Function
We are looking for an experienced Security Engineer – SecOps & Application Security to strengthen our Group Engineering team in Brussels. This is a senior security engineering role that merges Security Operations depth, Application Security engineering expertise and Security Architecture and Governance experience. You will be a trusted security partner to our application engineering, platform, and OT/IT operations teams, embedding security throughout the entire Software Development Lifecycle.
As Elia Group embeds AI into engineering products and faces increasingly AI-powered adversaries, you will also help secure both the AI systems we build and detect the AI-accelerated attacks we face.
As Security Engineer, you will:
- Champion a Secure-by-Design culture and run threat modelling for applications, platforms, AI/LLM-infused services, and major changes.
- Integrate security checks such as SAST, DAST, SCA, container scanning and IaC security checks into CI/CD pipelines whenever needed.
- Own the vulnerability management lifecycle for application-layer findings, including severity classification, remediation SLAs and tracking through to closure.
- Triage and contextualise findings from automated tools to eliminate noise and prioritise exploitable risk.
- Provide hands-on secure code review and security validation of AI-generated code where requested.
- Maintain and evolve security guidelines covering OWASP Top 10, OWASP LLM Top 10 and CWE mitigations, tailored to Elia Engineering and IT Security standards.
- Drive risk-based prioritisation for security-related issues picked up during SDLC activities and security monitoring activities.
- Act as an interface/internal consultant between the IT security teams and the Engineering teams.
- Advise on security architecture, including API gateway hardening, secrets management, OAuth 2.0/OIDC implementations and zero-trust network segmentation.
- Be a point of contact for the SOC and IT Security teams, providing application/engineering security support where needed.
- Support security incidents involving application-layer attacks and translate findings into hardening tasks for engineering teams.
- Support security initiatives in the organisation, including input into pentesting scope and validating findings with engineering teams.
Your Profile
- Master’s degree in IT, Business Administration, Engineering, or relevant equivalent experience
- Minimum of 5 years of combined experience in application security and/or security operations roles, preferably with at least 2 years in a KRITIS, financial services, or similarly regulated environment.
- Deep familiarity with OWASP ASVS, WSTG, SAMM and OWASP LLM Top 10 frameworks.
- Proficiency in at least two scripting/programming languages such as Python, Bash, Java, .NET, Go or similar.
- Practical experience integrating security tooling into CI/CD pipelines and working within Agile/SAFe delivery models.
- Knowledge of application security, secure SDLC, SAST/DAST tooling, threat modelling, code review, API security and AI/LLM application security.
- Experience working with both software engineering teams and governance/compliance functions.
- Experience using risk frameworks as a means to drive action.
- Strong communication skills, including executive risk reporting, developer coaching and stakeholder management.
- You are fluent in English. Knowledge of Dutch, French and/or German is a plus.
Nice to have:
- Certifications such as OSEP, GPEN, AWS/Azure Security Specialty, GXPN, CISM or CISSP.
- Experience with SIEM platforms, writing detection logic and familiarity with MITRE ATLAS for AI/ML threat modelling.
- Familiarity with OT/ICS security or energy sector technology stacks.
- Working proficiency in German or French; English is the working language of IT functions.
Offer
- Salary: a competitive salary package, allowance for representation expenses, year-end bonus, double vacation pay, meal vouchers (€10 per working day), eco-vouchers, sport & culture vouchers, bonuses based on individual and group results.
- Insurance: group insurance, hospitalisation insurance, ambulant care insurance for the whole family and also personal accident insurance.
- Vacation: You will be entitled to 20 vacation days and 5 additional vacation days, 6 local days, 4 exempt days (after 1 year of employment) and up to 5 long-service days (1 day for every 3 years in employment).
- Social fund: Year-end vouchers, birth and marriage allowance. We will also cover part of the cost of glasses, a dental prosthesis or similar needs.
- Communication: you will be given an iPhone, a phone subscription (for work and private use) and a laptop with internet reimbursement.
- Discounts: you will enjoy a 30% discount on your gas and electricity bill.
- Mobility: we will offer you a company car and public transport or a mobility budget.
- Elia shares: Elia will give you the opportunity to subscribe to shares with a discount of 16.66% on the average share price.
Location
Main working location will be in Brussels, Empereur. (Close to the central station) + Homeworking