AISB-1050 Senior Application Security Analyst (Risk-Oriented)

Abakus IT-Solutions

Namen

Hybride

EUR 70 000 - 110 000

Plein temps

Il y a 9 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV personnalisé et une lettre de motivation en environ une minute.

Passez les filtres ATS

Résumé du poste

Abakus IT-Solutions is seeking a senior Application Security Analyst (Risk-Oriented) with extensive IT security background to manage risk and requirements for application security cases from qualification to go-live. The role collaborates with project managers, architects, developers, operations, and suppliers to tailor controls to critical applications while keeping decisions traceable.

You will perform risk analyses and threat modelling using established methodologies, define and verify

Qualifications

  • Senior IT security experience, in an analyst role (IT Security Analyst, senior level).
  • Experience performing risk analyses for a critical application.
  • Experience in application threat modelling.
  • Experience defining and verifying security requirements in an application project.
  • Experience following up on exemptions or residual risks through to a formal decision.

Responsabilités

  • Handle risk and requirements aspects of application security cases from qualification through to go-live.
  • Advise project managers, architects, developers, business units and suppliers.
  • Track recommendations, exemptions, evidence and decisions.
  • Prepare security opinion before go-live.
  • Consolidate the security file and escalate significant arbitration items or risks to the team lead.
  • Contribute to standards, checklists, templates and lessons learned.
  • Document risk analyses and threat models and maintain traceability.

Connaissances

Application risk analysis
Threat modelling
Security requirements definition
Stakeholder communication
Autonomy

Outils

GRC tools

Description du poste

AISB-1050 Senior Application Security Analyst (Risk-Oriented)

Risk-oriented senior analyst role within a dedicated team, from initial qualification through to go-live.

Context and Project

An organisation manages an extensive application estate, including many web applications, built on a wide range of technologies and supplied by various vendors. Poor control of their lifecycle exposes the organisation to service interruptions, data compromise, exploitation of vulnerabilities, growing technical debt and non-compliance with security requirements (NIS2, CyFun).

A dedicated application security team sits within the security department. Its goal is to replace one-off, manual controls with a shared approach that is proportionate to risk, more automated and covers the full application lifecycle.

The team works with project managers, developers, architects, operations teams, functional owners, service centres, DevSecOps and SecOps teams, the SOC, business units and suppliers.

Role and Responsibilities

The role involves handling the risk and requirements aspects of application security cases. Projects are supported from initial qualification through to go-live, with a focus on matching controls to application criticality and keeping decisions traceable.

Qualification and Criticality
  • Collect relevant information and assess application criticality.
  • Determine the control pathway and the controls that apply.
Risks and Threats
  • Carry out or support risk analyses and threat modelling following the established methodology.
  • Prioritise scenarios, measures and residual risks.
Architecture and Requirements
  • Take part in architecture, design and data flow reviews.
  • Define and verify application security requirements.
Project Support
  • Advise project managers, architects, developers, business units and suppliers.
  • Track recommendations, exemptions, evidence and decisions.
Opinion and Go-Live
  • Consolidate the security file and prepare the security opinion before go-live.
  • Escalate significant arbitration items or risks to the team lead.
  • Contribute to standards, checklists, templates and lessons learned.
  • Qualification and criticality sheet.
  • Risk analysis or threat model.
  • Security requirements and control plan.
  • Register of recommendations, exemptions and residual risks.
  • Security opinion before go-live.
Profile

Education and Experience

  • Senior experience in IT security, in an analyst role (IT Security Analyst, senior level).
  • Experience performing risk analyses for a critical application.
  • Experience in application threat modelling.
  • Experience defining and verifying security requirements in an application project.
  • Experience following up on exemptions or residual risks through to a formal decision.

Required Technical Skills

  • Project support: requirements, reviews, exemptions, residual risks and security opinions: senior level.
  • Application risk analysis, identification of threat scenarios and definition of treatment measures: senior level.
  • Threat modelling methods and frameworks: OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2, CyFun: confirmed level.
  • Communication and explanation of security topics to project managers, architects, developers, business units and suppliers: confirmed level.

Appreciated Skills

  • Documentation, decision traceability and use of tracking or GRC tools: junior level.

Soft Skills

  • Analytical mindset: structure a complex situation and identify priority risks.
  • Pragmatism: propose measures that are proportionate, realistic and verifiable.
  • Teaching ability: make security requirements understandable to projects and business units.
  • Rigour: document assumptions, decisions, evidence and residual risks.
  • Autonomy: manage several cases in parallel.
  • Collaboration: work with developers, architects, DevSecOps teams, operations and suppliers.
Location and Conditions
  • Working model: hybrid, with on‑site presence of 60% of the time or more if needed.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

AISB-1049 Lead Application Security Expert
AISB-1049 Lead Application Security Expert

Abakus IT-Solutions • Namen

Hybride
EUR 85 000 - 120 000
AISB-1052 Application Security Analyst (Technical Controls and DevSecOps)
AISB-1052 Application Security Analyst (Technical Controls and DevSecOps)

Abakus IT-Solutions • Namen

Hybride
EUR 60 000 - 90 000
AISB-1047 Senior IT Security Analyst
AISB-1047 Senior IT Security Analyst

Abakus IT-Solutions • Namen

Hybride
EUR 60 000 - 90 000
AISB-1048 Medior IT Security Analyst
AISB-1048 Medior IT Security Analyst

Abakus IT-Solutions • Namen

Hybride
EUR 60 000 - 85 000
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP
Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP

Salt • Brussel Hoofdstad

Hybride
EUR 90 000 - 140 000
Senior Security Officer
Senior Security Officer

Onetowin • Brussel Hoofdstad

Hybride
EUR 90 000 - 120 000
Application Security Analyst
Application Security Analyst

Editx • Corbais

Sur place
EUR 60 000 - 90 000
Application Security & Risk Analyst – Medior / Senior
Application Security & Risk Analyst – Medior / Senior

Community Consulting • Namen

Hybride
EUR 55 000 - 75 000
Security Analyst
Security Analyst

Next Ventures • Brussel

Sur place
EUR 90 000 - 150 000
Junior Functional Security Analyst
Junior Functional Security Analyst

Nexeo • Brussel Hoofdstad

Sur place
EUR 30 000 - 42 000