUR 90 000 - 120 000
Security Coordinator
Security Coordinator

Editx • Brussel

Sur place
EUR 70 000 - 110 000
Cyber Security Project Manager
Cyber Security Project Manager

La Fosse • Brussel

Sur place
EUR 90 000 - 120 000