3 hours, 33 minutes ago

Medior Application Security Analyst – technical orientation and DevSecOps

SPW Digital manages a portfolio of approximately 800 applications, including nearly 400 web applications, based on various technologies and providers. Poor management of their lifecycle can lead to:

  • interruption of public services;
  • compromise of data or application functions;
  • exploitation of vulnerabilities in the code, components, or configurations;
  • increase in technical debt and risks of obsolescence;
  • non-compliance with security requirements, including NIS2, CyFun, and the SPW Information Security Program;
  • longer and more expensive fixes when security is addressed too late.

To address these risks, the SPW Digital Security Division has a team dedicated to Secure Application Lifecycle Management (SALM). Its main responsibilities are to:

  • determine the criticality of applications and the security controls to apply;
  • conduct risk analyses and monitor the measures decided upon according to the methodology in place at SPW;
  • define SPW's standards and practices for application security;
  • integrate security controls into projects and DevSecOps/CI/CD pipelines: SAST, DAST, SCA, vulnerability scans, and penetration tests;
  • monitor exemptions, residual risks, and recommendations before going into production;
  • ensure the monitoring of vulnerabilities, obsolescence, and decommissioning of applications;
  • advise project, development, architecture, and operations teams.

The team works with project managers, developers, architects, operations, functional managers, service centers, DevSecOps and SecOps teams, the SOC, business units, and providers.

The objective is to replace ad hoc and manual controls with a common approach, proportionate to the risks, more automated, and covering the entire application lifecycle.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration