Our client is seeking an experienced Application Security Specialist who can drive strategic security initiatives, lead by example, and raise the bar across the security domain. You will serve as the go-to expert for application security, shaping the security posture of a complex, high-impact IT landscape.
In this role, you are expected to maintain oversight across the entire estate and communicate effectively with both technical teams and senior management. You lead with expertise, guide your peers, and foster a security-first mindset throughout the organization.
Your Responsibilities
-
Lead on content and provide expert guidance to engineering and product teams.
-
Perform and guide threat modelling of assigned applications; store models in the organization’s threat modelling repository.
-
Conduct application security assessments, identify gaps, and register them promptly in the organization's GRC tooling.
-
Evaluate vendor contracts (e.g. SaaS, COTS) from a security perspective and identify deviations that require risk opinions or compensating measures.
-
Balance technical and organizational controls to ensure pragmatic security recommendations.
-
Identify recurring application security themes and initiate continuous improvement initiatives.
-
Translate complex security concepts into clear, actionable advice for non-technical audiences.
-
Contribute to DORA-aligned contract deviation assessments with timely and accurate reporting.
-
Act as a coach and role model to more junior team members, fostering a culture of knowledge sharing and continuous learning.
-
Work under pressure while keeping a clear overview and prioritizing critical issues.
Required Qualifications
-
10+ years of experience in IT and application security.
-
Proven experience with application migration, transition, and re-platforming projects.
-
Strong experience in reviewing vendor contracts from a security perspective.
-
In-depth knowledge of secure development practices, secure SDLC, and security by design.
-
Experience with IS documentation, reporting, and consulting.
-
Familiarity with threat modelling, security assessments, and GRC tooling.
-
Proficient in communicating with both technical and business stakeholders.
-
Strong stakeholder management skills, particularly in international and multicultural settings.
-
Recognized security certifications such as CISSP, CCSP, CEH, CISA, CISM, or CCSK.
-
A degree in Information Science, Computer Science, or a related discipline.
Nice to Have
-
Fluency in Dutch is a strong advantage.
-
Experience driving complex security topics across multiple teams or departments.
-
Comfortable presenting security issues to leadership and influencing organizational change.