AISB-1049 Lead Application Security Expert

Il y a 2 heures

Namur, Walloon Region, Belgique Abakus IT-Solutions Temps plein
h3AISB-1049 Lead Application Security Expert /h3pLead and go-to expert in application security, within a dedicated team, with a strong DevSecOps dimension. /ph3Context and Project /h3pAn organisation manages an extensive application estate, including many web applications, built on a wide range of technologies and supplied by various vendors. Poor control of their lifecycle exposes the organisation to service interruptions, data compromise, exploitation of vulnerabilities, growing technical debt and non-compliance with security requirements (NIS2, CyFun). /ppA dedicated application security team sits within the security department. Its goal is to replace one-off, manual controls with a shared approach that is proportionate to risk, more automated and covers the full application lifecycle. /ppThe team works with project managers, developers, architects, operations teams, functional owners, DevSecOps and SecOps teams, the SOC, business units and suppliers. /ph3Role and Responsibilities /h3ulliAllocate cases among team members. /liliTrack progress, deadlines and blockers. /liliReview high-stakes deliverables and align working practices. /liliPrepare decisions for arbitration and produce reporting (tracking dashboards, evolution plans). /li /ulpbOperational Expertise /b /pulliCarry out risk analyses following the established methodology. /liliSupport critical projects, from initial qualification to go-live. /liliTake part in architecture, design and code reviews. /liliAnalyse SAST, DAST, SCA, vulnerability scan and penetration test results. /liliDefine and prioritise recommendations. /li /ulpbMethodological Framework /b /pulliMaintain application security standards and checklists. /liliAdapt controls to application criticality and ensure decisions are traceable. /li /ulpbApplication Vulnerability Management /b /pulliFollow up on recommendations, exemptions and residual risks. /liliMonitor application obsolescence and decommissioning. /li /ulpbProjects and DevSecOps /b /pulliEmbed security controls in projects and CI/CD pipelines. /liliContribute to the automation of controls. /liliAdvise project managers, developers, architects and operations teams. /liliWorkload plan, dashboard and case tracking. /liliRisk analyses and security opinions. /liliRequirements and control plans. /liliSAST, DAST, SCA and penetration test reports. /liliApplication security standards and templates. /li /ulh3Profile /h3pbEducation and Experience /b /pulliSenior experience in IT security, in an expert role (IT Security Expert, senior level). /liliExperience coordinating a team of at least three people. /liliExperience securing critical applications. /liliExperience integrating SAST, DAST or SCA into a CI/CD pipeline. /liliExperience improving an application security approach across the full lifecycle, at the scale of an organisation of more than 1,000 people. /li /ulpbRequired Technical Skills /b /pulliApplication security and SSDLC (risks, requirements, reviews, vulnerabilities): senior level, with recent experience (this year). /liliDevSecOps: SAST, DAST, SCA, CI/CD, secrets management and penetration testing: senior level. /liliBacklog management based on risk and criticality: senior level. /liliProcesses, standards, templates, indicators and knowledge transfer: confirmed level. /li /ulpbSoft Skills /b /pulliLeadership: set direction, support and empower the team (confirmed level). /liliCommunication with projects, IT, business units, suppliers and management: senior level. Messages are tailored to each audience. /liliSense of responsibility: take ownership of assignments and report back. /liliTechnical credibility: handle complex cases and substantiate decisions. /liliPrioritisation: arbitrate based on risk and capacity. /liliHigh standards and supportiveness: ensure quality and help the team grow. /liliPragmatism: propose measures that can be applied in practice. /liliAutonomy and synthesis: follow up on commitments and flag decisions that need arbitration. /li /ulh3Language Requirements /h3h3Location and Conditions /h3ulliWorking model: hybrid, with on-site presence of 60% of the time or more if needed. /li /ul