We are looking for

Application Security Specialist - AlphaCredit (M/F/X)

Back to offers list
Retour

Application Security Specialist - AlphaCredit (M/F/X)

  • Permanent
  • Full time
  • Brussels, Brussels, Belgium
Apply
Last update 18.09.2026

AlphaCredit is the market leader in consumer loans in Belgium and Luxembourg and is part of the BNP Paribas group. From our office, within walking distance of Brussels Central station, we offer all possible credit solutions through our professional partners or directly to customers.  Present for over 30 years, our experience allows us to realize the dreams of thousands of clients with a responsible approach.

Job Purpose

As an Application Security Specialist at PF Benelux, you will play a critical role in securing our digital assets by identifying, assessing, and mitigating security vulnerabilities in applications, APIs, and software development lifecycle (SDLC) processes. You will collaborate with development teams (tribes), architects, and security stakeholders to embed security best practices, ensure compliance with regulatory requirements (e.g., GDPR,DORA), and protect the company’s systems and customer data from evolving threats.

Key Responsibilities

  1. Security Assessment & Vulnerability Management

Ensure that tribes use static (SAST), dynamic (DAST), and interactive (IAST) application security testing to identify vulnerabilities (e.g., OWASP Top 10, SANS CWE Top 25).

Advise the tribes in vulnerability remediation prioritization based on risk (CVSS, business impact).

Oversee the vulnerability remediations & advise the CISO on the compliance of a change to application security requirements.

Perform code reviews (manual and automated) for in-house and third-party applications, focusing on secure coding practices (e.g., OWASP ASVS, CERT guidelines).

  1. Secure SDLC & DevSecOps Integration

Promote security-by-design principles, embedding security controls early in the SDLC (e.g., security requirements, threat modeling).

Collaborate with DevOps/DevSecOps teams to integrate security tools (e.g., SonarQube, Fortify, Sysdig …) into CI/CD pipelines.

Provide application security expertise for the tribe security champions  on matters like (e.g., secure coding in Java, Python,.).

Advise on secure API design (OAuth 2.0, OpenID Connect, JWT, rate limiting) and microservices architecture.

  1. Risk Assessment & Threat Modeling

Identify risks associated with third-party vendors, open-source components, and cloud-native applications (e.g., container security, serverless)

Lead threat modeling exercises (e.g., STRIDE, DREAD) for critical applications and infrastructure.

  1. Awareness & Training

Deliver secure coding training and workshops for developers (e.g., OWASP Top 10, common pitfalls in financial applications).

Promote a security-first culture through awareness campaigns and knowledge sharing.

  1. Incident Response & Forensics

Assist in investigating security incidents related to applications (e.g., data breaches, injection attacks).

Analyze logs and artifacts to identify root causes and prevent recurrence.

Qualifications & Experience

Must-Have:

Education: Bachelor’s or Master’s degree in Computer Science, or equivalent experience.

Experience:

3+ years in application security, with hands-on experience in SAST/DAST tools, code review, and vulnerability management.

Familiarity with OWASP Top 10, SANS CWE, and secure coding practices (e.g., input validation, authentication, session management).

Experience with security testing tools (e.g., Nessus, Fortify,).

Knowledge of web technologies (HTTP/S, REST, WebSockets) and common frameworks (Spring, React, Angular).

Understanding of cloud security and containerization (e.g. Kubernetes).

Soft Skills:

Strong communication and collaboration skills to bridge security and development teams.

Excellent capacity to cooperate with other teams

Analytical mindset with a problem-solving approach.

Ability to translate technical risks into business impact for stakeholders.

Nice-to-Have:

Certifications: OSCP, CISSP, CSSLP, CEH, or OWASP-related certifications.

Scripting skills (e.g. Python, PowerShell) for automation.

Technical Environment

Languages/Frameworks: Java, Python, JavaScript/TypeScript, Go.

Tools: Burp Suite, OWASP ZAP, SonarQube, Checkmarx, Snyk, Fortify, Nessus, GitLab/GitHub Security.

Methodologies: Agile, DevSecOps, Threat Modeling (STRIDE, PASTA).

Regulations: GDPR, DORA

Offer

A rewarding function in a flexible working environment.

An open working environment and enthusiastic colleagues who, with you, strive to achieve a high level of customer satisfaction.

Many training opportunities to continue developing your knowledge and skills.

A permanent contract in a continuously evolving company within the solid BNP Paribas Group.

A competitive salary with a wide range of extra-legal benefits (insurance, meal vouchers, extra-legal days off, etc.).

A Flex Income Plan allowing you to convert your end-of-year bonus (with a fixed collective choice moment) into additional benefits each year, including a leasing bike or car, extra vacation days, etc.

A good work-life balance.

Promoting access to more responsible and sustainable consumption to support our clients and partners.

Leader in consumer credit in Belgium and Luxembourg, AlphaCredit is part of the BNP Paribas Group. We offer a full range of credit solutions through our professional partners

AlphaCredit is committed to promoting an inclusive and respectful work environment, where every individual is valued without distinction of race, gender, age, religion, sexual orientation, disability or any other characteristic protected by law.

Any form of discrimination is strictly prohibited by our code of conduct.