AISB-1052 Application Security Analyst (Technical Controls and DevSecOps)
Analyst role focused on technical application security controls, within a dedicated team.
Context and Project
An organisation manages an extensive application estate, including many web applications, built on a wide range of technologies and supplied by various vendors. Poor control of their lifecycle exposes the organisation to service interruptions, data compromise, exploitation of vulnerabilities, growing technical debt and non-compliance with security requirements (NIS2, CyFun).
A dedicated application security team sits within the security department. Its goal is to replace one-off, manual controls with a shared approach that is proportionate to risk, more automated and covers the full application lifecycle.
The team works with project managers, developers, architects, operations teams, functional owners, service centres, DevSecOps and SecOps teams, the SOC, business units and suppliers.
Role and Responsibilities
- Integrate and operate application security tools (SAST, DAST, SCA, secrets detection, vulnerability scans) in projects and CI/CD pipelines.
- Analyse and qualify vulnerabilities: exploitability, impact, false positive filtering and fix prioritisation.
- Define and configure blocking criteria (quality gates) before go-live.
- Contribute to the automation of controls in CI/CD pipelines.
- Assess the security of application architecture: data flows, authentication, authorisation, encryption, APIs and dependencies.
- Report findings in a technical, documented form.
- Take part in the follow-up of penetration tests and remediation plans.
- Advise project, development, architecture and operations teams.
Profile
Education and Experience
- Confirmed experience in IT security, in an analyst role (IT Security Analyst, confirmed level).
- Experience integrating or operating a SAST, DAST, SCA or secrets detection tool in a CI/CD pipeline.
- Experience qualifying scan results, filtering out false positives and prioritising fixes.
- Experience defining a quality gate or blocking criterion before go-live.
- Experience supporting developers in fixing application vulnerabilities.
- Experience following up a penetration test or a remediation plan.
Required Technical Skills
- Vulnerability analysis and qualification: exploitability, impact, false positives and prioritisation: confirmed level.
- Application architecture and security: data flows, authentication, authorisation, encryption, APIs and dependencies: confirmed level.
- CI/CD pipelines and DevSecOps practices: integration, configuration, automation and quality gates: confirmed level.
- Application security tools: SAST, DAST, SCA, secrets detection and vulnerability scans: confirmed level.
- Technical reporting, documentation and support for development teams: confirmed level.
- Technical frameworks: OWASP Top 10, ASVS, SAMM, CWE, CVSS and NIST SSDF: junior level.
- Secure development, APIs, software dependencies, containers and secrets management: junior level.
Location and Conditions
- Working model: hybrid, with on-site presence of 60% of the time or more if needed.