We're looking for a senior Application Security Lead to guide secure application lifecycle management from risk assessment through production. You'll combine technical reviews, proportionate controls and team leadership to embed repeatable DevSecOps checks across applications built with varied technologies.
What you'll do:
- Lead application security work, allocate team workload and track deadlines and blockers.
- Assess application risks, match controls to criticality and document decisions.
- Guide projects from initial assessment to production, including critical applications.
- Review architecture, design and code; assess SAST, DAST, SCA and penetration tests.
- Prioritise vulnerabilities and residual risks; follow remediation, obsolescence and decommissioning.
- Integrate security checks into CI/CD; maintain standards, checklists and progress reporting.
What you bring:
- Senior-level expertise in application security and the secure software development lifecycle (SSDLC).
- Strong knowledge of application risk analysis, security requirements, reviews and vulnerability management.
- Practical DevSecOps knowledge, including SAST, DAST, SCA, CI/CD, secrets management and penetration testing.
- Knowledge of OWASP, ISO 27001/27005, NIST SSDF, NIS2, CyFun and ANSSI.
- Ability to prioritise the backlog by risk and criticality, balancing workload and capacity.
- Leadership in coaching colleagues, reviewing high-impact deliverables and maintaining quality.
- Experience defining processes, standards, models, indicators and knowledge-transfer practices.
- Clear communication with project, IT, business, supplier and management stakeholders.
- Ability to turn findings into practical recommendations and traceable security decisions.
- Able to prepare workload plans, dashboards and concise reports for prioritisation and arbitration.
- French at B2 level.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

