Cyber Security Analyst

Job Description

Company: Stott and May

Location: Brussels, US

Job Description

Senior Cybersecurity Analyst

Operational and Technical ICT Security – Technical Leadership

Location: Brussels, Belgium – on-site – EU Nationality required

Engagement: Freelance / contract

Start date: ASAP

Duration: Long term engagement

Rate: €550/day gross excluding VAT

Role Overview

A senior technical leadership position within an operational security function. This is a hands-on seat: the successful candidate will lead security investigations and cyber-defence activity while remaining directly involved in the technical work, rather than moving into a purely managerial role.

The role combines the protection of the organisation’s IT infrastructure and applications, day-to-day operation of the security processes and platforms, and leadership of complex incident investigations at short notice.

Key Responsibilities

Protect the IT infrastructure and applications

– Design and implement secured architectures
– Design and implement security settings across a range of IT components
– Develop scripts and programs to improve automation

Run the operational security processes

– Operate the corporate security solutions — endpoint protection, public key infrastructure, encryption

– Operate the security assurance platforms and tooling
– Perform threat hunting activity: build and run regular scripts, analyse the results

– Detect and analyse security events
– Respond to incidents and carry out technical analysis
– Restore normal working conditions as quickly as possible, liaising with internal and external stakeholders

– Build and improve the organisation’s cyber-defence capability

Support wider security activity

– Provide technical support to project owners on security design
– Contribute to policies, standards and baselines
– Run market analysis and set up labs / proofs of concept to assess and select technical solutions

– Contribute technical presentations and demonstrations for user awareness

Essential Requirements

– Master’s degree, or Bachelor’s degree with additional years of relevant experience

– At least one recognised ICT security professional certification
– Minimum six years’ relevant professional experience (eight with a Bachelor’s), including:

– three years’ operational and technical cyber-defence experience — deployment or operation of a SOC, CSIRT, security assessment platform, or technical security infrastructure such as PKI or endpoint

– two years as team leader or technical leader on major security projects

– English to C1/C2 (CEFR) in both written and spoken form — mandatory
– French an asset
– Able to work on-site in Brussels
– Available for unplanned events and occasional work outside normal hours during severe security incidents

Core Technical Skills

The five capabilities that define this role:

– Incident response — handling complex incidents end to end, with detailed tracking of artefacts, actions and reporting

– Digital forensics — memory and file system analysis
– Malware analysis — static and dynamic techniques
– Threat hunting
– SIEM operation and detection engineering — monitoring policy configuration, IDS rules, detection and correlation rules

Wider technical competencies

Depth is expected across a good mix of the following, rather than all of them:

Protection

– Operating systems and secure configuration practice
– Endpoint security — anti-virus, host IDS/IPS, vulnerability assessment, encryption, hardening, data protection

– Network security — internet / intranet / extranet architecture, authentication, firewalls, proxies, network IDS/IPS, PKI, e-mail gateways, IP security, remote access control

– Identity and access management
– Application security — web application firewalls, secure coding practice
– Data protection and integrity — encryption, data loss prevention
– Implementing and managing technical security architectures, systems and software

Security assurance

– Auditing and reviewing the configuration of software, communication and computing systems and their architectures

– Vulnerability scanning tools and techniques
– Penetration testing
– Continuous vulnerability follow-up and remediation, including constructive engagement with asset owners

Security monitoring

– Cyber threat intelligence frameworks and tooling
– Log collection, centralisation and management
– Defining and implementing advanced supervision systems for security elements and infrastructure

Incident response and analysis

– Incident management tooling — ticketing, knowledge base, reporting
– Complex investigation of security events
– Reporting at both technical and management level
– Participation in red / blue team exercises

Personal competencies

– Excellent organisational skills, able to work with minimal supervision, committed to quality of service

– Able to produce reports and written analysis on complex, multi-domain security topics for both technical and senior audiences

– Comfortable managing unplanned events and working under pressure
– Strong communicator — able to lead multi-lingual meetings and present to managers, technical staff and end users

– Leadership, autonomy, and a commitment to increasing maturity
– Strong team player, able to coordinate the work of other experts

Source: LinkedIn