AISB-1047 Senior IT Security Analyst

Abakus IT-Solutions

Namen

Hybride

EUR 60 000 - 90 000

Plein temps

Il y a 9 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature complète en une minute — CV personnalisé et lettre de motivation, prêts à envoyer.

Passez les filtres ATS

Résumé du poste

Abakus IT-Solutions seeks a Senior IT Security Analyst to own technical SALM controls within development lifecycles. You will work with DevSecOps and project teams to embed automated security checks across pipelines, assess risks, and guide remediation.

You will communicate findings clearly, produce reusable recommendations, and help build standards for vulnerability management and secure development practices.

Qualifications

  • Vulnerability analysis including exploitability, impact and false positives.
  • CI/CD pipelines and DevSecOps integration with automation and quality gates.
  • Application security knowledge across architectures, authentication and APIs.
  • Familiarity with SAST, DAST, SCA and secret-detection tools.
  • Ability to report findings clearly and support development teams.

Responsabilités

  • Configure and operate SAST, DAST, SCA and secret-detection tooling.
  • Integrate security controls into CI/CD pipelines with DevSecOps teams.
  • Assess exploitability, impact and false positives; prioritise fixes.
  • Prepare and follow up scans, code reviews and penetration tests; verify fixes.
  • Explain vulnerabilities to developers; provide actionable remediation guidance.

Connaissances

Vulnerability analysis
CI/CD & DevSecOps
Application security
Security tooling
Technical reporting
Collaboration
Teaching ability
Curiosity
Autonomy
Prioritisation

Outils

SAST
DAST
SCA
Secret detection
Vulnerability scans

Description du poste

A technical role at the heart of application security, covering tooling, CI/CD and developer support.

Context and project

A public administration manages a portfolio of several hundred applications, a large share of them web applications, built on varied technologies and supplied by different vendors. Insufficient control over their lifecycle exposes the organisation to service interruptions, data compromise, technical debt and compliance gaps (NIS2, CyFun).

A dedicated Secure Application Lifecycle Management (SALM) team aims to replace one-off manual checks with a shared approach that is risk-proportionate, increasingly automated and covers the full application lifecycle. The team works with project managers, developers, architects, operations, DevSecOps, SecOps, the SOC, business teams and vendors.

The role involves taking charge of the technical controls of SALM files and integrating them into development practices. The profile is that of a SALM analyst able to understand the functional context and risk analysis of a file, with a strong emphasis on technical depth, tooling and developer support.

Responsibilities

Automated controls

  • Configure and operate SAST, DAST, SCA, secret detection and scanning tools.
  • Ensure the coverage and quality of controls.

DevSecOps and CI/CD

  • Integrate controls into pipelines together with DevSecOps teams.
  • Define thresholds, quality gates and exception rules proportionate to risk.

Vulnerability qualification

  • Assess exploitability, impact and false positives.
  • Prioritise fixes and propose compensating measures.

Testing and remediation

  • Prepare and follow up scans, code reviews and penetration tests.
  • Verify fixes or the formal acceptance of findings.

Technical support

  • Explain vulnerabilities and advise development teams.
  • Produce reusable recommendations and contribute to standards.
  • Technical control plans.
  • Configurations and procedures for SAST, DAST, SCA and secret detection integration.
  • Qualification and prioritisation reports for application vulnerabilities.
  • Penetration test follow-up and remediation plans.
  • Quality gate criteria and exception rules.
  • Remediation guides and technical recommendations.
  • Indicators for coverage, criticality and time to fix.
Required profile

Role and level

  • IT Security Analyst Senior

Technical skills (all mandatory)

  • Vulnerability analysis and qualification: exploitability, impact, false positives, prioritisation
  • CI/CD pipelines and DevSecOps practices: integration, configuration, automation, quality gates
  • Application architecture and security: flows, authentication, authorisation, encryption, APIs, dependencies
  • Application security tools: SAST, DAST, SCA, secret detection, vulnerability scans
  • Technical frameworks: OWASP Top 10, ASVS, SAMM, CWE, CVSS, NIST SSDF
  • Technical reporting, documentation and support for development teams
  • Secure development, APIs, software dependencies, containers and secrets management
  • Technical rigour: reproduce, qualify and document findings.
  • Pragmatism: prioritise genuinely exploitable vulnerabilities and propose realistic fixes.
  • Teaching ability: explain vulnerabilities and remediations to developers.
  • Curiosity: keep up to date with attack techniques and tools.
  • Autonomy: configure and run controls while escalating complex cases.
  • Collaboration: work with projects, developers, DevSecOps, SecOps and vendors.
Languages
  • French: C2 level (mandatory).
Location and conditions
  • Arrangement: hybrid, with on-site presence of 60% of the time or more if needed.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

AISB-1048 Medior IT Security Analyst
AISB-1048 Medior IT Security Analyst

Abakus IT-Solutions • Namen

Hybride
EUR 60 000 - 85 000
AISB-1052 Application Security Analyst (Technical Controls and DevSecOps)
AISB-1052 Application Security Analyst (Technical Controls and DevSecOps)

Abakus IT-Solutions • Namen

Hybride
EUR 60 000 - 90 000
AISB-1050 Senior Application Security Analyst (Risk-Oriented)
AISB-1050 Senior Application Security Analyst (Risk-Oriented)

Abakus IT-Solutions • Namen

Hybride
EUR 70 000 - 110 000
AISB-1049 Lead Application Security Expert
AISB-1049 Lead Application Security Expert

Abakus IT-Solutions • Namen

Hybride
EUR 85 000 - 120 000
Senior Application Security Analyst
Senior Application Security Analyst

Keystone Solutions • Namen

Sur place
EUR 70 000 - 110 000
Analyste en sécurité applicative et DevSecOps (Employed or freelance)
Analyste en sécurité applicative et DevSecOps (Employed or freelance)

EngiFlex BV • Namen

Sur place
EUR 60 000 - 90 000
Voiture de société
Formation continue / Certification
Medior Application Security Analyst – Risk-Oriented
Medior Application Security Analyst – Risk-Oriented

HumanInTech • Namen

Hybride
EUR 55 000 - 75 000
Expert Lead Sécurité Applicative
Expert Lead Sécurité Applicative

Community Consulting • Namen

Hybride
EUR 90 000 - 120 000
Analyste senior en sécurité applicative et DevSecOps (Freelance optional)
Analyste senior en sécurité applicative et DevSecOps (Freelance optional)

EngiFlex BV • Namen

Sur place
EUR 70 000 - 95 000
Voiture de société
Avantages extra-légaux
Analyste senior en sécurité applicative orienté risques (Freelance possible)
Analyste senior en sécurité applicative orienté risques (Freelance possible)

EngiFlex BV • Namen

Sur place
EUR 55 000 - 85 000
Voiture de société
Formation et certifications
Plan de carrière et budget formation