We're looking for a medior application security risk analyst to guide project security from initial application qualification through production. You'll assess criticality, define proportionate controls and use threat modelling and recognised security frameworks to keep risk decisions grounded.
What you'll do
- Gather application information, assess criticality and choose proportionate security controls.
- Analyse application risks, model threat scenarios and prioritise treatment measures.
- Review architectures, designs and data flows against security requirements.
- Advise project leads, architects, developers, business teams and suppliers.
- Track recommendations, exceptions, evidence and residual risks across project stages.
- Prepare security opinions to support production decisions.
What you bring
- Medior experience in application security risk assessment and project support.
- Experience handling security requirements, reviews, exceptions, residual risks and security opinions.
- Ability to identify threat scenarios and define clear, verifiable treatment measures.
- Knowledge of OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2 and CyFun.
- Ability to explain security risks clearly to project leads, architects, developers, business teams and suppliers.
- Rigorous documentation and decision traceability using tracking or GRC tools.
- Ability to contribute to security standards, checklists, templates and lessons learned.
- French at B2 level.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

