19 sep
|
Distinctive Advisory
|
España
19 sep
Distinctive Advisory
España
We are currently looking for an experienced Vulnerability Lead for a consulting assignment within the CISO Office of a large Belgian organization.
? Brussels / Hybrid way of working (homeworking + onsite presence)
? Full-time
? Initial duration: 3 months, renewable
This is a senior role with real ownership of the organisation’s enterprise Vulnerability Management programme, covering on-premise infrastructure, cloud, workplace, applications and container environments.
Your role
You will act as the central Vulnerability Lead and drive the full vulnerability lifecycle: from identification and prioritisation through remediation, verification, reporting and exception management.
Key responsibilities include:
Governance & Reporting
- Act as the Vulnerability Management SPOC towards the CISO Office
- Prepare and maintain audit-ready evidence, including NIS2-related compliance
- Produce and present monthly Vulnerability Management reporting to senior security governance
- Define and continuously evolve the scope of the VM programme
Process & SLA Ownership
- Own and continuously improve the end-to-end Vulnerability Management process
- Define and maintain the VM RACI across internal teams and external partners
- Establish risk-based prioritisation based on:
- CVSS
- Exploitability
- Threat intelligence
- Business criticality
- Define and monitor remediation SLAs for Critical, High, Medium and Low vulnerabilities
- Define and track Vulnerability Management KPIs and KRIs
Remediation & Patching Coordination
- Work closely with Infrastructure, Cloud, Workplace, Application, SOC, Incident Response and business teams
- Drive remediation commitments and SLA compliance
- Monitor remediation performance across teams and environments
- Coordinate vulnerability detection and remediation across:
- Servers
- End-user devices
- Cloud environments
- Applications
- Containers
- Manage prioritisation conflicts between vulnerability risk and delivery capacity
Verification & Exception Management
- Track vulnerabilities through verified closure and remediation scanning
- Maintain a consolidated view of coverage, SLA attainment, ageing and end-of-life risks
- Own the vulnerability exception register
- Ensure every exception has:
- Appropriate compensating controls
- A clear accountable owner
- A defined expiry date
- Prepare exception cases for Risk Management governance
Awareness & Continuous Improvement
- Promote vulnerability management best practices across the organisation
- Help mature the overall vulnerability management capability and operating model
Your profile
✅ 5+ years of experience in Vulnerability Management and/or Patch Management with direct programme ownership
✅ Strong knowledge of the Vulnerability Management Lifecycle
✅ Strong understanding of CVSS, exploitability analysis and threat intelligence
✅ Good understanding of enterprise infrastructure, networking, cloud and remediation processes
✅ Hands-on experience with Qualys, AWS Inspector and Microsoft Defender Vulnerability Management
✅ Experience in a large enterprise or public-sector environment, ideally with significant legacy systems and technical debt
✅ Experience with AWS and Azure
✅ Knowledge of container security
✅ Familiarity with NIS2
✅ Experience integrating Vulnerability Management with ITSM tools such as Jira and ServiceNow
✅ Strong analytical, governance and reporting skills
✅ Strong stakeholder management skills and ability to challenge remediation teams where needed
Languages
?? Fluent English required
?? Dutch and/or French is a strong plus
We are looking for someone who can combine security expertise, governance and hands-on programme ownership - someone capable of driving remediation across multiple technical teams rather than simply producing vulnerability reports.
Interested, or know someone who could be a good fit?
? Send your CV, availability and expected daily rate.
📌 Freelance / consultant opportunity – vulnerability lead (España)
🏢 Distinctive Advisory
📍 España