AISB-1048 Medior IT Security Analyst

Abakus IT-Solutions

Namen

Hybride

EUR 60 000 - 85 000

Plein temps

Il y a 9 heures
Soyez parmi les premiers à postuler
Générateur de candidature

N’envoyez pas un CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.

Passez les filtres ATS

Résumé du poste

Abakus IT-Solutions is seeking a medior Secure Application Lifecycle Management (SALM) specialist to manage risk, security controls and requirements across the full application lifecycle for a Belgian public administration.

You will support projects from initial classification through go-live, ensuring traceable decisions, proper risk mitigation and alignment with SALM standards. Hybrid work with on-site presence encouraged where needed.

Qualifications

  • Threat modelling methods and frameworks: OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2 and CyFun.
  • Clear communication of security topics to project managers, architects, developers, business units and suppliers.
  • Documentation, decision traceability and use of tracking or GRC tools.
  • Analytical thinking to structure complex situations and identify priority risks.
  • Autonomy to handle several cases in parallel.
  • Collaboration with DevSecOps, operations and suppliers.

Responsabilités

  • Support projects from initial classification through to go-live.
  • Define SALM path and applicable controls.
  • Carry out or support risk analyses and threat modelling.
  • Prioritize scenarios, measures and residual risks.
  • Take part in architecture, design and data flow reviews.
  • Define and verify application security requirements.
  • Advise project managers, architects, developers, business units and suppliers.
  • Track recommendations, exceptions, evidence and decisions.
  • Compile the SALM opinion before go-live and escalate significant risks.

Connaissances

Application risk analysis
Threat modelling
Communication with stakeholders
GRC tools
Threat modelling methods
OWASP
STRIDE
ISO 27005
NIST SSDF
NIS2 & CyFun
Documentation & traceability
Autonomy
Collaboration
Analytical thinking
Pragmatism
Teaching security concepts
Rigour

Outils

GRC tools
Tracking tools

Description du poste

A cross-functional application security role, from the initial classification of an application through to go-live.

Context and project

A Belgian public administration runs several hundred applications, many of them web applications. They rely on a wide range of technologies and suppliers. When their lifecycle is poorly controlled, several risks arise:

  • disruption of public services;
  • compromise of data or application functions;
  • exploitation of flaws in code, components or configurations;
  • growing technical debt and obsolescence;
  • non-compliance with security requirements, including NIS2, CyFun and the internal information security programme;
  • slower and more costly fixes when security comes in too late.

A dedicated Secure Application Lifecycle Management (SALM) team handles these risks. Its goal is to replace one-off manual checks with a shared, risk-based and more automated approach that covers the full application lifecycle. Its areas of work are:

  • application criticality and the security controls that apply;
  • risk analyses and follow-up of agreed measures;
  • application security standards and practices;
  • integration of controls into projects and DevSecOps/CI/CD pipelines: SAST, DAST, SCA, vulnerability scanning, penetration testing;
  • follow-up of exceptions, residual risks and recommendations before go-live;
  • tracking of vulnerabilities, obsolescence and application decommissioning;
  • advice to project, development, architecture and operations teams.

The team works with project managers, developers, architects, operations, functional owners, service centres, DevSecOps and SecOps teams, the SOC, business units and suppliers. It reports to the head of GRC and application security.

Responsibilities

The role covers the risk and requirements side of SALM cases. It involves supporting projects from initial classification through to go-live. It also involves making sure controls match each application's criticality and that decisions are traceable.

Classification and criticality

  • Gather the relevant information and assess the application's criticality.
  • Define the SALM path and the applicable controls.

Risks and threats

  • Carry out or support risk analyses and threat modelling, following the methodology in place.
  • Prioritize scenarios, measures and residual risks.

Architecture and requirements

  • Take part in architecture, design and data flow reviews.
  • Define and verify application security requirements.

Project support

  • Advise project managers, architects, developers, business units and suppliers.
  • Track recommendations, exceptions, evidence and decisions.

Security sign-off and go-live

  • Compile the security file and prepare the SALM opinion.
  • Escalate significant trade-offs or risks to the team lead.
  • Contribute to SALM standards, checklists, templates and lessons learned.
  • Classification and criticality sheet
  • Risk analysis or threat model
  • Security requirements and control plan
  • Register of recommendations, exceptions and residual risks
  • SALM opinion before go-live
Candidate profile
Required technical skills (medior level ~3 years experience)
  • Project support: requirements, reviews, exceptions, residual risks and security opinions.
  • Application risk analysis, identification of threat scenarios and definition of treatment measures.
  • Clear communication of security topics to project managers, architects, developers, business units and suppliers.
  • Documentation, decision traceability and use of tracking or GRC tools.
  • Threat modeling methods and frameworks: OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2 and CyFun.
  • Analytical thinking: structure complex situations and identify priority risks.
  • Pragmatism: propose proportionate, realistic and verifiable measures.
  • Teaching skills: make security requirements understandable for projects and business units.
  • Rigour: document assumptions, decisions, evidence and residual risks.
  • Autonomy: handle several cases in parallel.
  • Collaboration: work with developers, architects, DevSecOps teams, operations and suppliers.
Languages
  • French: C2 level (required)
Location and conditions
  • Hybrid work, with on-site presence of 60% or more if needed.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

AISB-1047 Senior IT Security Analyst
AISB-1047 Senior IT Security Analyst

Abakus IT-Solutions • Namen

Hybride
EUR 60 000 - 90 000
Medior Application Security Analyst – Risk-Oriented
Medior Application Security Analyst – Risk-Oriented

HumanInTech • Namen

Hybride
EUR 55 000 - 75 000
Analyste senior en sécurité applicative orienté risques (Freelance possible)
Analyste senior en sécurité applicative orienté risques (Freelance possible)

EngiFlex BV • Namen

Sur place
EUR 55 000 - 85 000
Voiture de société
Formation et certifications
Plan de carrière et budget formation
AISB-1050 Senior Application Security Analyst (Risk-Oriented)
AISB-1050 Senior Application Security Analyst (Risk-Oriented)

Abakus IT-Solutions • Namen

Hybride
EUR 70 000 - 110 000
AISB-1049 Lead Application Security Expert
AISB-1049 Lead Application Security Expert

Abakus IT-Solutions • Namen

Hybride
EUR 85 000 - 120 000
Expert Lead Sécurité Applicative
Expert Lead Sécurité Applicative

Community Consulting • Namen

Hybride
EUR 90 000 - 120 000
En sécurité applicative et DevSecOps (Employed or freelance)
En sécurité applicative et DevSecOps (Employed or freelance)

EngiFlex BV • Namen

Sur place
EUR 90 000 - 120 000
Voiture de société
Formation et certifications
Avantages extra-légaux
+1
Analyste en sécurité applicative orienté risques (Freelance optional)
Analyste en sécurité applicative orienté risques (Freelance optional)

EngiFlex BV • Namen

Sur place
EUR 65 000 - 95 000
Voiture de société
Analyste en sécurité applicative et DevSecOps (Employed or freelance)
Analyste en sécurité applicative et DevSecOps (Employed or freelance)

EngiFlex BV • Namen

Sur place
EUR 60 000 - 90 000
Voiture de société
Formation continue / Certification
Senior Application Security Analyst – Risk-Oriented
Senior Application Security Analyst – Risk-Oriented

HumanInTech • Namen

Hybride
EUR 65 000 - 90 000