IT Architect Application Security (Medior)

Rhox

Sint-Gillis

Sur place

EUR 70 000 - 100 000

Plein temps

Il y a 2 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’on recherche pour ce poste.

Passez les filtres ATS

Résumé du poste

Federal Public Service is launching a secure development programme to embed security across software delivery, aligned with NIS2 and CyFun requirements. You will lead foundations, integrate SCA/SAST/DAST in CI/CD, and map changes to development processes while creating dashboards and standard directives for internal and external projects.

You will collaborate with existing development teams, explain security concepts, and guide training and governance to ensure continuous security improvements

Qualifications

  • Background as an application architect with strong security knowledge.
  • Proven track record delivering security initiatives at scale.
  • At least 3 years reviewing security architectures.
  • At least 3 years implementing SCA, SAST and DAST in CI/CD pipelines.
  • At least 3 years of DevSecOps experience.
  • Knowledge of CyFun and SAMM frameworks.
  • Ability to map and document secure development processes clearly.
  • Strong communication to technical and non-technical colleagues.

Responsabilités

  • Review security architectures and advise on designs, infrastructure and development methods.
  • Map process changes and document clear guidance for secure development.
  • Embed SCA, SAST and DAST tools in CI/CD pipelines and promote continuous security.
  • Build application security dashboards and define routines for ongoing improvement.
  • Produce a standard directive for internal projects and external suppliers.
  • Create a security matrix to assess externally delivered projects.
  • Lead planning, progress reporting, documentation and secure-development training.

Connaissances

Security architecture
Application architecture
DevSecOps
CI/CD security tooling
SCA
SAST
DAST
Agile/Lean SD
CyFun knowledge
SAMM
Security concept communication

Outils

SCA tooling
SAST tooling
DAST tooling
CI/CD tooling

Description du poste

A federal public service is establishing a secure development practice to apply NIS2 and Belgian CyFun requirements in everyday software delivery. You will lead the programme’s foundations, combining security architecture reviews with DevSecOps and security tooling across CI/CD pipelines.

The mission

The work responds to NIS2, in force since October 2024, and the Belgian CyFun framework. Control PR.IP-2 calls for critical systems and components to be developed across the full design cycle, with security-control functions and design and implementation details for security-related interfaces documented. The goal is to integrate secure development into daily procedures, rather than treat compliance as a checklist.

You will work with existing development teams to introduce continuous security practices, using OWASP’s Software Assurance Maturity Model (SAMM) as a reference. You will map changes to development processes, document how teams can apply them, review technical designs, and advise on hardware, software and working methods. The programme also needs application security dashboards, repeatable improvement routines, a standard directive for internal projects and suppliers, and a security matrix for assessing external projects. As project lead, you will plan the work, report progress, document the chosen methods, and may develop and deliver training.

Your responsibilities
  • Review security architectures and advise on designs, infrastructure and development methods.
  • Map process changes and document clear guidance for secure development.
  • Embed SCA, SAST and DAST tools in CI/CD pipelines and promote continuous security.
  • Build application security dashboards and define routines for ongoing improvement.
  • Produce a standard directive for internal projects and external suppliers.
  • Create a security matrix to assess externally delivered projects.
  • Lead planning, progress reporting, documentation and secure-development training.
Your profile
Essential skills
  • Background as an application architect with strong security knowledge, or as a security architect with strong application-development knowledge.
  • Demonstrated experience delivering similar initiatives in an environment of comparable scale.
  • At least 3 years of experience reviewing security architectures.
  • At least 3 years of experience implementing SCA, SAST and DAST tools in CI/CD pipelines.
  • At least 3 years of experience in DevSecOps.
  • Knowledge of project management and Agile or Lean Software Development.
  • Knowledge of security frameworks, including CyFun and SAMM.
  • Knowledge of quality assurance and testing, including test-driven development.
  • Ability to map development-process changes and document them clearly.
  • Ability to explain and promote security concepts to technical and non-technical colleagues.
  • Planning, organisational, leadership and adjustment skills, with a results focus and sense of responsibility.
  • Negotiation and relationship-management skills, including the ability to build, lead and supervise a team.
Preferred skills
  • Familiarity with OWASP SAMM and CyFun.
  • Knowledge of ITIL, Java, Angular, Oracle, Web Services or Service Bus technologies.
Languages
  • Dutch: B2
  • French: B2
  • English: level not specified
Working context
  • This is the launch of a secure development programme, so you will help establish its working practices.
  • You will support existing development teams and provide guidance covering internal projects and external suppliers.
  • The approach centres on SecDevOps, continuous security practices, OWASP SAMM and Agile or Lean methods.
  • Project follow-up includes planning and progress meetings, with the selected methods and their implementation documented.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Application Architect with Security Focus
Application Architect with Security Focus

keystone-solutions • Brussel

Sur place
EUR 75 000 - 105 000
Architecte d’application sécurité DevSecOps (Freelance optional)
Architecte d’application sécurité DevSecOps (Freelance optional)

EngiFlex BV • Brussel Hoofdstad

Hybride
EUR 70 000 - 110 000
Voiture de société
Plan de carrière et formation
Formation continue financée
Architecte d’application sécurité DevSecOps (Freelance optional)
Architecte d’application sécurité DevSecOps (Freelance optional)

EngiFlex BV • Brussel

Sur place
EUR 85 000 - 120 000
Voiture de société
Formation ou certification
Security Architect H/F
Security Architect H/F

Act Digital France • Brussel Hoofdstad

Sur place
EUR 85 000 - 110 000
Architecte Cybersécurité Senior
Architecte Cybersécurité Senior

Rhox • Brussel

Sur place
EUR 90 000 - 130 000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

HumanInTech • Brussel Hoofdstad

Hybride
EUR 90 000 - 120 000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

keystone-solutions • Brussel

Sur place
EUR 120 000 - 150 000
Junior Functional Security Analyst
Junior Functional Security Analyst

Nexeo • Brussel Hoofdstad

Sur place
EUR 30 000 - 42 000
Senior Business Consultant - Cybersecurity
Senior Business Consultant - Cybersecurity

Orange Cyberdefense • Antwerpen

Sur place
EUR 90 000 - 130 000
32 vacation days
Meal vouchers
Eco-cheques
+4
Application Architect / Functional Analyst Job ID: JP055453
Application Architect / Functional Analyst Job ID: JP055453

Itproposal • Brussel

Hybride
EUR 90 000 - 120 000