Context and Objectives: The mission aims to assess and secure the business applications of the information system, to manage risks, and to improve their governance, architecture, operation, and compliance. – Identify risks, vulnerabilities, and compliance gaps; – Evaluate the effectiveness of controls, processes, and service level agreements; – Formulate prioritized and measurable operational recommendations.Main responsibilities: The consultant conducts audits of applications in development or production, particularly during a redesign, major upgrade, security review, intrusion risk assessment, or regulatory change. Their work covers governance, processes, functionalities, data, flows, interfaces, architecture, access rights, security, development, and testing.Activities and expected deliverables • Define the scope of the mission, analyze the documentation and develop the work program; • Conduct interviews, investigations, checks and tests on documents or on site; • Evaluate the risks and the quality of the controls, then formalize substantiated findings; • Facilitate feedback sessions and ensure follow-up on recommendations.Expected deliverables : • Scoping note and audit plan; • Risk and control matrix, application mapping and evidence file; • Register of findings and reporting support; • Provisional and final reports, action plan and monitoring table.Required skills • Proficiency in IT audit methodologies, risk analysis, and control assessment; • Expertise in application architectures, APIs, data flows, databases, cloud computing, access rights management, application security, and secure development practices; • Ability to review code, configurations, logs, and test results, qualify vulnerabilities, and rule out false positives; • Proficiency with audit and security tools, including Burp Suite, OWASP ZAP, Postman, Nessus, Qualys, OpenVAS, SonarQube, Checkmarx, Fortify, Snyk, Nmap, Wireshark, Microsoft Sentinel, Splunk, or equivalent; • Excellent analytical, writing, presentation, and facilitation skills, with rigor, autonomy, diplomacy, and respect for confidentiality.Required frameworks and standards • ISO/IEC 27001, 27002 and 27005, ISO 19011 and ISO 9001; • EBIOS Risk Manager, COBIT and ITIL; • OWASP Top 10 and ASVS, CIS Controls and Benchmarks, NIST Cybersecurity Framework and ANSSI recommendations; • GDPR and CNIL requirements.Selection criteria • Experience: at least five years in application auditing of critical or complex business applications, with comparable references; • Expertise: complete mastery of the audit cycle, risks, application security, tools and required frameworks; • Quality of intervention: structured method, reasoned findings, pragmatic recommendations and actionable deliverables; • Soft skills: autonomy, listening skills, teaching ability, respect for deadlines and ability to work with business, technical and managerial stakeholders.Desired profile: Experienced consultant with at least five years of effective experience in application auditing. They must have conducted end-to-end missions — scoping, document analysis, interviews, testing, risk assessment and controls, reporting and follow-up — on applications in project or production, in collaboration with business, development, production, security and IT governance teams.Application: CV + cover letter + copies of diplomas to be sent to contact@keoni.fr