Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’on recherche pour ce poste.
Federal Public Service is launching a secure development programme to embed security across software delivery, aligned with NIS2 and CyFun requirements. You will lead foundations, integrate SCA/SAST/DAST in CI/CD, and map changes to development processes while creating dashboards and standard directives for internal and external projects.
You will collaborate with existing development teams, explain security concepts, and guide training and governance to ensure continuous security improvements
A federal public service is establishing a secure development practice to apply NIS2 and Belgian CyFun requirements in everyday software delivery. You will lead the programme’s foundations, combining security architecture reviews with DevSecOps and security tooling across CI/CD pipelines.
The work responds to NIS2, in force since October 2024, and the Belgian CyFun framework. Control PR.IP-2 calls for critical systems and components to be developed across the full design cycle, with security-control functions and design and implementation details for security-related interfaces documented. The goal is to integrate secure development into daily procedures, rather than treat compliance as a checklist.
You will work with existing development teams to introduce continuous security practices, using OWASP’s Software Assurance Maturity Model (SAMM) as a reference. You will map changes to development processes, document how teams can apply them, review technical designs, and advise on hardware, software and working methods. The programme also needs application security dashboards, repeatable improvement routines, a standard directive for internal projects and suppliers, and a security matrix for assessing external projects. As project lead, you will plan the work, report progress, document the chosen methods, and may develop and deliver training.