Senior Application Security Consultant

Il y a 1 jour

Evere, Brussels, Belgique Orange Cyberdefense Temps plein

Position summary

As a Senior Application Security Consultant, you help organisations integrate security throughout the Secure Software Development Lifecycle (SSDLC) while ensuring alignment with governance, risk and compliance frameworks such as NIS2, DORA, ISO/IEC 27001 and OWASP ASVS. You combine deep application security expertise with strong advisory capabilities and can translate technical risks into business-oriented recommendations.

Key Responsibilities

- Lead Application Security Assessments and Secure Architecture Reviews.

- Facilitate Threat Modelling and Architectural Risk Assessments (ARA).

- Support the implementation and continuous improvement of SSDLC and DevSecOps practices.

- Define and review secure coding standards and security requirements.

- Assess applications against OWASP ASVS and other recognised standards.

- Advise development teams, architects and business stakeholders on secure design.

- Contribute to application security governance, policies and roadmaps.

Required Technical Expertise

- OWASP ASVS, OWASP Top 10, OWASP SAMM

- Threat Modelling (STRIDE)

- Risk Assessments (FAIR or an equivalent industry-recognized risk assessment framework)

- Secure Software Development Lifecycle (SSDLC)

- Application Security Architecture

- API Security

- DevSecOps and CI/CD Security

- Cloud Security (Azure and/or AWS)

- Identity & Access Management.

Governance, Risk & Compliance

- NIS2

- DORA

- ISO/IEC 27001

- ISO 27005

- NIST Cybersecurity Framework

- NIST SP 800-218 (SSDF)

- FAIR (preferred)

- CIS Controls.

Professional Experience

- Extensive professional experience in Cyber Security.

- Minimum 4 years in Application Security.

- Experience leading customer engagements and workshops.

- Experience producing executive-level reports and recommendations.

Preferred Certifications

- CISSP

- CSSLP

- CRISC

- ISO/IEC 27001 Lead Implementer or Lead Auditor

- Cloud security certification (Azure or AWS).

Soft Skills

- Strong analytical and strategic thinking.

- High learning agility and curiosity.

- Quality-oriented and systematic problem solver.

- Collaborative, influential and diplomatic.

- High integrity and resilience.

- Strong planning, organisation and self-management.

- Excellent written and verbal communication.

- Executive presentation skills.

- Workshop facilitation.

- Stakeholder management.

- Coaching and mentoring mindset.

- Commercial awareness.

Key Motivators

- Solving complex security challenges.

- Continuous professional development.

- Advising customers and influencing strategic decisions.

- Working autonomously while collaborating in multidisciplinary teams.