IT Cyber Security Specialist
ROLE: IT Cyber Security Specialist
Context
The SPW wishes to strengthen its team in charge of operational security. The main mission of this team is to ensure protection, detection, and response to cybersecurity incidents.
The goal is to integrate a SecOps engineer profile specialized in network and infrastructure security to reinforce security operations.
This person, in addition to their regular activities, will be available in on-call mode 24/7 (rotation among several people).
The SPW is currently working towards compliance with the NIS2 regulation (essential level).
The SPW has a complex environment providing services to Walloon citizens. It is a hybrid infrastructure (multi-site and cloud), an extended network (several dozen locations), numerous applications with a variety of technologies, and a large number of users. The security of its information system is therefore essential.
Objectives
- Ensure the daily management of security tools and security incidents.
- Maintain and optimize security tools (excluding operations).
- Collaborate with the SOC and other SPW teams to strengthen overall security.
- Participate in projects related to operational security.
- Intervene in on-call or duty mode depending on criticality.
Activities
- Management of security incidents (analysis, escalation, resolution) including documentation of incidents
- Coordination of different teams to resolve security incidents or to improve the security level
- Analysis of network flows and correlation with alerts
- Contribution to the securing of network architectures, relevance of configurations, management of exceptions (impact and risk analysis)
- Participate in tuning protection and detection rules, notably on network security tools (WAF, IDS/IPS, NDR, Proxy, etc.)
- Implement exception management (impact and risk analysis)
- Cross-functional support on security tools
- Post-mortem analysis of incidents: technical retrospective, recommendations, and follow-up of action plans with the ITSM team
- Handling of alerts (SIEM, WAF, etc.) coming from the SOC and/or security tools
- Security monitoring and threat intelligence: tracking CVEs, IOCs, MITRE ATT&CK tactics
- Participation in the development or continuous improvement of SecOps processes, procedures, and guides
- Support for IT projects related to operational security: security review, providing technical-functional advice, active participation in the project team
- Use of ITSM tools (Jira Service Management, etc.)
- Any other activity related to operational security depending on the needs and priorities of the service
Terms of Engagement
The mission is carried out within the security division of SPW Digital under the supervision of the Head of Operational Security.
The profile ensures a regular full-time service of 40h/week.
In addition to regular services, they provide a rotation to guarantee availability in on-call mode 24/7 with a commitment to availability. Certain alerts will need to be addressed within a maximum of 30 minutes.
The SOC and SPW may call the on-duty person to take charge of the analysis of a priority 1 or 2 incident, perform response actions, coordinate teams until incident resolution. Integration into existing processes (incident management, change management, SOC, etc.)
Expected Deliverables
- Activity and incident reports, follow-up reports on post-incident recommendations
- NIS2: initial notification, preliminary report, and final report
- Change log for rules (who, what, why)
- Optimized configurations of security tools
- Technical documentation, processes, and procedures
- Opinions and recommendations for improvement
- Cyber dashboard, operational, tactical, and strategic reporting
- Security KPI monitoring
Expected Behavioral Skills
- Clear communication
- Rigor in change management
- Emergency management
- Incident prioritization
- Adaptability and learning ability
- Technical curiosity
- Autonomy
- Team collaboration
- Assertiveness and ability to challenge
Evaluation Method
The evaluation will involve an interview during which questions and/or scenarios related to the mission description will be used.
Duration: MAX 3 years
Note: mission subject to 24/7 on-call duty during certain work weeks
Apply for this Job
This position was originally posted on Pro Unity.
It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.
Search jobs by category
- AI Engineer
- Application Support Analyst
- Business Analyst
- Business Intelligence Analyst
- CRM Developer
- Cybersecurity Analyst
- Data Analyst
- Database Administrator
- Data Engineer
- Data Scientist
- Developer
- DevOps Engineer
- Embedded Systems Engineer
- ERP Consultant
gofreelance
© 2026 gofreelance.be