Senior Application Security Consultant
Orange Cyberdefense · Evere, Brussels, Belgium
IT Services and IT Consulting · 1,001-5,000 employees
About the role
Lead application security assessments, threat modelling, and architectural risk reviews while supporting the implementation of DevSecOps practices. Advise stakeholders on secure design and contribute to the development of application security governance, policies, and roadmaps.
What they look for
Requirements
Requires at least 4 years of professional experience in application security and deep knowledge of frameworks like OWASP ASVS, NIS2, and ISO/IEC 27001. Candidates should possess strong analytical skills and the ability to translate technical risks into business-oriented recommendations.
Benefits
Full description
Position summary
As a Senior Application Security Consultant, you help organisations integrate security throughout the Secure Software Development Lifecycle (SSDLC) while ensuring alignment with governance, risk and compliance frameworks such as NIS2, DORA, ISO/IEC 27001 and OWASP ASVS. You combine deep application security expertise with strong advisory capabilities and can translate technical risks into business-oriented recommendations.
Key Responsibilities
- Lead Application Security Assessments and Secure Architecture Reviews.
- Facilitate Threat Modelling and Architectural Risk Assessments (ARA).
- Support the implementation and continuous improvement of SSDLC and DevSecOps practices.
- Define and review secure coding standards and security requirements.
- Assess applications against OWASP ASVS and other recognised standards.
- Advise development teams, architects and business stakeholders on secure design.
- Contribute to application security governance, policies and roadmaps.
Required Technical Expertise
- OWASP ASVS, OWASP Top 10, OWASP SAMM
- Threat Modelling (STRIDE)
- Risk Assessments (FAIR or an equivalent industry-recognized risk assessment framework)
- Secure Software Development Lifecycle (SSDLC)
- Application Security Architecture
- API Security
- DevSecOps and CI/CD Security
- Cloud Security (Azure and/or AWS)
- Identity & Access Management.
Governance, Risk & Compliance
- NIS2
- DORA
- ISO/IEC 27001
- ISO 27005
- NIST Cybersecurity Framework
- NIST SP 800-218 (SSDF)
- FAIR (preferred)
- CIS Controls.
Professional Experience
- Extensive professional experience in Cyber Security.
- Minimum 4 years in Application Security.
- Experience leading customer engagements and workshops.
- Experience producing executive-level reports and recommendations.
Preferred Certifications
- CISSP
- CSSLP
- CRISC
- ISO/IEC 27001 Lead Implementer or Lead Auditor
- Cloud security certification (Azure or AWS).
Soft Skills
- Strong analytical and strategic thinking.
- High learning agility and curiosity.
- Quality-oriented and systematic problem solver.
- Collaborative, influential and diplomatic.
- High integrity and resilience.
- Strong planning, organisation and self-management.
- Excellent written and verbal communication.
- Executive presentation skills.
- Workshop facilitation.
- Stakeholder management.
- Coaching and mentoring mindset.
- Commercial awareness.
Key Motivators
- Solving complex security challenges.
- Continuous professional development.
- Advising customers and influencing strategic decisions.
- Working autonomously while collaborating in multidisciplinary teams.
Success Criteria (first 12 months)
- Lead multiple Application Security and Architecture Risk Assessments.
- Support customers in strengthening their SSDLC and DevSecOps capabilities.
- Deliver governance and compliance recommendations aligned with NIS2, DORA and ISO/IEC 27001.
- Become a trusted advisor for application security and GRC topics.
What you can expect from us:
- Be taken care of - We offer you 32 vacation days (with the option to make it a whopping 37 days with our Benefit Motivation Plan :-)), meal vouchers, eco-cheques, hospitalization and group insurance, company laptop, mobile phone with unlimited use as well as other benefits. So you do not have to worry about a thing!
- Never stop learning - We want to be the best in what we do and therefore we provide training, certifications and learning opportunities for every employee so you continuously enrich your skills.
- Transparency - Communication is key! So we organize company and team meetings on a regular base so everyone is informed properly.
- Do what you love - Enjoy flexibility with offices in Brussels, Antwerp, Ghent & Rotselaar, a variety of events and lots of activities. We spend more time at work then we do at home, that is why it is important that everyone feels at home. And we make sure you do!
- Snack to your heart's desire - At Orange Cyberdefense we keep it healthy. So, you can enjoy an assortment of fresh fruit and healthy snacks. For those with an occasionally sugar dip, there are sweet snacks available.
- Reputable brand - You will join an internationally, growing company with over 25 years’ experience in the industry. This makes us experts in what we do. We have an international presence and yet local teams to assist our customers.
- The good life ...
🔥 Are you interested? Then jump in!
Orange Cyberdefense are equal opportunities employer, welcoming applications from all people, regardless of their race, sex, disability, age, religion, or sexual orientation.