
Security Engineer
Elia Group4 hours ago
Brussels, BelgiumSenior
Responsibilities
- Promote secure-by-design practices and create threat models for applications, platforms, services, AI/LLM integrations, and major changes.
- Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, container, and infrastructure-as-code scans.
- Manage the full application vulnerability lifecycle, including severity classification, remediation SLAs, prioritization, and follow-up through resolution.
- Assess automated security-tool results, filter irrelevant findings, and prioritize vulnerabilities with a realistic risk of exploitation.
- Conduct security-focused code reviews and validate the security of AI-generated code where needed.
- Maintain and develop guidance for the OWASP Top 10, OWASP LLM Top 10, and CWE-related weaknesses.
- Advise on security architecture, API gateways, secrets management, OAuth 2.0/OIDC, and zero-trust network segmentation.
- Serve as an internal consultant and point of contact for Engineering, IT Security, and SOC teams on application security and security engineering.
- Support application-related security incidents and convert incident insights into concrete improvements for Engineering teams.
- Contribute to security initiatives, including penetration-test scoping and validation of results with Engineering teams.
Requirements
- Master’s degree in IT, management, or engineering, or equivalent experience.
- At least five years of experience in application security and/or security operations.
- Preferably at least two years of experience in a critical-infrastructure, financial-services, or comparable regulated environment.
- Strong knowledge of OWASP ASVS, WSTG, SAMM, and the OWASP LLM Top 10.
- Proficiency in at least two scripting or programming languages, such as Python, Bash, Java, .NET, or Go, or comparable languages.
- Practical experience integrating security tools into CI/CD pipelines and familiarity with Agile and SAFe ways of working.
- Experience with application security, secure software development, SAST and DAST tools, threat modeling, code review, API security, and AI/LLM-integrated application security.
- Ability to collaborate with software engineering, governance, and compliance teams and translate risk frameworks into concrete actions.
- Excellent communication skills, including reporting risks to management, coaching development teams, and managing stakeholder relationships.
- Fluent English is required; Dutch, French, and/or German are advantageous.
- Relevant certifications such as OSEP, GPEN, AWS Security Specialty, Azure Security Specialty, GXPN, CISM, or CISSP are advantageous.
- Experience with SIEM platforms, detection-rule development, MITRE ATLAS, OT/ICS security, or energy-sector technology environments is advantageous.
Benefits
- Competitive compensation package with representation allowance, year-end bonus, double holiday pay, meal vouchers of €10 per working day, eco vouchers, sport and culture vouchers, and individual and collective performance bonuses.
- Group insurance, hospitalization insurance, family ambulatory-care insurance, and private-life accident insurance.
- Paid leave includes 20 vacation days, 5 compensatory vacation days, 6 local days, 4 seniority-related days after one year, and up to 5 additional seniority days.
- Social fund benefits include year-end vouchers and contributions for events or needs such as birth, marriage, glasses, or dentures.
- iPhone with subscription for private use, internet reimbursement, and laptop.
- 30% discount on gas and electricity bills.
- Company car plus public transportation or a mobility budget.
- Option to subscribe to Elia shares at a 16.66% discount on the average share price.
- Primary workplace is in Brussels near Brussels-Central Station, with working from home available.