Medior Application Security Analyst – Risk-Oriented

HumanInTech

Namen

Hybride

EUR 55 000 - 75 000

Plein temps

Il y a 2 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Obtenez une réponse de cet employeur — un CV et une lettre de motivation adaptés exactement à ce qu’on recherche pour ce poste.

Passez les filtres ATS

Résumé du poste

HumanInTech in Namur, Belgium, seeks a seasoned SALM risk specialist to manage risk analyses, threat modelling and security requirements across the application lifecycle. You will coordinate with project teams, architects and suppliers, ensuring proportionate controls and proper documentation.

The role supports a 12-month assignment starting January 2027 with hybrid on-site work (Namur). Employment options include freelance or permanent with potential for subsequent assignments.

Qualifications

  • Experience in application risk analysis and threat modelling.
  • Experience in project support: requirements definition, reviews, derogations and risk management.
  • Ability to communicate security requirements clearly to project managers, architects, developers and stakeholders.
  • Knowledge of threat modelling methods and frameworks: OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2 and CyFun.
  • Experience with documentation, decision traceability and tracking tools (GRC).
  • Strong analytical skills with the ability to prioritise risks.
  • Autonomous management of multiple cases in parallel.
  • Collaborative mindset when working with diverse technical and business teams.
  • Proficiency in French (C2).

Responsabilités

  • Collect information and qualify application criticality, determining SALM pathway and controls.
  • Perform or support risk analyses and threat modelling per organisation's methodology.
  • Participate in architecture and data-flow reviews to define security requirements.
  • Advise project managers, architects, developers and stakeholders throughout the project lifecycle.
  • Track recommendations, evidence and decisions; maintain a register of residual risks.
  • Prepare SALM opinion before production release and escalate significant risks.
  • Contribute to SALM standards, checklists, templates and lessons learned.
  • Collaborate with SOC, DevSecOps, SecOps and external suppliers to automate controls.

Connaissances

Application risk analysis
Threat modelling
Security requirements definition
Stakeholder communication
GRC tools
Analytical thinking
Autonomy in multiple cases
Collaboration
French (C2)

Formation

Bachelor's degree or higher

Outils

OWASP
STRIDE
ISO 27005
NIST SSDF
NIS2
CyFun
GRC tools

Description du poste

What you will do

You will join the Secure Application Lifecycle Management (SALM) team within the security unit of a Belgian public-sector organisation that manages a portfolio of around 800 applications, including nearly 400 web applications. Your main responsibility is to handle the risk and requirements aspects of SALM cases, accompanying projects from initial qualification to production while ensuring controls are proportionate to application criticality and decisions are properly documented.

Your key activities include:

  • Collect information and qualify application criticality, determining the SALM pathway and applicable controls
  • Perform or support application risk analyses and threat modelling according to the organisation's methodology, prioritising scenarios, measures and residual risks
  • Participate in architecture, design and data flow reviews, defining and verifying application security requirements
  • Advise project managers, architects, developers, business stakeholders and suppliers throughout the project lifecycle
  • Track recommendations, exceptions, evidence and decisions, maintaining a register of residual risks and derogations
  • Consolidate the security dossier and prepare the SALM opinion before production release, escalating significant arbitrations or risks to the team lead
  • Contribute to SALM standards, checklists, templates and lessons learned

You will work closely with project managers, developers, architects, operations teams, functional managers, service centres, DevSecOps and SecOps teams, the SOC, business units and external suppliers. The goal is to replace ad-hoc manual controls with a common, risk-proportionate approach that is more automated and covers the entire application lifecycle.

Typical deliverables include qualification and criticality sheets, risk analyses or threat models, security requirements and control plans, architecture or design review reports, registers of recommendations and residual risks, and SALM opinions before production.

What we are looking for
  • Proven experience in application risk analysis, identifying threat scenarios and defining treatment measures
  • Experience in project support: requirements definition, reviews, derogations, residual risk management and security opinions
  • Ability to communicate and explain security requirements clearly to project managers, architects, developers, business stakeholders and suppliers
  • Knowledge of threat modelling methods and frameworks: OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2 and CyFun
  • Experience with documentation, decision traceability and the use of tracking or GRC tools
  • Strong analytical skills: ability to structure complex situations and distinguish priority risks
  • Pragmatic approach: proposing proportionate, realistic and verifiable measures
  • Rigour in documenting assumptions, decisions, evidence and residual risks
  • Autonomy in managing multiple cases in parallel
  • Collaborative mindset when working with diverse technical and business teams
  • Proficiency in French (C2 level)
The setting

This assignment runs for 12 months starting in January 2027. The location is Namur, with a hybrid working arrangement. You are expected to be on-site at least 60% of the time.

You will report to the head of the GRC and application security sub-unit within the security unit.

You can join us for this assignment as a freelancer or as an employee of HumanInTech. Same role, same team. If you join as an employee, your employment continues beyond this assignment. When it ends, we’ll work together to find your next assignment.

Location: Namur, hybrid

Work address: Belgium

Employer / contracting party: HumanInTech

Applications close (Brussels time): October 7, 2026 at 2:00 AM

Engagement: Freelance or employed by HumanInTech

Working hours: Full-time

Experience: 3–5 years or more

Education: Bachelor's or more

Published: October 2026

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Application Security Analyst – Risk-Oriented
Senior Application Security Analyst – Risk-Oriented

HumanInTech • Namen

Hybride
EUR 65 000 - 90 000
Analyste en sécurité applicative Medior – Orienté risques
Analyste en sécurité applicative Medior – Orienté risques

HumanInTech • Namen

Hybride
EUR 60 000 - 85 000
Senior Application Security Risk Analyst (SALM)
Senior Application Security Risk Analyst (SALM)

HumanInTech • Namen

Hybride
EUR 55 000 - 75 000
Application Architect with Security Focus
Application Architect with Security Focus

HumanInTech • Brussel Hoofdstad

Hybride
EUR 75 000 - 95 000
Hybrid working model
Brussels-based assignment
Freelance or employee
Medior Application Security Analyst – Risikoorientiert
Medior Application Security Analyst – Risikoorientiert

HumanInTech • Namen

Hybride
EUR 60 000 - 90 000
Expert Lead Application Security
Expert Lead Application Security

HumanInTech • Namen

Hybride
EUR 85 000 - 120 000
Analyste senior en sécurité applicative orienté risques (Freelance possible)
Analyste senior en sécurité applicative orienté risques (Freelance possible)

EngiFlex BV • Namen

Sur place
EUR 55 000 - 85 000
Voiture de société
Formation et certifications
Plan de carrière et budget formation
Senior Application Security Analyst – Risikoorientiert
Senior Application Security Analyst – Risikoorientiert

HumanInTech • Namen

Hybride
EUR 70 000 - 100 000
Medior Application Security Analyst – Risicogericht
Medior Application Security Analyst – Risicogericht

HumanInTech • Namen

Hybride
EUR 65 000 - 90 000
Analyste en sécurité applicative orienté risques (Freelance optional)
Analyste en sécurité applicative orienté risques (Freelance optional)

EngiFlex BV • Namen

Sur place
EUR 65 000 - 95 000
Voiture de société