Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP

Salt

Brussel Hoofdstad

Hybride

EUR 90 000 - 140 000

Plein temps

Il y a 14 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature complète en une minute — un CV et une lettre de motivation personnalisés, prêts à être envoyés.

Passez les filtres ATS

Résumé du poste

Salt is seeking a Senior Cyber Security Risk Assessment Consultant to join a major Cyber & Information Security function in a hybrid setup across Brussels, Paris, London or Amsterdam. The role focuses on technical security risk assessments, translating risks into security requirements and defining secure by design controls.

You will work with architects, engineers and business stakeholders on complex security challenges.

Qualifications

  • 10+ years of experience in Cyber / Information Security.
  • Proven experience performing technical security risk assessments.
  • Strong knowledge of OWASP and application-security principles.
  • Experience with DAST, SAST, vulnerability assessment, or related security-testing approaches.

Responsabilités

  • Perform security risk assessments across business and IT projects.
  • Identify threats, vulnerabilities and impacts within proposed solutions.
  • Translate security architecture, risks and controls into functional and technical requirements.
  • Define design, implementation and testing processes to protect information systems.
  • Embed Secure by Design principles throughout the technology delivery lifecycle.
  • Review designs against security requirements and validate implementations.
  • Define application security testing requirements and testing scope.
  • Review testing reports and verify remediation of identified risks.
  • Provide security SME guidance to project teams and stakeholders.

Connaissances

Security risk assessment
OWASP knowledge
Stakeholder communication
Threat modeling
Security testing concepts

Outils

DAST
SAST
Code scanning
Penetration testing

Description du poste

Senior Cyber Security Risk Assessment Consultant – DAST / SAST/ OWASP
Location

Brussels , Paris, London or Amsterdam

Working Model

Hybrid

The Opportunity

We are looking for experienced Senior Cyber Security Risk Assessment Consultants to join a major Cyber & Information Security function within a global financial services environment.

You will provide security expertise across a broad portfolio of business and technology projects, working closely with architects, engineers, developers, project teams, risk management and business stakeholders.

A key part of the position is performing technical security risk assessments, translating identified risks into security requirements, reviewing and validating solution designs, and defining appropriate security testing requirements.

This is not a SOC or purely operational security role. We are looking for experienced security professionals who can understand complex technical solutions, identify security risks and vulnerabilities, and advise projects on the controls required to achieve Secure by Design.

Key Responsibilities
  • Perform security risk assessments across business and IT projects.
  • Identify threats, vulnerabilities, security weaknesses and potential impacts within proposed solutions.
  • Translate security architecture, policies, risks and controls into clear functional and technical security requirements.
  • Define and advise on the design, implementation and testing processes required to protect information systems and assets.
  • Embed Secure by Design principles throughout the technology delivery lifecycle.
  • Contribute to architectural and solution design discussions and validate designs against security requirements.
  • Review applications, platforms and infrastructure from a security perspective.
  • Define application security testing requirements, including appropriate use of DAST, SAST, code scanning and penetration testing.
  • Define penetration-testing scope and work closely with security-testing teams throughout execution.
  • Review security-testing and penetration-testing reports and assess whether identified risks have been appropriately addressed.
  • Apply OWASP principles and guidelines when assessing application security.
  • Identify security gaps and recommend appropriate remediation and compensating controls.
  • Produce and maintain security standards, principles, baselines and documented security requirements.
  • Recommend new or improved security services and controls.
  • Act as a Security Subject Matter Expert for project and business teams.
  • Present security risks, findings and recommendations clearly to both senior stakeholders and deep technical specialists.
  • Work closely with Business Owners, Business Analysts, Project Managers, Risk Management, Architects, Developers, Engineers and internal/external auditors.
Application Security / DAST / OWASP

We are particularly interested in candidates with strong knowledge of Application Security and experience across areas such as:

  • OWASP Top 10 and wider OWASP security principles
  • DAST / Dynamic Application Security Testing
  • SAST / Static Application Security Testing
  • Secure SDLC / Secure by Design
  • Application vulnerability assessment
  • Web application security
  • API security
  • Code scanning and security-analysis tooling
  • Penetration-testing methodology and scoping
  • Security testing and test-result validation
  • CI/CD security controls
  • DevSecOps
  • Security and compliance automation

You do not need to be a hands-on penetration tester, but you should have sufficient technical knowledge to define security-testing requirements, scope appropriate testing, challenge findings and determine whether security risks have been adequately addressed.

Broader Security Knowledge

Alongside application security, candidates should bring knowledge across one or more additional Cyber & Information Security domains, which could include:

  • Identity & Access Management / IAM / IDaaS
  • PAM, authentication, authorisation and federation
  • PKI, cryptography, encryption and key management
  • Network and DMZ security
  • WAFs and network segmentation
  • Endpoint and platform security
  • Data protection and DLP
  • IaaS / PaaS / SaaS
  • Database and storage security
  • Infrastructure as Code
  • Infrastructure and security automation

We are not expecting candidates to be specialists across every security domain.

Your Experience

For the senior positions, we are looking for candidates with:

  • 10+ years' experience within Cyber / Information Security.
  • Proven experience performing technical security risk assessments.
  • Strong understanding of application and/or infrastructure security.
  • Experience identifying security risks and translating these into practical security requirements and controls.
  • Experience contributing to and/or validating technical and architectural solution designs.
  • Strong knowledge of OWASP and application-security principles.
  • Experience with DAST, SAST, vulnerability assessment, penetration testing or related security-testing approaches.
  • Experience defining security-testing requirements and reviewing the resulting findings.
  • Ability to understand complex applications, infrastructure and technology architectures.
  • Experience producing security documentation, standards, principles, requirements or baselines.
  • Experience translating business requirements into appropriate technical security solutions.
  • Strong analytical and critical-thinking skills.
  • Ability to take ownership of security assessments and work independently across multiple projects.
  • Excellent stakeholder-management and communication skills.
  • Ability to explain and defend security recommendations with both senior business stakeholders and highly technical IT professionals.
  • Experience working within large, complex enterprise environments.

Experience within banking, financial services, payments, financial-market infrastructure or another highly regulated/critical environment would be particularly valuable.

Certifications

Relevant professional certifications are advantageous, including:

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Cyber Security Consultant
Cyber Security Consultant

Arcus Search • Brussel Hoofdstad

Sur place
EUR 70 000 - 95 000
AISB-1022 Senior Cybersecurity Expert
AISB-1022 Senior Cybersecurity Expert

Abakus IT-Solutions • Namen

Hybride
EUR 85 000 - 125 000
Security Risk Assesment Consultant
Security Risk Assesment Consultant

recurv • Brussel

Sur place
EUR 90 000 - 130 000
Junior Functional Security Analyst
Junior Functional Security Analyst

Nexeo • Brussel Hoofdstad

Sur place
EUR 30 000 - 42 000
Cybersecurity Engineer – Medior / Senior (M/F/X)
Cybersecurity Engineer – Medior / Senior (M/F/X)

Leonardo Belgium • Brussel

Sur place
EUR 60 000 - 90 000
Cybersecurity Analyst Vulnerability & Attack Surface Management
Cybersecurity Analyst Vulnerability & Attack Surface Management

Harvey Nash • Brussel

Sur place
EUR 70 000 - 90 000
Senior Cybersecurity Architect
Senior Cybersecurity Architect

Keystone Solutions • Brussel

Sur place
EUR 90 000 - 130 000
Senior Security Project Manager
Senior Security Project Manager

In4Matic • Brussel Hoofdstad

Hybride
EUR 90 000 - 130 000
Senior Security Project Manager
Senior Security Project Manager

In4Matic • Brussel

Sur place
EUR 90 000 - 130 000
Senior Cybersecurity Expert Consultant
Senior Cybersecurity Expert Consultant

Keystone Solutions • Brussel

Sur place
EUR 90 000 - 130 000