Orange Cyberdefense logo
Orange CyberdefensePosted 3 weeks ago

Senior Application Security Consultant

HybridGent, Flanders, Belgium or Wijnegem, Flanders, Belgium

Full TimeSenior LevelEnterprise

Job Summary

Lead Application Security Assessments, Secure Architecture Reviews, and Threat Modelling while advising development teams and architects on secure design. Define secure coding standards, review applications against OWASP ASVS, and support the implementation of SSDLC and DevSecOps practices. Contribute to application security governance, policies, and roadmaps aligned with NIS2, DORA, and ISO/IEC 27001 frameworks. Become a trusted advisor for application security and GRC topics within 12 months. Join Orange Cyberdefense, an international leader with over 25 years of experience, to solve complex security challenges and influence strategic decisions.

Required Qualifications

  • OWASP ASVS
  • OWASP Top 10
  • OWASP SAMM
  • Threat Modelling (STRIDE)
  • Risk Assessments (FAIR or an equivalent industry-recognized risk assessment framework)
  • Secure Software Development Lifecycle (SSDLC)
  • Application Security Architecture
  • API Security
  • DevSecOps and CI/CD Security
  • Cloud Security (Azure and/or AWS)
  • Identity & Access Management
  • NIS2
  • DORA
  • ISO/IEC 27001
  • ISO 27005
  • NIST Cybersecurity Framework
  • NIST SP 800-218 (SSDF)
  • CIS Controls
  • Extensive professional experience in Cyber Security
  • Minimum 4 years in Application Security
  • Experience leading customer engagements and workshops
  • Experience producing executive-level reports and recommendations
  • Strong analytical and strategic thinking
  • High learning agility and curiosity
  • Quality-oriented and systematic problem solver
  • Collaborative, influential and diplomatic
  • High integrity and resilience
  • Strong planning, organisation and self-management
  • Excellent written and verbal communication
  • Executive presentation skills
  • Workshop facilitation
  • Stakeholder management
  • Coaching and mentoring mindset
  • Commercial awareness

Desired Qualifications

  • FAIR
  • CISSP
  • CSSLP
  • CRISC
  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • Cloud security certification (Azure or AWS)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce