JustJoin.IT Praca zdalna Senior

Cybersecurity Expert (m/f/n)

Shimi Sp. z o.o.

⚲ Bruksela

9 450 - 11 340 EUR netto (B2B)

Wymagania

  • Security Governance
  • Risk Management
  • identity and access management principles
  • Vulnerability Management

Opis stanowiska

Currently, for one of our Partners, a European Union Organisation based in Brussels, we are looking for an experienced Cybersecurity Expert (m/f/n) to join a long-term international project.

Requirements:


At least 5 years of professional experience in cybersecurity, information security, IT security, IT risk management, security governance, or equivalent cybersecurity-related roles on IT projects.

• At least 4 years of experience acting as Security Officer, Cybersecurity Expert, cybersecurity focal point, security consultant, CISO-office consultant, IT risk consultant, security governance consultant, or equivalent role.
• At least 4 years of experience acting as the main cybersecurity reference or one of the main cybersecurity references within an IT project, service, or programme.
• At least 2 years of experience with information security risk assessments, risk treatment, risk registers, and remediation follow-up.
• At least 2 years of experience defining, reviewing, or validating security requirements for IT systems, applications, suppliers, infrastructure, cloud environments, or technical solutions.
• At least 2 years of experience supporting audits, security assessments, certification activities, penetration tests, vulnerability management, or remediation tracking.
• At least 2 years of experience preparing cybersecurity documentation, reports, procedures, risk assessments, meeting materials, and management briefings.


Language: English – minimum B2 level (CEFR).

Technical skills:
• At least 2 years in information security governance, risk management, compliance and security control frameworks, including standards such as ISO 27001, ISO 27002, ISO 27005, NIST, CIS Controls, OWASP or equivalent.
• At least 2 years in identity and access management principles, including authentication, authorisation, privileged access, role-based access control and segregation of duties.
• At least 2 years in vulnerability management and penetration testing processes, including incident management and corrective action follow-up.
• At least 2 years in the elaboration of technical documentation, project deliverables, audit evidence, risk documentation and security reports.
• At least 1 year in supplier and third-party security management.
• At least 1 year in cryptographic concepts, including public/private key cryptography, digital signatures, hashing, certificates and key management.
• At least 1 year in secure software development lifecycle principles and common application security risks.
• At least 1 year in cloud security fundamentals, including secure configuration, access control, logging, encryption, monitoring and shared responsibility models.
• At least 1 year in network and infrastructure security fundamentals.
• At least 1 year in logging, monitoring, alerting and security event escalation principles.


Lead Auditor ISO/IEC 27001 or similar.

Responsibilities:
• Act as Security Officer or Cybersecurity Expert in IT projects, services, or programmes.
• Provide cybersecurity guidance to project teams during the project lifecycle.
• Identify applicable security requirements, risks, and controls.
• Define, review, and validate security requirements for applications, platforms, infrastructure, cloud services, suppliers, and technical solutions.
• Perform and maintain information security risk assessments.
• Maintain risk registers, define treatment plans, and follow up on remediation actions.
• Contribute to the definition of cybersecurity strategy, security direction, security roadmaps, and security improvement plans.
• Support secure-by-design activities and ensure security controls are considered during project delivery.
• Review and follow up on vulnerabilities, penetration test findings, audit findings, and security weaknesses.
• Coordinate vulnerability management, penetration testing, security assessments, and remediation tracking.
• Support supplier security assessments, third-party risk reviews, evidence analysis, and remediation follow-up when applicable.
• Support incident management activities, including escalation, coordination, documentation, lessons learned, and corrective actions.
• Support compliance with cybersecurity policies, contractual obligations, regulatory requirements, and recognised security standards.
• Prepare and maintain security documentation, including policies, procedures, security plans, reports, dashboards, and management briefings.
• Participate in project boards, technical meetings, supplier meetings, audit meetings, and security reviews.
• Promote cybersecurity awareness and provide practical security guidance to project stakeholders.

Our offer:


Long-term B2B cooperation with SHIMI



Project duration of up to 48 months



Competitive rate of 450-540 EUR/day 

• Location: Mostly remote setup. Services must be performed from within the EU. Two physical meetings with the customer are foreseen per 12-month period, max 2 days each. These planned meetings are at contractor’s cost.
• International and multicultural working environment.
• Collaboration with highly skilled professionals from across Europe.

🔍 Dekoder Ogłoszenia

🔴
long-term international project
Może oznaczać projekt o nieokreślonym czasie trwania, który może zostać zakończony w każdej chwili, lub projekt z potencjałem na przedłużenie, ale bez gwarancji.
🔴
equivalent cybersecurity-related roles on IT projects
Zakres ról jest bardzo szeroki i może obejmować zadania, które nie są bezpośrednio związane z zaawansowanym cyberbezpieczeństwem.
🔴
one of the main cybersecurity references
Może oznaczać, że będziesz jednym z wielu ekspertów, a nie główną osobą decyzyjną.
🔴
supporting audits, security assessments, certification activities, penetration tests, vulnerability management, or remediation tracking
Zakres obowiązków jest bardzo szeroki i może oznaczać, że będziesz wykonywać głównie zadania pomocnicze, a nie strategiczne.
🔴
preparing cybersecurity documentation, reports, procedures, risk assessments, meeting materials, and management briefings
Duży nacisk na dokumentację i raportowanie, co może oznaczać mniej czasu na faktyczne działania techniczne.