
Security Engineer
Elia Group2 hours ago
Brussels, BelgiumSenior
Responsibilities
- Champion secure-by-design practices and conduct threat modeling for applications, platforms, AI/LLM services, and major changes.
- Integrate SAST, DAST, SCA, container scanning, and infrastructure-as-code security checks into CI/CD pipelines.
- Own the application-layer vulnerability management lifecycle, including severity classification, remediation SLAs, tracking, triage, and risk prioritization.
- Perform secure code reviews and validate AI-generated code when requested.
- Maintain security guidelines covering OWASP Top 10, OWASP LLM Top 10, and CWE mitigations.
- Advise on API gateway hardening, secrets management, OAuth 2.0/OIDC, security architecture, and zero-trust network segmentation.
- Support SOC and IT Security teams with application and engineering security expertise and assist with application-layer security incidents.
- Support security initiatives, penetration-testing scope, engineering validation of findings, and hardening activities.
- Act as an internal consultant and interface between IT security, engineering, governance, and compliance teams.
Requirements
- Master’s degree in Computer Science, Computer Engineering, Cybersecurity, or relevant equivalent experience.
- At least 5 years of combined experience in application security and/or security operations, preferably including 2 years in a KRITIS, financial services, or similarly regulated environment.
- Deep familiarity with OWASP ASVS, WSTG, SAMM, and OWASP LLM Top 10.
- Proficiency in at least two scripting or programming languages such as Python, Bash, Java, .NET, or Go.
- Practical experience integrating security tooling into CI/CD pipelines and working with Agile/SAFe delivery models.
- Knowledge of application security, secure SDLC, SAST/DAST tooling, threat modeling, code review, API security, and AI/LLM application security.
- Experience collaborating with software engineering teams and governance/compliance functions and using risk frameworks to drive action.
- Strong communication skills, including executive risk reporting, developer coaching, and stakeholder management.
- Fluent English; Dutch, French, and/or German is a plus, with working proficiency in German or French desirable.
- Preferred certifications include OSEP, GPEN, AWS Security Specialty, Azure Security Specialty, GXPN, CISM, or CISSP.
- Experience with SIEM platforms, detection logic, MITRE ATLAS, OT/ICS security, or energy-sector technology stacks is desirable.
Benefits
- Competitive salary package with representation-expense allowance, year-end bonus, double vacation pay, meal vouchers, eco-vouchers, sport and culture vouchers, and individual and group performance bonuses.
- Group, hospitalisation, ambulant-care, and personal-accident insurance for the employee and family.
- 20 vacation days, 5 additional vacation days, 6 local days, 4 exempt days after one year, and up to 5 long-service days.
- Year-end vouchers, birth and marriage allowances, and partial reimbursement for glasses, dental prostheses, or similar needs.
- Company iPhone with subscription, laptop, and internet reimbursement.
- 30% discount on gas and electricity bills.
- Company car and public transport or mobility budget.
- Opportunity to subscribe to Elia shares at a 16.66% discount on the average share price.
- Main working location in Brussels near Central Station, with homeworking available.