Business application audit consultant

Keoni

Paris

Hybride

EUR 70 000 - 100 000

Plein temps

Il y a 18 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV personnalisé et une lettre de motivation qui correspondent directement à l’offre.

Passez les filtres ATS

Résumé du poste

Keoni is seeking an experienced IT auditing consultant to assess and secure critical business applications across development and production environments, especially during redesigns, upgrades, security reviews, or regulatory changes.

You will map architectures, data flows, and controls, review code and logs, and deliver risk assessments, findings, action plans, and monitoring tables in close collaboration with business, development, production, security, and IT governance teams.

Qualifications

  • Proficiency in IT audit methodologies, risk analysis, and control assessment.
  • Expertise in application architectures, APIs, data flows, databases, cloud computing, access rights management, application security, and secure development practices.
  • Ability to review code, configurations, logs, and test results, qualify vulnerabilities, and rule out false positives.
  • Proficiency with audit and security tools, including Burp Suite, OWASP ZAP, Postman, Nessus, Qualys, OpenVAS, SonarQube, Checkmarx, Fortify, Snyk, Nmap, Wireshark, Microsoft Sentinel, Splunk, or equivalent.
  • Excellent analytical, writing, presentation, and facilitation skills, with rigor, autonomy, diplomacy, and respect for confidentiality.

Responsabilités

  • Define the scope of the mission, analyze the documentation and develop the work program.
  • Conduct interviews, investigations, checks and tests on documents or on site.
  • Evaluate the risks and the quality of the controls, then formalize substantiated findings.
  • Facilitate feedback sessions and ensure follow-up on recommendations.

Connaissances

IT audit methodologies
Risk analysis
Control assessment
Application architectures
APIs
Data flows
Databases
Cloud computing
Access rights management
Application security
Secure development practices
Code review
Configurations review
Logs review
Vulnerability qualification
False positives elimination
Audit tools
Burp Suite
OWASP ZAP
Postman
Nessus
Qualys
OpenVAS
SonarQube
Checkmarx
Fortify
Snyk
Nmap
Wireshark
Microsoft Sentinel
Splunk
Equivalent tools

Outils

Burp Suite
OWASP ZAP
Postman
Nessus
Qualys
OpenVAS
SonarQube
Checkmarx
Fortify
Snyk
Nmap
Wireshark
Microsoft Sentinel
Splunk

Description du poste

Context and Objectives: The mission aims to assess and secure the business applications of the information system, to manage risks, and to improve their governance, architecture, operation, and compliance. – Identify risks, vulnerabilities, and compliance gaps; – Evaluate the effectiveness of controls, processes, and service level agreements; – Formulate prioritized and measurable operational recommendations.Main responsibilities: The consultant conducts audits of applications in development or production, particularly during a redesign, major upgrade, security review, intrusion risk assessment, or regulatory change. Their work covers governance, processes, functionalities, data, flows, interfaces, architecture, access rights, security, development, and testing.Activities and expected deliverables • Define the scope of the mission, analyze the documentation and develop the work program; • Conduct interviews, investigations, checks and tests on documents or on site; • Evaluate the risks and the quality of the controls, then formalize substantiated findings; • Facilitate feedback sessions and ensure follow-up on recommendations.Expected deliverables : • Scoping note and audit plan; • Risk and control matrix, application mapping and evidence file; • Register of findings and reporting support; • Provisional and final reports, action plan and monitoring table.Required skills • Proficiency in IT audit methodologies, risk analysis, and control assessment; • Expertise in application architectures, APIs, data flows, databases, cloud computing, access rights management, application security, and secure development practices; • Ability to review code, configurations, logs, and test results, qualify vulnerabilities, and rule out false positives; • Proficiency with audit and security tools, including Burp Suite, OWASP ZAP, Postman, Nessus, Qualys, OpenVAS, SonarQube, Checkmarx, Fortify, Snyk, Nmap, Wireshark, Microsoft Sentinel, Splunk, or equivalent; • Excellent analytical, writing, presentation, and facilitation skills, with rigor, autonomy, diplomacy, and respect for confidentiality.Required frameworks and standards • ISO/IEC 27001, 27002 and 27005, ISO 19011 and ISO 9001; • EBIOS Risk Manager, COBIT and ITIL; • OWASP Top 10 and ASVS, CIS Controls and Benchmarks, NIST Cybersecurity Framework and ANSSI recommendations; • GDPR and CNIL requirements.Selection criteria • Experience: at least five years in application auditing of critical or complex business applications, with comparable references; • Expertise: complete mastery of the audit cycle, risks, application security, tools and required frameworks; • Quality of intervention: structured method, reasoned findings, pragmatic recommendations and actionable deliverables; • Soft skills: autonomy, listening skills, teaching ability, respect for deadlines and ability to work with business, technical and managerial stakeholders.Desired profile: Experienced consultant with at least five years of effective experience in application auditing. They must have conducted end-to-end missions — scoping, document analysis, interviews, testing, risk assessment and controls, reporting and follow-up — on applications in project or production, in collaboration with business, development, production, security and IT governance teams.Application: CV + cover letter + copies of diplomas to be sent to contact@keoni.fr
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

IT Project Audit Consultant
IT Project Audit Consultant

Keoni • Paris

Hybride
EUR 60 000 - 90 000
Transport Allowance
Senior Application Audit & Risk Consultant
Senior Application Audit & Risk Consultant

Keoni • Paris

Hybride
EUR 70 000 - 100 000
Application Security/AppSec Team Lead – DevSecOps
Application Security/AppSec Team Lead – DevSecOps

Demartino Law • France

Hybride
EUR 90 000 - 140 000
Senior Consultant, IT Governance and Organization - CLA
Senior Consultant, IT Governance and Organization - CLA

Demartino Law • France

Hybride
EUR 90 000 - 130 000
Senior Audit Consultant – IT Incident Audit
Senior Audit Consultant – IT Incident Audit

Keoni • Paris

Hybride
EUR 90 000 - 130 000
Business Consultant – Business Analyst – IDF
Business Consultant – Business Analyst – IDF

Demartino Law • Paris

Hybride
EUR 45 000 - 65 000
Business Analyst Senior & Chef de Projet – Application Conformité
Business Analyst Senior & Chef de Projet – Application Conformité

Business At Work • Paris

Sur place
EUR 60 000 - 90 000
Consultant Gouvernance Risque et Conformité Cyber
Consultant Gouvernance Risque et Conformité Cyber

CNPP • Clichy

Hybride
EUR 90 000 - 125 000
Consultant Gouvernance Risque et Conformité Cyber
Consultant Gouvernance Risque et Conformité Cyber

Groupe CNPP • Clichy

Sur place
EUR 90 000 - 130 000
Formation continue
Projets variés
Consultant Risk & Compliance Tech H/F
Consultant Risk & Compliance Tech H/F

Advolis Orfis • Paris

Sur place
EUR 60 000 - 90 000