HAL Allergy Group

Security Engineer – HAL Allergy Group – Leiden

Jobid=7af5e5d1931d (0.0998)

Security Engineer

Location: Leiden (NL) | Hours: 36-40 per week

This role is based in the Netherlands. Applicants must be eligible to work in the Netherlands.

HAL Allergy is modernising its technology landscape with a strong focus on resilience and secure design. This role sits at the centre of that work, shaping a secure hybrid IT and OT environment that supports the development, production, and delivery of allergy treatments for patients.

As Security Engineer, you protect what matters most – critical systems, sensitive patient and user data, and the continuity of manufacturing operations. You close real security gaps, harden platforms, and embed security into new designs as the environment evolves. You operate as the primary security owner, working closely with the Director IT and supported by the IT team and external security partners with a tangible impact on patient health and safety.

Your tasks

  • Design and implement pragmatic security controls across a hybrid IT environment.

  • Secure cloud, on‑premises, and OT environments, including network segmentation and secure connectivity.

  • Secure Microsoft Azure workloads, including Azure Virtual Desktop (AVD), network security, and platform and end-point hardening.

  • Identify security gaps, risks, and misconfigurations, and implement them into concrete technical improvements.

  • Manage IT risks using a risk‑based approach, ensuring identified risks are assessed, prioritised, and mitigated.

  • Lead incident response activities, including technical investigation, coordination, and lessons learned.

  • Deliver security and infrastructure improvement initiatives end‑to‑end, from design through implementation.

  • Work closely with the Director IT, Infrastructure Team, and external cybersecurity partners.

  • Support NIS2 compliance activities, audits, and penetration tests, ensuring follow‑up actions are completed.

  • Act as the go‑to security expert for IT and business stakeholders.

  • Build and promote security awareness across the organisation in a practical and engaging way, working directly with teams to support secure and effective use of IT systems.

  • You have

  • Bachelor's degree in IT, Computer Science, or a related discipline or equivalent experience.
  • At least 6 years of experience in information security, with demonstrated experience delivering security initiatives.
  • Relevant certifications, particularly Azure‑focused security and identity certifications (e.g. AZ‑500, SC‑300, SC‑200). or equivalent; candidates working toward CISSP, CISM, are encouraged to apply.
  • Practical experience with cloud platforms, particularly Microsoft Azure, IAM, endpoint security, and network security.
  • Understanding of IT/OT security boundaries in regulated environments. Exposure to NIS2 is a strong plus.
  • Deep knowledge of Azure security, AVD, endpoint, platform and application hardening.
  • Advanced Identity and Access Management skills, including Entra ID and privileged access management.
  • Excellent command of the English language, both spoken and written; proficiency in Dutch is highly preferred.
  • Lees hier meer

    Deel deze vacature:

    Deel deze vacature: