We're looking for a medior application security risk analyst to assess application risks and guide projects from initial qualification through production. You'll shape proportionate security requirements across the application lifecycle, combining threat modelling with practical risk management for varied technologies and suppliers.
What you'll do
- Assess application criticality and select proportionate security controls.
- Analyse risks and threats, prioritising treatment measures and residual exposure.
- Review architecture, designs and data flows against security requirements.
- Advise project stakeholders and suppliers on practical security requirements.
- Track recommendations, exceptions, evidence, decisions and residual risks.
- Prepare pre-production security advice and contribute to standards and checklists.
What you bring
- Experience in application risk analysis and translating findings into security requirements.
- Knowledge of threat modelling methods, including OWASP, STRIDE and ISO 27005.
- Familiarity with NIST SSDF, NIS2 and CyFun.
- Clear communication with project leads, architects, developers, business teams and suppliers.
- Rigorous documentation and decision traceability using tracking or GRC tools.
- Analytical judgement to identify priorities and manage several cases independently.
- A pragmatic approach to realistic, proportionate and verifiable security measures.
- French (B2).
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

