Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglish
Employee holding a coffee cup at a desk with a screen full of code

Security specialist: from standard to a measure someone actually carries out

The hard part of this craft is not knowing what needs to happen. It is writing it down so an organisation actually does it.

First this

This page describes a role group, not an open position. A role on this site means we speak to people for it continuously and keep our pool up to strength — not that a seat is free today. What is actually open sits on our recruitment portal.

The work

What you do

The work as it looks here, not as it sounds in a job profile.

  • Mapping vulnerabilities, assessing alerts and putting security measures in place across endpoint, identity and network edge.
  • Translating requirements from NIS2, ISO 27001 and client contracts into steps an organisation can take, each with an owner and a date.
  • Working an incident: isolate, establish what was reached, and only reopen once you know why it went wrong.
  • Making sure the evidence falls out of the management work, rather than someone assembling it afterwards.
The profile

What you bring

Not a shopping list. This is what actually counts.

  • Knowledge of endpoint detection, identity management and the usual firewall platforms — the practice, not only the exam.
  • Being able to explain to a director why something matters, in sentences without acronyms.
  • Resistance to the urge to lock everything down. A measure that makes the work impossible gets worked around, and then it is less safe than before.
  • Care in recording. In this craft, what you cannot demonstrate did not happen.
The organisation

Where you land

ITproposal was founded in 2019 and works from Amsterdam, Antwerp and Karaman. Some of our people work in our own teams, others are placed with a client. Either way the same holds: you are reachable, you write down what you did, and you explain in plain language what is going on.

On critical services support runs 24/7, on a rota rather than on a private mobile. Working outside office hours happens according to that rota, not because there is nobody else.

What you can expect from us sits on the vacancies page: four steps, no endless rounds, and an answer even when the answer is no.

The work this role sits on is described under Cybersecurity.

How to introduce yourself

Four steps, no endless rounds

Send your details

Mail your CV and a short note to [email protected]. Name this role group and the region you want to work in.

Introduction

We get in touch for a first conversation, by phone or video. We go through your background, what you are after and the kind of work you are looking for.

Technical conversation

If it matches, you speak to a colleague from the same field. That conversation is about practice: which environments do you know and how do you approach a failure.

Feedback

You hear from us what the next step is. If there is no fitting role right now, we keep your profile and get in touch as soon as that changes.

Frequently asked

Questions we get about this

The ones that come up most often before someone gets in touch.

Is there an open vacancy for this role right now?

There may be, but this page does not say so. What is open at the moment sits on our recruitment portal, because that is where it is kept current. This page describes the role group itself: what the work is and what we look for. If nothing is open and the role does fit you, get in touch anyway — we keep your profile and come back to you as soon as something appears.

Is this a SOC role or an advisory role?

With us usually both, and that is deliberate. Someone who only monitors loses the feel for what a measure costs an organisation; someone who only advises loses the feel for what actually goes wrong. In practice that means: you assess alerts and you are also at the table when something has to be decided. If you want pure research or pure pen-testing, we will say honestly that you will only partly find that here — we run or commission a pen test, but it is not the core of the role.

Will I work at ITproposal or at a client?

Both happen. Some of our people work in our own teams, others are placed with a client, sometimes for a few months and sometimes for years. Which you prefer is something we discuss in the first conversation, because it is a real difference: on placement you see more environments, in an in-house team you build on the same thing for longer.

I cannot do everything listed. Is it worth applying?

Yes. The list above describes the role at its broadest and nobody ticks all of it. What we look at is what you have done, how you approach a problem and whether you can explain what you did. What you do not know yet can be learned; how you deal with people when something is broken is much less so.

Vacancies

The other role groups

If this one does not fit, perhaps one of these does.

Recognise yourself in this?

You do not have to wait for a vacancy to appear. Send your CV and a few lines about what you are looking for.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. Privacy policy.