AISB-1050 Senior Application Security Analyst
Il y a 5 heures
Namur, Walloon Region, Belgique
Abakus IT-Solutions
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
h3AISB-1050 Senior Application Security Analyst (Risk-Oriented) /h3pRisk-oriented senior analyst role within a dedicated team, from initial qualification through to go-live. /ph3Context and Project /h3pAn organisation manages an extensive application estate, including many web applications, built on a wide range of technologies and supplied by various vendors. Poor control of their lifecycle exposes the organisation to service interruptions, data compromise, exploitation of vulnerabilities, growing technical debt and non-compliance with security requirements (NIS2, CyFun). /ppA dedicated application security team sits within the security department. Its goal is to replace one-off, manual controls with a shared approach that is proportionate to risk, more automated and covers the full application lifecycle. /ppThe team works with project managers, developers, architects, operations teams, functional owners, service centres, DevSecOps and SecOps teams, the SOC, business units and suppliers. /ph3Role and Responsibilities /h3pThe role involves handling the risk and requirements aspects of application security cases. Projects are supported from initial qualification through to go-live, with a focus on matching controls to application criticality and keeping decisions traceable. /pbQualification and Criticality /bulliCollect relevant information and assess application criticality. /liliDetermine the control pathway and the controls that apply. /li /ulbRisks and Threats /bulliCarry out or support risk analyses and threat modelling following the established methodology. /liliPrioritise scenarios, measures and residual risks. /li /ulbArchitecture and Requirements /bulliTake part in architecture, design and data flow reviews. /liliDefine and verify application security requirements. /li /ulbProject Support /bulliAdvise project managers, architects, developers, business units and suppliers. /liliTrack recommendations, exemptions, evidence and decisions. /li /ulbOpinion and Go-Live /bulliConsolidate the security file and prepare the security opinion before go-live. /liliEscalate significant arbitration items or risks to the team lead. /liliContribute to standards, checklists, templates and lessons learned. /liliQualification and criticality sheet. /liliRisk analysis or threat model. /liliSecurity requirements and control plan. /liliRegister of recommendations, exemptions and residual risks. /liliSecurity opinion before go-live. /li /ulh3Profile /h3pbEducation and Experience /b /pulliSenior experience in IT security, in an analyst role (IT Security Analyst, senior level). /liliExperience performing risk analyses for a critical application. /liliExperience in application threat modelling. /liliExperience defining and verifying security requirements in an application project. /liliExperience following up on exemptions or residual risks through to a formal decision. /li /ulpbRequired Technical Skills /b /pulliProject support: requirements, reviews, exemptions, residual risks and security opinions: senior level. /liliApplication risk analysis, identification of threat scenarios and definition of treatment measures: senior level. /liliThreat modelling methods and frameworks: OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2, CyFun: confirmed level. /liliCommunication and explanation of security topics to project managers, architects, developers, business units and suppliers: confirmed level. /li /ulpbAppreciated Skills /b /pulliDocumentation, decision traceability and use of tracking or GRC tools: junior level. /li /ulpbSoft Skills /b /pulliAnalytical mindset: structure a complex situation and identify priority risks. /liliPragmatism: propose measures that are proportionate, realistic and verifiable. /liliTeaching ability: make security requirements understandable to projects and business units. /liliRigour: document assumptions, decisions, evidence and residual risks. /liliAutonomy: manage several cases in parallel. /liliCollaboration: work with developers, architects, DevSecOps teams, operations and suppliers. /li /ulh3Location and Conditions /h3ulliWorking model: hybrid, with on‑site presence of 60% of the time or more if needed. /li /ul