Euroclear is a global critical financial infrastructure company. Security is at the core of the company’s services, firmly embedded in their management systems and processes. Our Tribe provides impact analysis, security risk assessment, security requirements, design validation for all IT projects in Euroclear, regular security assessments of Euroclear applications and the underlying infrastructure. We also support Euroclear’s compliance activities by reviewing and publishing secure configuration baselines and by organising the Security Exception Review Board. Finally, we provide consultancy for anyone in Euroclear for any IT security related question.
Required Technical and Professional Expertise
We are looking for Cyber & Information Security experts to strengthen our squad in our Brussels office with experience in one or more of the following areas:
1. Proven experience in security risk assessments, development of functional security requirements, process design and management reporting.
2. Familiarity with industry best practices in key security domains such as identity and access management, PKI, network security, data protection.
3. Application security knowledge with a good understanding of software development and testing, OWASP (Open Web Application Security Project) guidelines, code scanning tools, security and compliance automation using a CI/CD pipeline.
4. Knowledge of and experience with security technologies including IDAAS (Identity as a service) and identity management platforms, Secure access management and federation services, PKI and cryptographic solutions, web application firewalls, endpoint security
5. Knowledge of and experience with security technologies covering domains Virtualisation, Software Defined Networks, Cloud IAAS/PAAS/SAAS, Network and DMZ infrastructure, VOIP, Wi-Fi, 802.1x, Anti-malware, System protection, Middleware, Collaboration and end-user workspace solutions, Storage (SAN, NAS), Databases, infrastructure automation services (Infrastructure as a code)
6. Preferred professional certifications are CISSP, GIAC, SABSA, ISO 27001 LA/LI. Specific Security related Product certifications are considered an asset.
Your Responsibilities
7. Define and advise on the design, implementation, and test processes necessary to protect information system assets.
8. Perform risk assessments and translate the security architecture and high-level policies and controls towards security requirements (secure by design) for business and IT projects.
9. Contribute to the architectural design and validate it against the security requirements
10. Define security testing requirements and penetration test scope, actively support the testing squads to perform these tests and approve the test reports.
11. Define, implement, and ensure the proper functioning of security services of our tribe in line with IT security policies.
12. Recommend and advise on new or improved security services towards the division management.
13. Produce documented security services, technical standards, or principles.
14. Act as a security subject matter expert within a certain domain (for example Mainframe security, PKI and Cryptography, Network security, platform security, IAM, application security or secure coding), being the point of contact for both business and project squads. Your stakeholders are the business owners/analysts, project leader, risk management, internal/external auditors and off course the engineers, developers, and architects.
Your Profile
15. University degree in Computer Science, Engineering, or similar degree.
16. IT-security professional with solid experience in the infrastructure security domain or in the IT application security domain.
17. Good working knowledge of documentation and presentation applications including PowerPoint, Visio, Excel, and Word
18. Experience translating business requirements into technical solutions
19. Effective organizational, planning and time management skills
20. Effective research, analytical, and critical thinking skills
21. Effective skill exercising initiative and using good judgment to make sound decisions
22. Effective skill maintaining accuracy with diligence and meeting deadlines
23. Effective skill presenting findings, conclusions, alternatives, and information clearly and concisely
24. Able to operate within an international/multi-cultural, networked environment.
25. Fluent in English
26. Squad player who communicates in an open, respectful, and constructive way with customers and peers, both verbally and in writing.
27. Strong communication skills, being able to discuss, defend and translate security topics with both senior business people as with deep technical IT experts.
28. Ability to handle different projects and cope with pressure and stressful situations.
29. Take ownership and ensure that organizational quality standards are met.
30. Independent, service-oriented and organized.
#LI-AK1