Cyber And Information Security Expert
Posted on Apr 29, 2022 by Salt
Salt is currently working with a Financial Services Institution in Brussels who are looking for a Cyber and Information Security Expert.
The Cyber and Information Expert will be joining the CISO team.
We are looking for Cyber & Information Security experts to strengthen our team in our Brussels office with experience in one or more of the following areas:
* Proven experience in security risk assessments, development of functional security requirements, process design and management reporting.
* Familiarity with industry best practices in key security domains like: identity and access management, PKI, network security, data protection.
* Application security knowledge with a good understanding of software development and testing, OWASP (Open Web Application Security Project) guidelines, code scanning tools, security and compliance automation using a CI/CD pipeline.
* Knowledge of and experience with security technologies including IDAAS (Identity as a service) and identity management platforms, Secure access management and federation services, PKI and cryptographic solutions, web application Firewalls, endpoint security
* Knowledge of and experience with security technologies covering domains Virtualisation, Software Defined Networks, Cloud IAAS/PAAS/SAAS, Network and DMZ infrastructure, VOIP, Wifi, 802.1x, Anti-malware, System protection, Middleware, Collaboration and end-user workspace solutions, Storage (SAN, NAS), Databases, infrastructure automation services (Infrastructure as a code)
* Preferred professional certifications are CISSP, GIAC, SABSA, ISO 27001 LA/LI. Specific Security related Product certifications are considered an asset.
- Define and advise on the design, implementation and test processes necessary to protect information system assets.
- Perform risk assessments and translate the security architecture and high-level policies and controls towards security requirements (secure by design) for business and IT projects.
- Contribute to the architectural design and validate it against the security requirements
- Define security testing requirements and penetration test scope, actively support the testing teams to perform these tests and approve the test reports.
- Define, implement and ensure the proper functioning of security services of our department in line with IT security policies.
- Recommend and advise on new or improved security services towards the division management.
- Produce documented security services, technical standards or principles.
- Act as a security subject matter expert within a certain domain (for example Mainframe security, PKI and Cryptography, Network security, platform security, IAM, application security or secure coding), being the point of contact for both business and project teams. Your stakeholders are mainly the business owners/analysts, project leader, risk management, internal/external auditors and off course the engineers, developers and architects.
Please do send across to me the most up to date copy of your CV to (see below)