Security Professional - FEC
Bekijk en reageer bij IQ Staffing (externe link)
Security Professional needed for fraud and sanctions detection teams at a financial organisation, hybrid in the Utrecht region (secondment).
- Locatie
- Utrecht
- Werkvorm
- hybride
- Contractvorm
- detachering
- Gepubliceerd
Eisen
- Track record of vulnerability remediation and implementing security controls
- Agile/DevOps environment experience
- 3-5 years experience in cyber security, security engineering, DevOps/platform engineering, IT risk management or software engineering
- Dutch and English communication and presentation skills
- Secure-by-design experience (threat modelling, secure SDLC, OWASP Top 10)
- Secure SDLC, threat modelling, OWASP Top 10, vulnerability management, IAM, DevSecOps, CI/CD security controls
- Bachelor's degree in computer science, cyber security, information security, IT or engineering (or equivalent)
- ISO 27001, NIST Cybersecurity Framework, DORA
- Stakeholder influence without authority
Wensen
- Participation in penetration testing, audits and risk assessments
- Security certifications (Comptia Security+, SC-900, CISSP, CISM, CCSP, GIAC)
- Zero Trust architecture
- Security monitoring
- Python scripting
- KQL scripting
- Encryption and key management
- Background in banking, payments, financial economic crime or regulated environment
- Cloud security controls, particularly Azure
Omschrijving
Security Professional — Fraud & Sanctions Detection. You are the security conscience of a set of engineering teams building fraud and sanctions detection systems, embedding security into design rather than bolting it on. The role involves threat modelling workshops, vulnerability reviews, secure coding, and turning reactive firefighting into secure-by-design. You act as the security point of contact for teams, liaising with security specialists, risk officers and architects. Responsibilities include facilitating threat modelling, reviewing architectures against Zero Trust and defence-in-depth, defining security acceptance criteria, chairing vulnerability reviews, embedding SAST/DAST/SCA into CI/CD, strengthening controls (authentication, least-privilege, secrets management, encryption, logging), supporting incident investigation and reporting on security posture. The client is a financial organisation supporting teams that detect external fraud and screen against sanctions; the work sits at the intersection of engineering and financial crime prevention. You work in agile, DevOps-oriented teams and connect into the wider security and risk community. Core frameworks: Secure SDLC, threat modelling, OWASP Top 10, vulnerability management, IAM, DevSecOps, CI/CD security; standards: ISO 27001, NIST, DORA; also cloud security (Azure), Zero Trust, encryption, security monitoring, Python and KQL scripting. Must-haves: 3-5 years in cyber security/security engineering/DevOps/platform/IT risk/software engineering; practical secure-by-design experience; track record of vulnerability remediation; comfort in agile/DevOps; stakeholder influence without authority; Dutch and English communication. Nice-to-haves: background in banking/payments/financial crime; cloud security (Azure); penetration testing/audits; certifications such as CompTIA Security+, CISSP, CISM, etc. A bachelor's degree or equivalent. The role is hybrid based in the Utrecht region; pre-employment screening is part of the process. This is a secondment position.
Alle opdrachtenBekijk en reageer bij IQ Staffing (externe link)
Gegevens automatisch overgenomen uit de oorspronkelijke publicatie; controleer de details bij de bron. Wij zijn geen partij bij de aanvraag. Hoe wij werken.