Rhox

IT Architect Application Security (Medior)

Closes on 02/10/2026
Brussels
Hybrid, 60% on site
Starts on 01/07/2027
Remuneration: 2.850 - 3.250 EUR/mo gross+ extralegal advantages ·Freelance also possible

Apply for this role

or apply with email & CV

Drag & drop your CV here, or click to browse

PDF, DOC, DOCX, or TXT (max 10MB)

By applying, you agree to our Terms of Service and Privacy Policy.

A federal public service is establishing a secure development practice to apply NIS2 and Belgian CyFun requirements in everyday software delivery. You will lead the programme’s foundations, combining security architecture reviews with DevSecOps and security tooling across CI/CD pipelines.

The mission

The work responds to NIS2, in force since October 2024, and the Belgian CyFun framework. Control PR.IP-2 calls for critical systems and components to be developed across the full design cycle, with security-control functions and design and implementation details for security-related interfaces documented. The goal is to integrate secure development into daily procedures, rather than treat compliance as a checklist.

You will work with existing development teams to introduce continuous security practices, using OWASP’s Software Assurance Maturity Model (SAMM) as a reference. You will map changes to development processes, document how teams can apply them, review technical designs, and advise on hardware, software and working methods. The programme also needs application security dashboards, repeatable improvement routines, a standard directive for internal projects and suppliers, and a security matrix for assessing external projects. As project lead, you will plan the work, report progress, document the chosen methods, and may develop and deliver training.

Your responsibilities

  • Review security architectures and advise on designs, infrastructure and development methods.
  • Map process changes and document clear guidance for secure development.
  • Embed SCA, SAST and DAST tools in CI/CD pipelines and promote continuous security.
  • Build application security dashboards and define routines for ongoing improvement.
  • Produce a standard directive for internal projects and external suppliers.
  • Create a security matrix to assess externally delivered projects.
  • Lead planning, progress reporting, documentation and secure-development training.

Your profile

Essential skills

  • Background as an application architect with strong security knowledge, or as a security architect with strong application-development knowledge.
  • Demonstrated experience delivering similar initiatives in an environment of comparable scale.
  • At least 3 years of experience reviewing security architectures.
  • At least 3 years of experience implementing SCA, SAST and DAST tools in CI/CD pipelines.
  • At least 3 years of experience in DevSecOps.
  • Knowledge of project management and Agile or Lean Software Development.
  • Knowledge of security frameworks, including CyFun and SAMM.
  • Knowledge of quality assurance and testing, including test-driven development.
  • Ability to map development-process changes and document them clearly.
  • Ability to explain and promote security concepts to technical and non-technical colleagues.
  • Planning, organisational, leadership and adjustment skills, with a results focus and sense of responsibility.
  • Negotiation and relationship-management skills, including the ability to build, lead and supervise a team.

Preferred skills

  • Familiarity with OWASP SAMM and CyFun.
  • Knowledge of ITIL, Java, Angular, Oracle, Web Services or Service Bus technologies.

Languages

  • Dutch: B2
  • French: B2
  • English: level not specified

Working context

  • This is the launch of a secure development programme, so you will help establish its working practices.
  • You will support existing development teams and provide guidance covering internal projects and external suppliers.
  • The approach centres on SecDevOps, continuous security practices, OWASP SAMM and Agile or Lean methods.
  • Project follow-up includes planning and progress meetings, with the selected methods and their implementation documented.

What's next?

The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.

We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.

It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.