Description
Description
We are looking for a motivated Functional Analyst with a passion for new technologies and a strong sensitivity to application security. You will join a dynamic team dedicated to addressing application security issues for solutions we develop on behalf of our clients. You will collaborate closely with developers, architects, and cybersecurity experts.
As a Functional Analyst Security, you will be responsible for functional analysis of business needs, focusing on security requirements at every stage of the application development lifecycle.
- You will draft functional and technical specifications related to the implementation of application security.
- You will participate in the definition and implementation of the Security Development Lifecycle (SDL) based on NIST best practices.
- You will collaborate with development teams to integrate security controls throughout the application lifecycle.
- You will ensure compliance with security standards and applicable regulations.
- You will actively monitor new vulnerabilities, techniques, and security methodologies.
- You will contribute to raising awareness among internal teams about security issues.
- You will assist in organizing application security testing.
- You will monitor emerging threats related to software vulnerabilities and identify new risks to applications.
- You will analyze vulnerability reports from both external sources (e.g., vulnerability databases) and internal sources.
Profile
With a degree in computer science, you are a professional with solid experience in functional analysis and writing technical specifications. You also have a strong technical knowledge and keen interest in the security of information systems and applications. You are eager to invest in an ever-evolving environment where security is a critical challenge.
- You have a good understanding of software development processes (e.g., Agile, DevOps).
- You are familiar with security best practices (e.g.,NIST, OWASP, ASVS).
- You can understand and analyze complex technical issues.
- You can collaborate with multidisciplinary teams (developers, architects, security experts).
- You possess strong written and verbal communication skills, including the ability to simplify technical issues for various audiences.
- You are familiar with the concept of Software Bills of Materials (e.g., CycloneDX, SPDX).
- You have knowledge of tools for security vulnerability analysis (e.g., Dependency-Track).
- You understand the different versions of the CVSS scoring system and EPSS.
- You are familiar with the principles of the Security Development Lifecycle (SDL).
- You are proficient with application lifecycle management tools (e.g., Jira, Jenkins, GIT).
- You have a basic understanding of cryptography, authentication, and access control.
- You are familiar with security frameworks (e.g., NIST, ISO 27001, ASVS).
- You understand secure software architectures and threat modeling techniques.
- You have experience with vulnerability analysis tools (e.g.,SAST,DAST).
Proficiency in one of the two national languages, along with a good understanding of the second, is essential. You also possess strong writing skills in English.