Application Security Consultant
Already experienced in the world of cyber security? New to it all, but genuinely interested? Well, at NVISO we might be looking for you and we’d love to have a chat!
Who are we?
It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents.
So what does this mean in practice? What do we actually do?
- Defining the overall cyber security strategy (e.g. building out and delivering an awareness program)
- Offensive security services such as red teaming and penetration testing
- Building and securing cloud-native architectures
- Emergency support such as incident response / forensics when organizations are breached
- Managed services such as Managed Detection & Response and Vulnerability Management
- Highly tailored / niche cyber security work in for example ICS environments
The list is not exhaustive and our very own NVISO Labs is continuously investigating new possible services or new ways to tackle the rapidly changing problems in cyber security!
As a proudly European company, we currently have offices in Belgium (Brussels), Germany (Frankfurt and Munich) and Greece (Athens). Technically, we are present in many more towns and cities, as our people often work from home too.
All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS!
As an Application Security Consultant, you assist clients in creating a more secure development process, you actively coach developers in secure coding and help implement security concepts into the development lifecycle. Using your knowledge of security, you will help creating more secure applications.
Projects you will work on will consist of:
- Implementing security controls inside of the development process, in order to increase the overall maturity of the software development lifecycle's at our client's.
- Presenting your roadmap to increase the maturity of our client's software development practice;
- Providing hands-on training on secure development concepts and secure coding to developers of various coding languages;
Scope, Execute & Plan assessment type of projects including
- Threat modeling
- Architecture Reviews (software based)
- Maturity Assessments (SAMM, DSOMM,...)
- Securing the development pipeline
- Source code reviews (if interested)
- Penetration testing (if interested)
You have a strong interest in the field of IT security and believe the following to be applicable to you:
- Knowledge of development frameworks, application architectures and authentication systems (OpenID, oAUTH, ...)
- a deep understanding of development practices, preferably with some hands-on experience in coding yourself;
- Experience using build tools (e.g. Jenkins, TFS, maven,...)
- Strong knowledge of secure development lifecycle (SDLC) and practical implementation, requirements gathering and test planning, software architecture and secure coding.
- Hand-on experience with tooling to secure the development pipeline (SAST, DAST, ...)
- The ability to credibly talk to (top)-management in a convincing manner on security in software development.
- Experience providing software architecture security guidance, including developing application threat models and methodically protecting against business logic and design flaws that could introduce security vulnerabilities.
- Positive, team and mission-oriented attitude;
- Strong interpersonal and verbal/written communications skills that enable the ability to work effectively in a collaborative team environment;
- Excellent English communications skills, both verbal and written; Dutch and / or French is a plus;
- You are ambitious and want to help clients;
- You are willing to learn and become a better version of yourself, everyday;
- Team player who works well under pressure;
- Candidates must recognize and deal appropriately with confidential and sensitive information;
- Ability to obtain a BE/EU/NATO clearance.
At NVISO, we care. We are committed to offering you a highly competitive remuneration package including financial and non-financial components:
- Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (BlackHat, BruCON, OWASP, etc) and all of our technical staff can acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc)
- An entrepreneurial and agile company, where you will be stimulated and supported in driving new initiatives (either through internal innovation or by improving our service offering), without losing sight of having fun!
- Regular team-building and fun events with legendary off-site events once a year. The location of the next team building is one of the most closely guarded secrets at NVISO… We can however disclose that we’ve visited Lisbon, Dubai and Malta over the past few years
- Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team, whose role is to ensure your well-being and helps you grow in your career!
- Flexible working hours and home office possibilities
- Flex Reward Plan
- 32 holidays
IF YOU'RE INTERESTED, PLEASE SEND US YOUR APPLICATION!
WE'RE LOOKING FORWARD TO MEET YOU!