Senior Cyber Security Risk Assessment Consultant – DAST
Il y a 4 heures
Brussels, Brussels, Belgique
Salt
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP
Location:
Brussels , Paris, London or Amsterdam Contract:
Long-term contract Working Model:
Hybrid Hiring:
Multiple positions available
The Opportunity We are looking for experienced
Senior Cyber Security Risk Assessment Consultants
to join a major Cyber & Information Security function within a global financial services environment. You will provide security expertise across a broad portfolio of business and technology projects, working closely with architects, engineers, developers, project teams, risk management and business stakeholders.
A key part of the position is performing
technical security risk assessments , translating identified risks into security requirements, reviewing and validating solution designs, and defining appropriate security testing requirements. This is not a SOC or purely operational security role. We are looking for experienced security professionals who can understand complex technical solutions, identify security risks and vulnerabilities, and advise projects on the controls required to achieve
Secure by Design .
Key Responsibilities Perform
security risk assessments
across business and IT projects. Identify threats, vulnerabilities, security weaknesses and potential impacts within proposed solutions. Translate security architecture, policies, risks and controls into clear
functional and technical security requirements . Define and advise on the design, implementation and testing processes required to protect information systems and assets. Embed
Secure by Design
principles throughout the technology delivery lifecycle. Contribute to architectural and solution design discussions and validate designs against security requirements. Review applications, platforms and infrastructure from a security perspective. Define
application security testing requirements , including appropriate use of DAST, SAST, code scanning and penetration testing. Define penetration-testing scope and work closely with security-testing teams throughout execution. Review security-testing and penetration-testing reports and assess whether identified risks have been appropriately addressed. Apply
OWASP principles and guidelines
when assessing application security. Identify security gaps and recommend appropriate remediation and compensating controls. Produce and maintain security standards, principles, baselines and documented security requirements. Recommend new or improved security services and controls. Act as a
Security Subject Matter Expert
for project and business teams. Present security risks, findings and recommendations clearly to both senior stakeholders and deep technical specialists. Work closely with Business Owners, Business Analysts, Project Managers, Risk Management, Architects, Developers, Engineers and internal/external auditors.
Application Security / DAST / OWASP We are particularly interested in candidates with strong knowledge of
Application Security
and experience across areas such as: OWASP Top 10 and wider OWASP security principles DAST / Dynamic Application Security Testing SAST / Static Application Security Testing Secure SDLC / Secure by Design Application vulnerability assessment Web application security API security Code scanning and security-analysis tooling Penetration-testing methodology and scoping Security testing and test-result validation CI/CD security controls DevSecOps Security and compliance automation
You do
not
need to be a hands-on penetration tester, but you should have sufficient technical knowledge to
define security-testing requirements, scope appropriate testing, challenge findings and determine whether security risks have been adequately addressed . Broader Security Knowledge
Alongside application security, candidates should bring knowledge across one or more additional Cyber & Information Security domains, which could include: Identity & Access Management / IAM / IDaaS PAM, authentication, authorisation and federation PKI, cryptography, encryption and key management Network and DMZ security WAFs and network segmentation Endpoint and platform security Data protection and DLP Azure / AWS / Cloud Security IaaS / PaaS / SaaS Virtualisation Windows / Linux security Database and storage security Infrastructure as Code Infrastructure and security automation We are
not expecting candidates to be specialists across every security domain .
Your Experience For the senior positions, we are looking for candidates with: 10+ years' experience within Cyber / Information Security . Proven experience performing
technical security risk assessments . Strong understanding of application and/or infrastructure security. Experience i
Brussels , Paris, London or Amsterdam Contract:
Long-term contract Working Model:
Hybrid Hiring:
Multiple positions available
The Opportunity We are looking for experienced
Senior Cyber Security Risk Assessment Consultants
to join a major Cyber & Information Security function within a global financial services environment. You will provide security expertise across a broad portfolio of business and technology projects, working closely with architects, engineers, developers, project teams, risk management and business stakeholders.
A key part of the position is performing
technical security risk assessments , translating identified risks into security requirements, reviewing and validating solution designs, and defining appropriate security testing requirements. This is not a SOC or purely operational security role. We are looking for experienced security professionals who can understand complex technical solutions, identify security risks and vulnerabilities, and advise projects on the controls required to achieve
Secure by Design .
Key Responsibilities Perform
security risk assessments
across business and IT projects. Identify threats, vulnerabilities, security weaknesses and potential impacts within proposed solutions. Translate security architecture, policies, risks and controls into clear
functional and technical security requirements . Define and advise on the design, implementation and testing processes required to protect information systems and assets. Embed
Secure by Design
principles throughout the technology delivery lifecycle. Contribute to architectural and solution design discussions and validate designs against security requirements. Review applications, platforms and infrastructure from a security perspective. Define
application security testing requirements , including appropriate use of DAST, SAST, code scanning and penetration testing. Define penetration-testing scope and work closely with security-testing teams throughout execution. Review security-testing and penetration-testing reports and assess whether identified risks have been appropriately addressed. Apply
OWASP principles and guidelines
when assessing application security. Identify security gaps and recommend appropriate remediation and compensating controls. Produce and maintain security standards, principles, baselines and documented security requirements. Recommend new or improved security services and controls. Act as a
Security Subject Matter Expert
for project and business teams. Present security risks, findings and recommendations clearly to both senior stakeholders and deep technical specialists. Work closely with Business Owners, Business Analysts, Project Managers, Risk Management, Architects, Developers, Engineers and internal/external auditors.
Application Security / DAST / OWASP We are particularly interested in candidates with strong knowledge of
Application Security
and experience across areas such as: OWASP Top 10 and wider OWASP security principles DAST / Dynamic Application Security Testing SAST / Static Application Security Testing Secure SDLC / Secure by Design Application vulnerability assessment Web application security API security Code scanning and security-analysis tooling Penetration-testing methodology and scoping Security testing and test-result validation CI/CD security controls DevSecOps Security and compliance automation
You do
not
need to be a hands-on penetration tester, but you should have sufficient technical knowledge to
define security-testing requirements, scope appropriate testing, challenge findings and determine whether security risks have been adequately addressed . Broader Security Knowledge
Alongside application security, candidates should bring knowledge across one or more additional Cyber & Information Security domains, which could include: Identity & Access Management / IAM / IDaaS PAM, authentication, authorisation and federation PKI, cryptography, encryption and key management Network and DMZ security WAFs and network segmentation Endpoint and platform security Data protection and DLP Azure / AWS / Cloud Security IaaS / PaaS / SaaS Virtualisation Windows / Linux security Database and storage security Infrastructure as Code Infrastructure and security automation We are
not expecting candidates to be specialists across every security domain .
Your Experience For the senior positions, we are looking for candidates with: 10+ years' experience within Cyber / Information Security . Proven experience performing
technical security risk assessments . Strong understanding of application and/or infrastructure security. Experience i