3 hours, 30 minutes ago

Senior Application Security Analyst focused on risk

SPW Digital manages an inventory of approximately 800 applications, including nearly 400 web applications, based on a variety of technologies and service providers. Poor management of their lifecycle can lead to:

  • an interruption of public services;
  • a compromise of data or application functions;
  • the exploitation of vulnerabilities in the code, components, or configurations;
  • an increase in technical debt and risks of obsolescence;
  • non-compliance with security requirements, notably NIS2, CyFun, and the SPW Information Security Program;
  • longer and more expensive fixes when security is addressed too late.

To address these risks, the SPW Digital Security Division has a team dedicated to Secure Application Lifecycle Management (SALM). Its main responsibilities are to:

  • determine the criticality of applications and the security controls to apply;
  • conduct risk analyses and monitor the measures decided upon according to the methodology in place at SPW;
  • define SPW’s application security standards and practices;
  • integrate security controls into projects and DevSecOps/CI/CD pipelines: SAST, DAST, SCA, vulnerability scans, and penetration testing;
  • track exceptions, residual risks, and recommendations before go-live;
  • ensure the monitoring of vulnerabilities, obsolescence, and decommissioning of applications;
  • advise project, development, architecture, and operations teams.

The team works with project managers, developers, architects, operations, functional managers, service centers, DevSecOps and SecOps teams, the SOC, business units, and service providers.

The objective is to replace ad hoc and manual controls with a common approach, proportionate to the risks, more automated, and covering the entire application lifecycle.

Expected Behavioral Skills

Analytical mindset: structure a complex situation and identify priority risks.
Pragmatism: propose proportionate, realistic, and verifiable measures.
Pedagogy: make security requirements understandable to projects and business units.
Rigor: document assumptions, decisions, evidence, and residual risks.
Autonomy: manage several cases in parallel.
Collaboration: work with developers, architects, DevSecOps, operations, and suppliers.

Mission Description

Main mission

Take charge of the risk and requirements aspects of SALM cases. Support projects from initial qualification to go-live, ensuring that controls are appropriate to the application’s criticality and that decisions are traceable.

All members of the SALM team report hierarchically to the head of the GRC & Application Security sub-division (currently acting position held by the head of the security division).

Key Activities

| Domain | Key Activities | |-----------------------------|---------------| | Qualification and criticality| | | Risks and threats | | | Architecture and requirements| | | Project support | | | Review and go-live | | | Continuous improvement | |

Example Deliverables

  • Qualification and criticality sheet.
  • Risk analysis or threat model.
  • Security requirements and control plan.
  • Architecture or design review report.
  • Register of recommendations, exceptions, and residual risks.
  • SALM opinion before go-live.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration