About this role
The consultant will be responsible for building, managing, and further professionalising services related to cybersecurity testing and exposure management for Flemish government entities and local authorities. Cybersecurity testing includes penetration testing, vulnerability disclosure programmes, bug bounty programmes, and other offensive security assessments. Exposure management includes vulnerability management, attack surface management, and related processes, methodologies, and tooling used to identify and manage security weaknesses and exposure risks. Required Skills & Expertise: Minimum 5 years of experience as a Product Owner or in a comparable role. Minimum 5 years of experience as a Security Consultant in application, infrastructure, data, cloud, or a related environment. Minimum 5 years of experience with exposure-management solutions, including vulnerability scanners or attack surface management. Minimum 5 years of experience performing or coordinating penetration tests. Demonstrable expertise in a specialised information-security domain. Experience analysing, optimising, and documenting security processes and governance. Knowledge of vulnerability management and remediation processes. Experience reviewing security-testing reports and deliverables. Strong product vision, roadmap, and stakeholder-management capabilities. Should Have Minimum 3 years of experience with RFI and RFP processes, including requirements, evaluation criteria, proposal assessment, and selection advice. Minimum 3 years of experience with at least two recognised penetration-testing standards, such as OWASP, NIST, OSSTMM, or PTES. Minimum 5 years of experience with security-management frameworks. Minimum 3 years of experience with service governance. SLA and KPI definition and monitoring. Service reviews and escalation management. Continuous service improvement. ISO/IEC 27000 series. COBIT for Security. NIST. OWASP. CIS Critical Security Controls. Relevant certifications such as CISM, CISSP, or CEH. Vulnerability disclosure programmes. Bug bounty programmes. Attack Surface Management. Supplier management.