Expert en cybersécurité/Experte en cybersécurité

Il y a 16 heures

Namur, Wallonia, Belgique ABAKUS IT-SOLUTIONS Temps plein
A technical role at the heart of application security, covering tooling, CI/CD and developer support. Context and project A public administration manages a portfolio of several hundred applications, a large share of them web applications, built on varied technologies and supplied by different vendors. Insufficient control over their lifecycle exposes the organisation to service interruptions, data compromise, technical debt and compliance gaps (NIS2, CyFun). A dedicated Secure Application Lifecycle Management (SALM) team aims to replace one-off manual checks with a shared approach that is risk-proportionate, increasingly automated and covers the full application lifecycle. The team works with project managers, developers, architects, operations, DevSecOps, SecOps, the SOC, business teams and vendors. The role involves taking charge of the technical controls of SALM files and integrating them into development practices. The profile is that of a SALM analyst able to understand the functional context and risk analysis of a file, with a strong emphasis on technical depth, tooling and developer support. Responsibilities Automated controls
• Configure and operate SAST, DAST, SCA, secret detection and scanning tools.
• Ensure the coverage and quality of controls. DevSecOps and CI/CD
• Integrate controls into pipelines together with DevSecOps teams.
• Define thresholds, quality gates and exception rules proportionate to risk. Vulnerability qualification
• Assess exploitability, impact and false positives.
• Prioritise fixes and propose compensating measures. Testing and remediation
• Prepare and follow up scans, code reviews and penetration tests.
• Verify fixes or the formal acceptance of findings. Technical support
• Explain vulnerabilities and advise development teams.
• Produce reusable recommendations and contribute to standards. Expected deliverables
• Technical control plans.
• Configurations and procedures for SAST, DAST, SCA and secret detection integration.
• Qualification and prioritisation reports for application vulnerabilities.
• Penetration test follow-up and remediation plans.
• Quality gate criteria and exception rules.
• Remediation guides and technical recommendations.
• Indicators for coverage, criticality and time to fix. Required profile Role and level
• IT Security Analyst Senior Technical skills (all mandatory)
• Vulnerability analysis and qualification: exploitability, impact, false positives, prioritisation
• CI/CD pipelines and DevSecOps practices: integration, configuration, automation, quality gates
• Application architecture and security: flows, authentication, authorisation, encryption, APIs, dependencies
• Application security tools: SAST, DAST, SCA, secret detection, vulnerability scans
• Technical frameworks: OWASP Top 10, ASVS, SAMM, CWE, CVSS, NIST SSDF
• Technical reporting, documentation and support for development teams
• Secure development, APIs, software dependencies, containers and secrets management Soft skills
• Technical rigour: reproduce, qualify and document findings.
• Pragmatism: prioritise genuinely exploitable vulnerabilities and propose realistic fixes.
• Teaching ability: explain vulnerabilities and remediations to developers.
• Curiosity: keep up to date with attack techniques and tools.
• Autonomy: configure and run controls while escalating complex cases.
• Collaboration: work with projects, developers, DevSecOps, SecOps and vendors. Languages
• French: C2 level (mandatory). Location and conditions
•

Location:
Namur (Belgium).
• Arrangement: hybrid, with on-site presence of 60% of the time or more if needed.