AISB-1049 Lead Application Security Expert
Lead and go-to expert in application security, within a dedicated team, with a strong DevSecOps dimension.
Context and Project
An organisation manages an extensive application estate, including many web applications, built on a wide range of technologies and supplied by various vendors. Poor control of their lifecycle exposes the organisation to service interruptions, data compromise, exploitation of vulnerabilities, growing technical debt and non-compliance with security requirements (NIS2, CyFun).
A dedicated application security team sits within the security department. Its goal is to replace one-off, manual controls with a shared approach that is proportionate to risk, more automated and covers the full application lifecycle.
The team works with project managers, developers, architects, operations teams, functional owners, DevSecOps and SecOps teams, the SOC, business units and suppliers.
Role and Responsibilities
- Allocate cases among team members.
- Track progress, deadlines and blockers.
- Review high-stakes deliverables and align working practices.
- Prepare decisions for arbitration and produce reporting (tracking dashboards, evolution plans).
Operational Expertise
- Carry out risk analyses following the established methodology.
- Support critical projects, from initial qualification to go-live.
- Take part in architecture, design and code reviews.
- Analyse SAST, DAST, SCA, vulnerability scan and penetration test results.
- Define and prioritise recommendations.
Methodological Framework
- Maintain application security standards and checklists.
- Adapt controls to application criticality and ensure decisions are traceable.
Application Vulnerability Management
- Follow up on recommendations, exemptions and residual risks.
- Monitor application obsolescence and decommissioning.
Projects and DevSecOps
- Embed security controls in projects and CI/CD pipelines.
- Contribute to the automation of controls.
- Advise project managers, developers, architects and operations teams.
- Workload plan, dashboard and case tracking.
- Risk analyses and security opinions.
- Requirements and control plans.
- SAST, DAST, SCA and penetration test reports.
- Application security standards and templates.
Profile
Education and Experience
- Senior experience in IT security, in an expert role (IT Security Expert, senior level).
- Experience coordinating a team of at least three people.
- Experience securing critical applications.
- Experience integrating SAST, DAST or SCA into a CI/CD pipeline.
- Experience improving an application security approach across the full lifecycle, at the scale of an organisation of more than 1,000 people.
Required Technical Skills
- Application security and SSDLC (risks, requirements, reviews, vulnerabilities): senior level, with recent experience (this year).
- DevSecOps: SAST, DAST, SCA, CI/CD, secrets management and penetration testing: senior level.
- Backlog management based on risk and criticality: senior level.
- Processes, standards, templates, indicators and knowledge transfer: confirmed level.
Soft Skills
- Leadership: set direction, support and empower the team (confirmed level).
- Communication with projects, IT, business units, suppliers and management: senior level. Messages are tailored to each audience.
- Sense of responsibility: take ownership of assignments and report back.
- Technical credibility: handle complex cases and substantiate decisions.
- Prioritisation: arbitrate based on risk and capacity.
- High standards and supportiveness: ensure quality and help the team grow.
- Pragmatism: propose measures that can be applied in practice.
- Autonomy and synthesis: follow up on commitments and flag decisions that need arbitration.
Language Requirements
Location and Conditions
- Working model: hybrid, with on-site presence of 60% of the time or more if needed.