In this role, you will be part of the NPM security team: our mission is to enable the business securely while protecting us, our customers, and its critical services against internal as well as external threats. To reinforce this security team, we are looking for a Cyber Security Risk Assurance Consultant.
In this role, you will be responsible for supporting major transformation programs, strengthening the cyber-resilience of our platforms and contributing to compliance initiatives. You will work in a team of security professionals and collaborate with the engineering and operational teams on a daily basis. You will be fascinated by a highly diverse technical environment, the strong collaboration across the different teams and a remarkable can-do attitude.
· You advise the teams during project design and execution, checking for compliance with security requirements, and proposing adequate (technical) controls, in line with the standards defined for the business unit.
· You maintain the oversight of compliance with established baselines, and flag and document risk resulting from any deviations.
· You analyze vulnerability reports, audit findings, penetration test reports, assess the risk and develop effective remediation plans for identified deficiencies.
· You support the teams to adopt and integrate our service platforms with security tooling and services, including e.g. tools for vulnerability scanning, SIEM, PAM, PKI etc.
· You establish a positive working relationship with technical teams to effectively collaborate on reducing operational and technology risks.
· You contribute to the establishment of relevant security metrics that will help to assess and report on risk in a consistent and objective manner.
· You provide security requirements to be included in RfQs and RfPs, evaluate vendor responses and advise business stakeholders.
· You follow up on the effectiveness of administrative controls, including recurring access reviews/recertifications.
· You review and optimize access rights using our central platforms and tools to restrict access to critical infrastructure and to comply with security policies, Belgian or European laws and regulations that we must comply with.
· You engage in operational processes, review change requests, flag and document any risk incurred by these, and facilitate mitigation of this risk where possible.
· You will report to the divisional security officer.
Your Profile:
· Bachelor or Master degree in IT and/or cyber security or equivalent combination of education and experience.
· Knowledge of information security and risk management.
· Having industry recognized cybersecurity certification(s): CISSP or CISM are highly considered.
· Very good interpersonal skills, mixing collaboration & communication skills, open minded, can-do attitude with constructive assertiveness, while acknowledging the importance of stakeholder management.
· Ability to present complex concepts and issues in a way that is easy to understand for various target audiences: delivery teams, operational teams, management etc.
· Eager to learn. Very curious. Wants to develop himself/herself continuously.
· Able to work in an environment which is continuously changing.
· Background telecom, network engineering, or web engineering is certainly a plus.
· Have some knowledge in telecommunication technologies (5G, IMS, IOT, …).
· Language skills: fluent in English (spoken and written). Knowledge of French and/or Dutch is a plus.
· You have strong analytical skills and are able to keep the helicopter overview.