3 hours, 32 minutes ago

Senior Application Security Analyst – technical orientation and DevSecOps

The SPW Digital manages a portfolio of approximately 800 applications, including nearly 400 web applications, relying on various technologies and service providers. Poor management of their lifecycle can lead to:

  • an interruption of public services;
  • a compromise of data or application functions;
  • exploitation of vulnerabilities in code, components, or configurations;
  • an increase in technical debt and obsolescence risks;
  • non-compliance with security requirements, notably NIS2, CyFun, and the SPW Information Security Program;
  • longer and more costly fixes when security is addressed too late.

To address these risks, the SPW Digital Security Division has a dedicated team for Secure Application Lifecycle Management (SALM). Its main responsibilities are to:

  • determine the criticality of applications and the security controls to apply;
  • conduct risk analyses and monitor the implementation of decided measures according to SPW's methodology;
  • define SPW's application security standards and best practices;
  • integrate security controls into projects and DevSecOps/CI/CD pipelines: SAST, DAST, SCA, vulnerability scans, and penetration tests;
  • monitor exceptions, residual risks, and recommendations before production rollout;
  • track vulnerabilities, obsolescence, and application decommissioning;
  • advise project, development, architecture, and operations teams.

The team works with project managers, developers, architects, operations, functional managers, service centers, DevSecOps and SecOps teams, the SOC, business units, and service providers.

The goal is to replace ad-hoc and manual controls with a common approach, proportionate to risks, more automated, and covering the entire application lifecycle.

Expected behavioral skills

Technical rigor: reproduce, qualify, and document findings.
Pragmatism: prioritize genuinely exploitable vulnerabilities and propose realistic fixes.
Pedagogy: explain vulnerabilities and remediations to developers.
Curiosity: keep up to date with attack techniques and tools.
Autonomy: configure and operate controls while escalating complex cases.
Collaboration: work with projects, developers, DevSecOps, SecOps, and service providers.

Mission description

Main mission

Take charge of technical controls within SALM files and their integration into development practices. Use tool results, qualify vulnerabilities, support their remediation, and contribute to the automation of controls in CI/CD pipelines.

The profile remains that of a SALM analyst able to understand the functional context and risk analysis of a case file; with a focus on technical depth, tooling, and supporting developers.

All SALM team members report hierarchically to the head of the GRC & application security sub-division (currently held ad interim by the head of the security division).

Key activities

Domain
Key activities

Automated controls

DevSecOps and CI/CD

Vulnerability qualification

Testing and remediation

Technical support

Example deliverables

  • Technical control plans.
  • SAST, DAST, SCA, and secrets integration configurations and procedures.
  • Qualification and prioritization reports for application vulnerabilities.
  • Penetration test tracking and remediation plans.
  • Quality gate criteria and exception rules.
  • Remediation guides and technical recommendations.
  • Coverage, criticality, and remediation time indicators.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration