AISB-1050 Senior Application Security Analyst (Risk-Oriented)
Risk-oriented senior analyst role within a dedicated team, from initial qualification through to go-live.
Context and Project
An organisation manages an extensive application estate, including many web applications, built on a wide range of technologies and supplied by various vendors. Poor control of their lifecycle exposes the organisation to service interruptions, data compromise, exploitation of vulnerabilities, growing technical debt and non-compliance with security requirements (NIS2, CyFun).
A dedicated application security team sits within the security department. Its goal is to replace one-off, manual controls with a shared approach that is proportionate to risk, more automated and covers the full application lifecycle.
The team works with project managers, developers, architects, operations teams, functional owners, service centres, DevSecOps and SecOps teams, the SOC, business units and suppliers.
Role and Responsibilities
The role involves handling the risk and requirements aspects of application security cases. Projects are supported from initial qualification through to go-live, with a focus on matching controls to application criticality and keeping decisions traceable.
Qualification and Criticality- Collect relevant information and assess application criticality.
- Determine the control pathway and the controls that apply.
Risks and Threats- Carry out or support risk analyses and threat modelling following the established methodology.
- Prioritise scenarios, measures and residual risks.
Architecture and Requirements- Take part in architecture, design and data flow reviews.
- Define and verify application security requirements.
Project Support- Advise project managers, architects, developers, business units and suppliers.
- Track recommendations, exemptions, evidence and decisions.
Opinion and Go-Live- Consolidate the security file and prepare the security opinion before go-live.
- Escalate significant arbitration items or risks to the team lead.
- Contribute to standards, checklists, templates and lessons learned.
- Qualification and criticality sheet.
- Risk analysis or threat model.
- Security requirements and control plan.
- Register of recommendations, exemptions and residual risks.
- Security opinion before go-live.
Profile
Education and Experience
- Senior experience in IT security, in an analyst role (IT Security Analyst, senior level).
- Experience performing risk analyses for a critical application.
- Experience in application threat modelling.
- Experience defining and verifying security requirements in an application project.
- Experience following up on exemptions or residual risks through to a formal decision.
Required Technical Skills
- Project support: requirements, reviews, exemptions, residual risks and security opinions: senior level.
- Application risk analysis, identification of threat scenarios and definition of treatment measures: senior level.
- Threat modelling methods and frameworks: OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2, CyFun: confirmed level.
- Communication and explanation of security topics to project managers, architects, developers, business units and suppliers: confirmed level.
Appreciated Skills
- Documentation, decision traceability and use of tracking or GRC tools: junior level.
Soft Skills
- Analytical mindset: structure a complex situation and identify priority risks.
- Pragmatism: propose measures that are proportionate, realistic and verifiable.
- Teaching ability: make security requirements understandable to projects and business units.
- Rigour: document assumptions, decisions, evidence and residual risks.
- Autonomy: manage several cases in parallel.
- Collaboration: work with developers, architects, DevSecOps teams, operations and suppliers.
Location and Conditions
- Working model: hybrid, with on‑site presence of 60% of the time or more if needed.