About the job Senior Application Security Analyst
Mission Overview:
Keystone Solutions is seeking a Senior Application Security Analyst with a technical orientation and DevSecOps expertise for a consultancy mission at a client site. The client manages a portfolio of approximately 800 applications, including nearly 400 web applications, utilizing various technologies and providers. A lack of mastery over their lifecycle can lead to significant risks, including service interruptions, data compromises, and increased technical debt.
Key Responsibilities:
As a consultant representing Keystone Solutions, you will be responsible for:
- Managing technical controls for Secure Application Lifecycle Management (SALM) and integrating them into development practices.
- Utilizing results from tools to qualify vulnerabilities, assist in their remediation, and contribute to the automation of controls in CI/CD pipelines.
- Determining application criticality and applicable security controls.
- Conducting risk analyses and monitoring measures according to established methodologies.
- Defining application security standards and practices.
- Integrating security controls into DevSecOps/CI/CD projects, including SAST, DAST, SCA, vulnerability scans, and penetration testing.
- Monitoring exceptions, residual risks, and recommendations prior to production deployment.
- Advising project, development, architecture, and operations teams.
Expected Behavioral Skills:
- Technical rigor: reproduce, qualify, and document findings.
- Pragmatism: prioritize exploitable vulnerabilities and propose realistic corrections.
- Pedagogy: explain vulnerabilities and remediations to developers.
- Curiosity: keep knowledge updated on attack techniques and tools.
- Autonomy: configure and operate controls while escalating complex cases.
- Collaboration: work with projects, developers, DevSecOps, SecOps, and providers.
Why Join Keystone Solutions?
As a consultant at Keystone Solutions, you will experience:
- Consultancy Nature: Focus on on-site work and embodying the consultant identity.
- Dynamic Projects: Engage with diverse challenges across various client environments.
- Turbo-Charged Learning: Benefit from professional development and broad learning experiences.
- Skyrocketing Ambition: Enjoy a commitment to career growth within our framework.
- Values: Being a "K-Stone" means bringing our core values to every engagement.
If you are ready to tackle technical and strategic challenges in a dynamic consultancy environment, apply today at Keystone Solutions Career Portal.
Duration: 04/01/2027 - 03/01/2028 12 months • (full time)
Skills required:
- Analyse et qualification des vulnérabilités : exploitabilité, impact, faux positifs et priorisation
- (mandatory) - Level: T3 - Senior - Most recent: Any time
- Architecture et sécurité applicative : flux, authentification, autorisation, chiffrement, API et dépendances
- (mandatory) - Level: T2 - Confirmed - Most recent: Any time
- Chaînes CI/CD et pratiques DevSecOps : intégration, paramétrage, automatisation et quality gates
- (mandatory) - Level: T3 - Senior - Most recent: Any time
- Outils de sécurité applicative : SAST, DAST, SCA, détection de secrets et scans de vulnérabilités
- (mandatory) - Level: T2 - Confirmed - Most recent: Any time
- Référentiels techniques : OWASP Top 10, ASVS, SAMM, CWE, CVSS et NIST SSDF
- (mandatory) - Level: T2 - Confirmed - Most recent: Any time
- Restitution technique, documentation et accompagnement des équipes de développement
- (mandatory) - Level: T2 - Confirmed - Most recent: Any time
- Sécurité du développement, API, dépendances logicielles, conteneurs et gestion des secrets
- (mandatory) - Level: T2 - Confirmed - Most recent: Any time
Language requirements:
French
(mandatory)
Level Proficiency (C2)