We're looking for a senior application security risk analyst to guide projects through security requirements, risk reviews and approval before production. You'll assess application criticality, carry out threat modelling and recommend controls proportionate to risk, using recognised security frameworks. You'll work from initial qualification through production, helping technical and business stakeholders understand security decisions and residual risks.
What you'll do
- Assess application criticality and select proportionate security controls.
- Analyse application risks, model threat scenarios and prioritise treatment measures.
- Review architecture, designs and data flows; define and verify application security requirements.
- Advise project leads, architects, developers, business stakeholders and suppliers in clear language.
- Track recommendations, exceptions, evidence and residual risks through production approval.
- Prepare security opinions and contribute to standards, checklists and lessons learned.
What you bring
- Senior-level experience in application security risk analysis and project security reviews.
- Experience defining security requirements, assessing threats and selecting proportionate risk treatments.
- Clear communication with project leads, architects, developers, business stakeholders and suppliers.
- Ability to document decisions, evidence, exceptions and residual risks, maintaining traceability with tracking or GRC tools.
- Knowledge of OWASP, STRIDE, ISO 27005, NIST SSDF, NIS2 and CyFun.
- French, B2.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

