Sivel Labs Talents

Cybersecurity Analyst | Vulnerability & Attack Surface Management | Freelance | Flanders

Organization
Sivel Labs Talents
Location
Flanders, Belgium
Contract type
freelance

We are looking for a Cybersecurity Analyst specialised in Vulnerability Management and Attack Surface Management to support a large public-sector environment in Flanders. The consultant will contribute to the further development, execution and optimisation of services related to vulnerability management, exposure management and cyber awareness. This is a hands-on operational role combining cybersecurity analysis, vulnerability prioritisation, automation and stakeholder support. You will analyse and follow up information related to vulnerabilities, exposed systems and security risks, validate findings, eliminate false positives, put vulnerabilities into the appropriate risk context, develop and maintain Python scripts and API integrations for vulnerability data collection, enrichment, correlation, monitoring and reporting, and work closely with internal security teams, external service providers and different public-sector organisations. You will also support cyber-awareness initiatives and phishing simulations, and contribute to the documentation, standardisation and continuous improvement of security processes and operational procedures. What we're looking for Must-Have Requirements: Minimum 3 years of experience as a Cybersecurity Analyst focused on Vulnerability Management. Proven experience with vulnerability identification, validation, risk-based prioritisation and remediation follow-up. Minimum 3 years of experience as a Security Consultant within infrastructure, applications, data or another relevant security environment. Minimum 3 years of experience with vulnerability scanning and/or exposure-management solutions, including configuration, scan execution and interpretation of results. Strong Python scripting and automation experience. Experience developing API integrations. Experience processing and correlating security data. Experience creating automated reporting. Experience analysing, optimising and documenting security processes and governance. Strong expertise in at least one Information Security domain. Dutch at CEFR C2 level. Willingness to sign the required NDA. Should-Have Requirements: Minimum 3 years of experience translating technical security findings into recommendations for technical and non-technical stakeholders. Minimum 3 years of experience with ticketing and workflow systems such as Jira and ServiceNow. Knowledge of recognised security frameworks and standards such as ISO 27000 series, NIST, OWASP, CIS Critical Security Controls, COBIT for Security. Relevant cybersecurity certification such as CISSP, CISM, CEH or equivalent. Nice to Have: Minimum 3 years of experience supporting cyber-awareness programmes. Experience designing or coordinating phishing simulations. Experience working in complex public-sector or highly regulated environments. Vulnerability Management, Attack Surface Management, Cybersecurity analysis, Vulnerability identification, Validation, Risk-based prioritisation, Remediation follow-up, Vulnerability scanning, Exposure-management solutions, Configuration, Scan execution, Interpretation of results, Python scripting, Automation, API integrations, Processing security data, Correlating security data, Automated reporting, Security processes and governance, Information Security, Jira, ServiceNow, ISO 27000 series, NIST, OWASP, CIS Critical Security Controls, COBIT for Security, Cyber-awareness programmes, Phishing simulations, Dutch C2 What we offer Information not provided in the source posting. Nice-to-have Information not provided in the source posting. Additional details Cybersecurity Analyst | Vulnerability & Attack Surface Management | Freelance | Flanders Your Role You will analyse and follow up information related to vulnerabilities, exposed systems and security risks. You will validate findings, eliminate false positives and put vulnerabilities into the appropriate risk context in order to provide clear and actionable recommendations. A strong focus will also be placed on automation. Due to the volume of security data and information sources, you will develop and maintain Python scripts and API integrations supporting vulnerability data collection, enrichment, correlation, monitoring and reporting. You will work closely with internal security teams, external service providers and different public-sector organisations. Key Responsibilities Analyse vulnerabilities and exposed assets based on multiple security data sources*Validate findings and filter noise and false positives Assess the real security impact for the affected organisation Prioritise vulnerabilities based on: CVSS EPSS Exploit availability/status Organisational context Identify broader vulnerability trends and organisation-specific risks Translate technical findings into clear remediation recommendations Support organisations in prioritising and following up remediation actions Develop and maintain Python scripts for security automation Build and maintain API

View the vacancy and apply

Back to vacancies