Senior Application Security Consultant

Orange
Antwerpen, Belgium
29 days ago
Apply on be.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Continuous Integration Identity and Access Management Information Systems Security Architecture Professional Open Web Application Security Software Engineering Software Security CIS Benchmarks Devsecops

Job description

As a Senior Application Security Consultant, you help organisations integrate security throughout the Secure Software Development Lifecycle (SSDLC) while ensuring alignment with governance, risk and compliance frameworks such as NIS2, DORA, ISO/IEC 27001 and OWASP ASVS. You combine deep application security expertise with strong advisory capabilities and can translate technical risks into business-oriented recommendations., * Lead Application Security Assessments and Secure Architecture Reviews.

  • Facilitate Threat Modelling and Architectural Risk Assessments (ARA).
  • Support the implementation and continuous improvement of SSDLC and DevSecOps practices.
  • Define and review secure coding standards and security requirements.
  • Assess applications against OWASP ASVS and other recognised standards.
  • Advise development teams, architects and business stakeholders on secure design.
  • Contribute to application security governance, policies and roadmaps., * Lead multiple Application Security and Architecture Risk Assessments.
  • Support customers in strengthening their SSDLC and DevSecOps capabilities.
  • Deliver governance and compliance recommendations aligned with NIS2, DORA and ISO/IEC 27001.
  • Become a trusted advisor for application security and GRC topics.

What you can expect from us:

  • Be taken care of - We offer you 32 vacation days (with the option to make it a whopping 37 days with our Benefit Motivation Plan :-)), meal vouchers, eco-cheques, hospitalization and group insurance, company laptop, mobile phone with unlimited use as well as other benefits. So you do not have to worry about a thing!
  • Never stop learning - We want to be the best in what we do and therefore we provide training, certifications and learning opportunities for every employee so you continuously enrich your skills.
  • Transparency - Communication is key! So we organize company and team meetings on a regular base so everyone is informed properly.
  • Do what you love - Enjoy flexibility with offices in Brussels, Antwerp, Ghent & Rotselaar, a variety of events and lots of activities. We spend more time at work then we do at home, that is why it is important that everyone feels at home. And we make sure you do!
  • Snack to your heart’s desire - At Orange Cyberdefense we keep it healthy. So, you can enjoy an assortment of fresh fruit and healthy snacks. For those with an occasionally sugar dip, there are sweet snacks available.
  • Reputable brand - You will join an internationally, growing company with over 25 years’ experience in the industry. This makes us experts in what we do. We have an international presence and yet local teams to assist our customers.

Requirements

  • OWASP ASVS, OWASP Top 10, OWASP SAMM
  • Threat Modelling (STRIDE)
  • Risk Assessments (FAIR or an equivalent industry-recognized risk assessment framework)
  • Secure Software Development Lifecycle (SSDLC)
  • Application Security Architecture
  • API Security
  • DevSecOps and CI/CD Security
  • Cloud Security (Azure and/or AWS)
  • Identity & Access Management.

Governance, Risk & Compliance

  • NIS2
  • DORA
  • ISO/IEC 27001
  • ISO 27005
  • NIST Cybersecurity Framework
  • NIST SP 800-218 (SSDF)
  • FAIR (preferred)
  • CIS Controls.

Professional Experience

  • Extensive professional experience in Cyber Security.
  • Minimum 4 years in Application Security.
  • Experience leading customer engagements and workshops.
  • Experience producing executive-level reports and recommendations.

Preferred Certifications

  • CISSP
  • CSSLP
  • CRISC
  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • Cloud security certification (Azure or AWS).

Soft Skills

  • Strong analytical and strategic thinking.
  • High learning agility and curiosity.
  • Quality-oriented and systematic problem solver.
  • Collaborative, influential and diplomatic.
  • High integrity and resilience.
  • Strong planning, organisation and self-management.
  • Excellent written and verbal communication.
  • Executive presentation skills.
  • Workshop facilitation.
  • Stakeholder management.
  • Coaching and mentoring mindset.
  • Commercial awareness.

Key Motivators

  • Solving complex security challenges.
  • Continuous professional development.
  • Advising customers and influencing strategic decisions.
  • Working autonomously while collaborating in multidisciplinary teams.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on be.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all