3 hours, 30 minutes ago

Expert Lead Application Security

The SPW Digital manages an asset of approximately 800 applications, including nearly 400 web applications, relying on various technologies and providers. Poor management of their lifecycle can lead to:

  • interruption of public services;
  • compromise of data or application functions;
  • exploitation of vulnerabilities in code, components, or configurations;
  • increased technical debt and risks of obsolescence;
  • non-compliance with security requirements, including NIS2, CyFun, and the SPW Information Security Program;
  • longer and more expensive fixes when security is addressed too late.

To address these risks, the SPW Digital Security Department has a dedicated team for Secure Application Lifecycle Management (SALM). Its main responsibilities are to:

  • determine the criticality of applications and the security controls to apply;
  • carry out risk analyses and monitor decided measures according to the methodology in place at SPW;
  • define SPW's application security standards and practices;
  • integrate security controls into projects and DevSecOps/CI/CD pipelines: SAST, DAST, SCA, vulnerability scans, and penetration tests;
  • monitor exceptions, residual risks, and recommendations before production deployment;
  • ensure the follow-up of vulnerabilities, obsolescence, and decommissioning of applications;
  • advise project, development, architecture, and operations teams.

The team works with project managers, developers, architects, operations, functional managers, service centers, DevSecOps and SecOps teams, the SOC, business units, and providers.

The objective is to replace ad hoc and manual controls with a common approach, proportionate to the risks, more automated, and covering the entire application lifecycle.

Expected Behavioral Competencies

Leadership: frame, support, and empower the team.
Sense of responsibility: take charge of tasks and report back.
Technical credibility: handle complex cases and support decisions.
Prioritization: make decisions based on risks and capacity.
High standards and kindness: ensure quality and help the team improve.
Pragmatism: propose applicable measures.
Communication: adapt messages to stakeholders.

Autonomy and synthesis: monitor commitments and report on arbitrations.

Main Mission

Reference for expertise in application security regarding risks, project support, technical aspects, and DevSecOps.

Take charge of the risk and requirements aspects of SALM files. Support projects from initial qualification to production deployment, ensuring that controls are appropriate to the application's criticality and that decisions are traceable.

Take charge of the technical controls in SALM files and their integration into development practices. Utilize tool results, qualify vulnerabilities, support their remediation, and contribute to the automation of controls in CI/CD pipelines.

Lead on the SALM topic: monitor operational activities, compliance with methods and deadlines. Evolve the SALM topic and report via tracking tables and development plans.

All members of the SALM team report hierarchically to the head of the GRC & application security sub-department (temporarily held by the head of the security department).

Key Activities

| Domain | Key Activities | |------------------------------|----------------------------------| | Thematic lead | | | Operational expertise | | | Methodological framework | | | Application vulnerability management | | | Projects and DevSecOps | | | Collaboration and reporting | |

Example Deliverables

  • Workload plan, dashboard, and file tracking.
  • Risk analyses and security advisories.
  • Requirements and control plans.
  • SAST, DAST, SCA reports and penetration tests.
  • SALM standards and templates.
  • Dashboard and arbitration support materials.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration