7 hours, 32 minutes ago

Application Architect with a focus on security

NDLS

Applications Architect with a focus on Security

Mission context:

The security aspect in the development of new software is an important component in the new NIS2 regulation that has been in effect since October 2024. Within the Belgian CyFun framework—being developed by the Belgian Center for Cybersecurity—it serves as a number of checkpoints to ensure that companies and government institutions are compliant with the regulations.

PR.IP-2: The development process for critical systems and system components must cover the full design cycle and provide a description of the functional properties of security controls, as well as design and implementation information for security-relevant system interfaces.

Within the FPS Justice, we want this regulation to be more than a checklist of procedures and checkmarks, and we want to incorporate secure development into our daily procedures and way of working. To this end, we are launching a project on secure development, of which this is the starting point.

The profile we are looking for is an experienced application architect with thorough knowledge of security or a security architect with thorough knowledge of application development. They have experience with implementing and analyzing the necessary changes in a development process and can also map and document these in a comprehensive way. The profile can communicate with both highly technical profiles and those with a less technical background, and is able to convincingly promote the necessary concepts around security and development.

For establishing a Secure Development practice within the FPS Justice, we have opted to base ourselves on the Software Assurance Maturity Model (SAMM) from the Open Worldwide Application Security Project (OWASP), a framework that helps organizations improve their software security through best practices and measurable goals. Knowledge of this framework is therefore recommended.

The profile will help the existing teams incorporate secure development into their daily tasks and, in doing so, lay the foundation for the fundamentals of a secure development program within the FPS Justice. The focus is on SecDevOps and its implementation.

By describing, documenting, and teaching these methodologies, the profile actively contributes to increasing the security of the programs built within and for the FPS Justice. Additionally, efforts are made to increase the overall security maturity within the development teams. The profile will also participate in setting up application security dashboards and will put the necessary routines in place and map them out to permanently improve the security of developments.

An important outcome of this project is a standard guideline on how secure development can be actively applied, not only for internal projects but also for suppliers, and a security matrix that can be used to assess external projects.

Because this is the start of the project, the profile must have the necessary experience and maturity to act as project lead. In addition, it will be necessary to participate in the required meetings to report on planning and progress of the project, and the necessary documentation will be created regarding the chosen methodology and the way it can be implemented.

Within the scope of the assignment, the profile may also be asked to develop and teach the necessary secure development training to the involved teams.

As an expert architect, the profile is able to assess and comment on technical designs, and to provide well-founded advice on both basic infrastructure regarding hardware and software as well as methodology.

Required expertise:

  • Demonstrable experience in similar projects in an environment of the same scale as the FPS Justice
  • At least 3 years of experience in reviewing security architectures
  • At least 3 years of experience in setting up SCA, SAST, and DAST tooling in a CI/CD pipeline
  • At least 3 years of experience in DevSecOps
  • Knowledge of Project Management
  • Agile / Lean Software Development
  • Security Frameworks (CyFun/SAMM/…)
  • Quality Assurance & Testing (test-driven development)
  • Result–, Customer-oriented, sense of responsibility
  • Planning and organizational skills, ability to direct, control, and

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration