Senior Application Security Consultant
Il y a 18 heures
Brussels, Brussels, Belgique
Orange Cyberdefense
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
As a Senior Application Security Consultant, you help organisations integrate security throughout the Secure Software Development Lifecycle (SSDLC) while ensuring alignment with governance, risk and compliance frameworks such as NIS2, DORA, ISO/IEC 27001 and OWASP ASVS. You combine deep application security expertise with strong advisory capabilities and can translate technical risks into business-oriented recommendations.
Key Responsibilities
Lead Application Security Assessments and Secure Architecture Reviews.
Facilitate Threat Modelling and Architectural Risk Assessments (ARA).
Support the implementation and continuous improvement of SSDLC and DevSecOps practices.
Define and review secure coding standards and security requirements.
Assess applications against OWASP ASVS and other recognised standards.
Advise development teams, architects and business stakeholders on secure design.
Contribute to application security governance, policies and roadmaps.
Required Technical Expertise
OWASP ASVS, OWASP Top 10, OWASP SAMM
Risk Assessments (FAIR or an equivalent industry-recognized risk assessment framework)
Secure Software Development Lifecycle (SSDLC)
Application Security Architecture
API Security
DevSecOps and CI/CD Security
Cloud Security (Azure and/or AWS)
Identity & Access Management.
NIS2
DORA
ISO/IEC 27001
ISO 27005
NIST Cybersecurity Framework
NIST SP 800-218 (SSDF)
FAIR (preferred)
CIS Controls.
Professional Experience
Extensive professional experience in Cyber Security.
Minimum 4 years in Application Security.
Experience leading customer engagements and workshops.
Experience producing executive-level reports and recommendations.
Preferred Certifications
CISSP
CSSLP
CRISC
ISO/IEC 27001 Lead Implementer or Lead Auditor
Cloud security certification (Azure or AWS).
Soft Skills
Strong analytical and strategic thinking.
High learning agility and curiosity.
Quality-oriented and systematic problem solver.
Collaborative, influential and diplomatic.
High integrity and resilience.
Strong planning, organisation and self-management.
Workshop facilitation.
Coaching and mentoring mindset.
Key Motivators
Solving complex security challenges.
Advising customers and influencing strategic decisions.
Working autonomously while collaborating in multidisciplinary teams.
Success Criteria (first 12 months)
Lead multiple Application Security and Architecture Risk Assessments.
Support customers in strengthening their SSDLC and DevSecOps capabilities.
Deliver governance and compliance recommendations aligned with NIS2, DORA and ISO/IEC 27001.
Become a trusted advisor for application security and GRC topics.
What you can expect from us:
Be taken care of - We offer you 32 vacation days (with the option to make it a whopping 37 days with our Benefit Motivation Plan), meal vouchers, eco-cheques, hospitalization and group insurance, company laptop, mobile phone with unlimited use as well as other benefits. So you do not have to worry about a thing
Never stop learning - We want to be the best in what we do and therefore we provide training, certifications and learning opportunities for every employee so you continuously enrich your skills.
Transparency - Communication is key So we organize company and team meetings on a regular base so everyone is informed properly.
Do what you love - Enjoy flexibility with offices in Brussels, Antwerp, Ghent & Rotselaar, a variety of events and lots of activities. We spend more time at work then we do at home, that is why it is important that everyone feels at home. And we make sure you do
Snack to your heart's desire - At Orange Cyberdefense we keep it healthy. So, you can enjoy an assortment of fresh fruit and healthy snacks. For those with an occasionally sugar dip, there are sweet snacks available.
Reputable brand - You will join an internationally, growing company with over 25 years’ experience in the industry. This makes us experts in what we do. We have an international presence and yet local teams to assist our customers.
The good life ...
Orange Cyberdefense are equal opportunities employer, welcoming applications from all people, regardless of their race, sex, disability, age, religion, or sexual orientation.
Key Responsibilities
Lead Application Security Assessments and Secure Architecture Reviews.
Facilitate Threat Modelling and Architectural Risk Assessments (ARA).
Support the implementation and continuous improvement of SSDLC and DevSecOps practices.
Define and review secure coding standards and security requirements.
Assess applications against OWASP ASVS and other recognised standards.
Advise development teams, architects and business stakeholders on secure design.
Contribute to application security governance, policies and roadmaps.
Required Technical Expertise
OWASP ASVS, OWASP Top 10, OWASP SAMM
Risk Assessments (FAIR or an equivalent industry-recognized risk assessment framework)
Secure Software Development Lifecycle (SSDLC)
Application Security Architecture
API Security
DevSecOps and CI/CD Security
Cloud Security (Azure and/or AWS)
Identity & Access Management.
NIS2
DORA
ISO/IEC 27001
ISO 27005
NIST Cybersecurity Framework
NIST SP 800-218 (SSDF)
FAIR (preferred)
CIS Controls.
Professional Experience
Extensive professional experience in Cyber Security.
Minimum 4 years in Application Security.
Experience leading customer engagements and workshops.
Experience producing executive-level reports and recommendations.
Preferred Certifications
CISSP
CSSLP
CRISC
ISO/IEC 27001 Lead Implementer or Lead Auditor
Cloud security certification (Azure or AWS).
Soft Skills
Strong analytical and strategic thinking.
High learning agility and curiosity.
Quality-oriented and systematic problem solver.
Collaborative, influential and diplomatic.
High integrity and resilience.
Strong planning, organisation and self-management.
Workshop facilitation.
Coaching and mentoring mindset.
Key Motivators
Solving complex security challenges.
Advising customers and influencing strategic decisions.
Working autonomously while collaborating in multidisciplinary teams.
Success Criteria (first 12 months)
Lead multiple Application Security and Architecture Risk Assessments.
Support customers in strengthening their SSDLC and DevSecOps capabilities.
Deliver governance and compliance recommendations aligned with NIS2, DORA and ISO/IEC 27001.
Become a trusted advisor for application security and GRC topics.
What you can expect from us:
Be taken care of - We offer you 32 vacation days (with the option to make it a whopping 37 days with our Benefit Motivation Plan), meal vouchers, eco-cheques, hospitalization and group insurance, company laptop, mobile phone with unlimited use as well as other benefits. So you do not have to worry about a thing
Never stop learning - We want to be the best in what we do and therefore we provide training, certifications and learning opportunities for every employee so you continuously enrich your skills.
Transparency - Communication is key So we organize company and team meetings on a regular base so everyone is informed properly.
Do what you love - Enjoy flexibility with offices in Brussels, Antwerp, Ghent & Rotselaar, a variety of events and lots of activities. We spend more time at work then we do at home, that is why it is important that everyone feels at home. And we make sure you do
Snack to your heart's desire - At Orange Cyberdefense we keep it healthy. So, you can enjoy an assortment of fresh fruit and healthy snacks. For those with an occasionally sugar dip, there are sweet snacks available.
Reputable brand - You will join an internationally, growing company with over 25 years’ experience in the industry. This makes us experts in what we do. We have an international presence and yet local teams to assist our customers.
The good life ...
Orange Cyberdefense are equal opportunities employer, welcoming applications from all people, regardless of their race, sex, disability, age, religion, or sexual orientation.