We're looking for a medior application security analyst to assess vulnerabilities and embed security controls across application lifecycles. The work centres on hands-on DevSecOps, CI/CD pipelines and practical guidance for development teams.
What you'll do:
- Assess exploitability, impact, false positives and vulnerability priorities.
- Review application architecture, APIs, authentication, authorisation, encryption and dependencies.
- Integrate and configure SAST, DAST, SCA, secret detection and vulnerability scans in CI/CD.
- Automate security checks and quality gates across development workflows.
- Document findings and guide development teams on remediation.
What you bring:
- Medior experience in application security and secure software development.
- Knowledge of OWASP Top 10, ASVS, SAMM, CWE, CVSS and NIST SSDF.
- Experience with containers, software dependencies and secrets management.
- French at B2 level.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

