3 hours, 31 minutes ago

Medior Application Security Analyst with a risk-oriented approach (2/2)

SPW Digital manages a portfolio of approximately 800 applications, including nearly 400 web applications, based on various technologies and providers. Poor management of their lifecycle can lead to:

  • an interruption of public services;
  • a compromise of data or application functions;
  • exploitation of vulnerabilities in the code, components, or configurations;
  • an increase in technical debt and obsolescence risks;
  • non-compliance with security requirements, notably NIS2, CyFun, and the SPW Information Security Program;
  • longer and more expensive corrections when security is addressed too late.

To address these risks, the SPW Digital Security Division has a dedicated team for Secure Application Lifecycle Management (SALM). Its main responsibilities are to:

  • determine the criticality of applications and the security controls to apply;
  • carry out risk analyses and monitor the measures decided according to the methodology in place at SPW;
  • define SPW's application security standards and practices;
  • integrate security controls into projects and DevSecOps/CI/CD pipelines: SAST, DAST, SCA, vulnerability scans, and penetration tests;
  • monitor exceptions, residual risks, and recommendations before go-live;
  • ensure monitoring of vulnerabilities, obsolescence, and decommissioning of applications;
  • advise project, development, architecture, and operations teams.

The team works with project managers, developers, architects, operations, functional managers, service centers, DevSecOps and SecOps teams, the SOC, business units, and providers.

The objective is to replace ad hoc and manual controls with a common approach, proportionate to the risks, more automated, and covering the entire application lifecycle.

Expected Behavioral Skills

Analytical mindset: structure a complex situation and distinguish priority risks.
Pragmatism: propose proportionate, realistic, and verifiable measures.
Pedagogy: make security requirements understandable for projects and business units.
Rigor: document assumptions, decisions, evidence, and residual risks.
Autonomy: manage several cases in parallel.
Collaboration: work with developers, architects, DevSecOps, operations, and suppliers.

Mission Description

Main Mission

Take charge of the risk and requirements aspects of SALM files. Support projects from the initial qualification to go-live, ensuring the adequacy of controls with the criticality of the application and traceability of decisions.

All members of the SALM team report hierarchically to the head of the GRC & Application Security sub-division (currently covered ad interim by the head of the security division).

Key Activities

Domain | Key Activities
Qualification and criticality |
Risks and threats |
Architecture and requirements |
Project support |
Review and go-live |
Continuous improvement |

Examples of Deliverables

  • Qualification and criticality sheet.
  • Risk analysis or threat model.
  • Security requirements and control plan.
  • Architecture or design review report.
  • Register of recommendations, exceptions, and residual risks.
  • SALM review prior to go-live.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration