> Markdown version of [/jobs/ext/760087-senior-application-security-consultant-threat-modeling](https://www.wearedevelopers.com/jobs/ext/760087-senior-application-security-consultant-threat-modeling). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Consultant (Threat Modeling) - **Company:** NVISO - **Location:** Brussel, Belgium (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Applications Architecture, Business Logic, Software System Penetration Testing, Code Review, Cyber Security, Identity and Access Management, Apache Maven, Team Foundation Server, OAuth, OpenID, Software Architecture, Secure Coding, Software Engineering, Application Enhancement Tool, Software Security, Build Tools, Jenkins, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** June 6, 2026 - **Apply:** https://www.careerjet.be/jobad/be40669b57d1066cbffc2b80f3c3eea247 ## About the Role You have a strong interest in the field of IT security and believe the following to be applicable to you: * You hold citizenship in one of the 32 NATO member states; * A previous experience in penetration testing, threat modeling or related projects; * Knowledge of development frameworks, application architectures and authentication systems (OpenID, oAUTH, ...) * a deep understanding of development practices, preferably with some hands-on experience in coding yourself; * Experience using build tools (e.g. Jenkins, TFS, maven,...); * Strong knowledge of secure development lifecycle (SDLC) and practical implementation, requirements gathering and test planning, software architecture and secure coding; * Hand-on experience with tooling to secure the development pipeline (SAST, DAST, ...); * The ability to credibly talk to (top)-management in a convincing manner on security in software development; * Experience providing software architecture security guidance, including developing application threat models and methodically protecting against business logic and design flaws that could introduce security vulnerabilities. * Positive, team and mission-oriented attitude; * Strong interpersonal and verbal/written communications skills that enable the ability to work effectively in a collaborative team environment; * Excellent English communications skills, both verbal and written; Dutch and / or French is a plus; * You are ambitious and want to help clients; * You are willing to learn and become a better version of yourself, everyday; * Candidates must recognize and deal appropriately with confidential and sensitive information. ## Description As an Senior Application Security Consultant, you assist clients in creating a more secure development process, you actively coach developers in secure coding and help implement security concepts into the development lifecycle. Using your knowledge of security, you will help creating more secure applications. Projects you will work on will consist of: * Implementing security controls inside of the development process, in order to increase the overall maturity of the software development lifecycle's at our client's. * Presenting your roadmap to increase the maturity of our client's software development practice; * Providing hands-on training on secure development concepts and secure coding to developers of various coding languages; * Scope, Execute & Plan assessment type of projects including * Threat modeling * Architecture Reviews (software based) * Maturity Assessments (SAMM, DSOMM,...) * Securing the development pipeline * Source code reviews (if interested), Please be aware that the creation and submission of application documents (e.g. CV, cover letter, case studies, etc.) using AI-powered tools is only permitted to a limited extent. Our expectations: * Application documents must authentically reflect your own qualifications, personality, and motivation. * The use of AI for supportive purposes (e.g. spell-checking, improving wording) is acceptable. * Fully generated application documents created by AI without personal adaptation or review are not permitted. * Under no circumstances may NVISO information, data, or documents be uploaded to or processed by external AI tools. We reserve the right to exclude applications from the selection and interview process that are clearly created primarily or exclusively by AI and show no recognizable personal input. The purpose of this policy is to ensure a fair and transparent recruitment process and to obtain an authentic impression of our applicants. NVISO We are a young team of cyber security professionals who decided to do things differently. With innovation rooted in our foundations, we offer services that are up against the modern adversary and that help you Prevent, Detect & Respond to cyber attacks. Curious for more? Say hello and meet the team! ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [The Netherlands – Europe’s powerhouse for software development?](https://www.wearedevelopers.com/magazine/31-the-netherlands-europe-s-powerhouse-for-software-development) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)