An application security function supports software solutions developed for external organisations and is integrating security into functional analysis and delivery processes. As a Junior Functional Analyst focused on Security, you will work with functional analysts, developers, architects and cybersecurity specialists to define requirements, support secure development lifecycle procedures, and coordinate application security testing with SAST, DAST and SCA tooling.
The mission
The team works across the application development lifecycle, from early business and security requirements through testing, vulnerability review and compliance follow-up. Its reference landscape includes OWASP, NIST, NIS2, ISO 27001 and C2M2, with controls translated into procedures that development teams can apply. This connects application security testing with security management and regulatory expectations, instead of treating vulnerability findings as isolated technical reports. The role provides practical exposure to both software delivery and the governance required to document security decisions.
With support from experienced colleagues, you will turn business needs and security expectations into functional and technical specifications. You will work with delivery teams on controls for authentication, access control, encryption and secure development, then help verify that agreed controls and testing evidence are available. You will review findings from vulnerability databases, assessment tools and internal or external reports, document risks and explain them to technical and non-technical stakeholders. The scope is suited to a recent graduate or someone with initial experience in functional analysis, software development, IT or cybersecurity.
Your responsibilities
- Translate business, security and regulatory needs into clear functional and technical requirements that teams can implement.
- Embed secure development lifecycle procedures and NIST-based practices into application delivery activities.
- Coordinate and follow up application security testing using SAST, DAST and SCA tooling, including Veracode where applicable.
- Assess vulnerability reports, identify application risks, and support prioritisation and remediation follow-up.
- Produce security documentation and compliance evidence that makes findings understandable to technical and non-technical stakeholders.
- Contribute to security awareness activities and keep guidance current as vulnerabilities and application security practices evolve.
Your profile
Essential skills
- Apply functional analysis to break down technical and business topics into clear requirements, specifications and documentation.
- Understand software development processes such as Agile or DevOps and have familiarity with tools such as Jira, Git or Jenkins.
- Bring introductory knowledge of application security principles, including OWASP, OAuth, OpenID, authentication, access control, encryption and software vulnerabilities.
- Understand or be ready to work with NIS2, NIST, ISO 27001 and C2M2 security management frameworks, plus secure development lifecycle procedures.
- Have familiarity with SAST, DAST and SCA concepts and the purpose of application security testing and vulnerability management.
- Communicate clearly and collaborate with developers, architects, functional analysts and cybersecurity specialists.
- Show an analytical, organised and detail-oriented way of working, with the confidence to ask questions and learn from experienced colleagues.
Education
- A degree in computer science, cybersecurity, information systems or a related field, or equivalent knowledge gained through relevant training or practical experience.