Security Engineer
Elia is the operator of the Belgian high-voltage grid from 380 kV to 30 kV. Elia is responsible for the development and maintenance of this grid, makes it accessible to users, and manages energy flows. The Elia group has a team of 2000 professionals whose mission is to ensure the continuity of the electricity supply in Belgium and part of Germany. As the owner and operator of the transmission grids in Belgium and Germany, Elia plays an important role and has a mission to support and realize European energy and climate policy.
Job Description
We are looking for an experienced Security Engineer - SecOps & Application Security to strengthen our Group Engineering team in Brussels. In this senior role, you will combine expertise in security operations and application security with experience in security architecture and security governance. You will act as a trusted partner for our application engineering, platform engineering, and OT/IT Operations teams, helping them to integrate security into every phase of the software development lifecycle.
AI is playing an increasingly large role in the engineering products of Elia Group. At the same time, cyber threats are increasingly being strengthened or accelerated using AI. You will therefore also contribute to the security of the AI systems we develop and to the detection of AI-assisted attacks.
Your responsibilities as a Security Engineer:
- You promote a Secure-by-Design culture and develop threat models for applications, platforms, and services in which AI or LLMs are integrated, as well as for major changes.
- Where relevant, you integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, container, and IaC scans.
- You manage the full lifecycle for vulnerabilities identified at the application level. This includes classification according to severity, SLAs for remediation, and follow-up until the vulnerabilities are resolved.
- You assess and contextualize the results of automated tools to filter out irrelevant alerts and prioritize vulnerabilities with a real risk of exploitation.
- Where necessary, you perform security-focused code reviews and validate the security of code generated by AI.
- You keep the security guidelines for the OWASP Top 10, the OWASP LLM Top 10, and measures against CWE-related weaknesses up to date and develop them further. In doing so, you align them with the standards of Elia Engineering and IT Security.
- You ensure that security issues identified during software development or through security monitoring are prioritized and addressed based on their risk.
- You act as a point of contact/internal consultant for the IT Security and Engineering teams.
- You advise on security architecture, including the security of API gateways, secrets management, the implementation of OAuth 2.0/OIDC, and network segmentation according to the zero-trust principle.
- You are one of the points of contact for the SOC and IT Security teams and support them where necessary in the field of application security and security engineering.
- You provide support during security incidents where applications are attacked. You translate the insights from these incidents into concrete actions through which the Engineering teams can further improve security.
- You support security initiatives within the organization. For example, you provide input for the scope of penetration tests and validate the results together with the Engineering teams.
Your Profile
- You have a master's degree in IT, management, or engineering, or possess equivalent experience.
- You have at least five years of total experience in application security and/or security operations. Preferably, you have gained at least two of these years in a KRITIS environment, at a financial service provider, or in a similar regulated environment.
- You have thorough knowledge of OWASP ASVS, WSTG, SAMM, and LLM Top 10.
- You master at least two scripting or programming languages, such as Python, Bash, Java, .NET, or Go, or similar languages.
- You have practical experience with integrating security tools into CI/CD pipelines and with Agile and SAFe methodologies.
- You are familiar with application security, the secure software development lifecycle, SAST and DAST tools, threat modeling, code review, API security, and the security of applications in which AI or LLMs are integrated.
- You are used to collaborating with both software engineering teams and teams responsible for governance and compliance.
- You know how to use risk frameworks to translate risks into concrete actions.
- You possess excellent communication skills. You can clearly report risks to management, coach development teams, and effectively manage relationships with stakeholders.
- You speak English fluently. Knowledge of Dutch, French, and/or German is a plus.
Pluses:
- You possess one or more certifications, such as OSEP, GPEN, AWS/Azure Security Specialty, GXPN, CISM, or CISSP.
- You have experience with SIEM platforms and creating detection rules. Additionally, you are familiar with MITRE ATLAS for modeling threats related to AI and machine learning.
- You are familiar with OT/ICS security or with technological environments specific to the energy sector.
- You possess practical knowledge of German or French. English is the working language within the IT functions.
Contact person
Listed by the employer in the job posting — for questions and your application.
- Katleen Houben