Se rendre au contenu

Expert Application Architect Security - SPF Justice - FOD Justitie

Customer: SPF Justice - FOD Justitie Rue Evers, 2-8 1000 Bruxelles Belgique
Dates: 2027-07-01 2027-12-31
Arrangements: Full time; hybrid; 880 hours during the second half of 2027; optional extension in 2028 up to 1760 hours subject to approval by the Inspection of Finance
Apply before: 2026-10-01

Description

FOD Justitie / SPF Justice is launching a Secure Development project to embed software security into daily development processes. The initiative is linked to NIS2 and the Belgian CyFun framework, including expectations for secure development of critical systems and components. OWASP SAMM will serve as an important reference model for improving software security through best practices and measurable objectives. The consultant will help turn these requirements into practical, repeatable ways of working.

The consultant will support existing teams in adopting secure development and SecDevOps practices. Responsibilities include documenting methodologies, training teams, establishing application-security dashboards and defining routines for continuous improvement. Key deliverables include a standard secure-development guideline covering internal projects and external suppliers, plus a security matrix for assessing external projects. The work is intended to raise both application security and the overall security maturity of development teams.

The assignment also requires project leadership because the initiative is at its launch stage. The consultant will participate in follow-up meetings, report on planning and progress, document the selected methodologies and their implementation, and may design and deliver secure-development training. As an expert architect, the consultant will assess and comment on technical designs and provide substantiated advice on hardware, software and working methodologies. The initial engagement runs full-time and hybrid in Brussels from July through December 2027.

Top Reasons to Apply
Launch security program
Shape secure development
Lead DevSecOps adoption
Raise security maturity
Train technical teams
Responsibilities
Integrate secure development practices
Establish Secure Development program
Implement continuous security practices
Describe secure development methodologies
Document secure development methodologies
Train development teams
Increase application security maturity
Build application security dashboards
Must Have
Comparable project experience
3 years security architecture
3 years SCA/SAST/DAST
3 years DevSecOps
Project management knowledge
Agile Lean development
Security frameworks knowledge
Quality assurance testing
Nice to Have
ITIL knowledge
Java knowledge
Angular knowledge
Oracle knowledge
Web Services knowledge
Service Bus knowledge
SAMM framework familiarity
CyFun framework familiarity
English language

Detailed Responsibilities and Skills

Additional Responsibilities

  • Define security improvement routines
  • Create secure development guideline
  • Create external security matrix
  • Lead secure development project
  • Attend project follow-up meetings
  • Report planning and progress
  • Document methodology implementation
  • Design secure development training
  • Deliver secure development training
  • Assess technical architecture designs
  • Comment technical architecture designs
  • Advise hardware software infrastructure
  • Advise working methodologies

General skills

  • Demonstrated experience in similar projects in an environment comparable in scale to FOD Justitie / SPF Justice
  • Knowledge of project management
  • Result orientation, client orientation and sense of responsibility
  • Planning and organizational ability, including steering, controlling and adjusting
  • Negotiation ability and relationship orientation
  • Ability to build, lead and supervise a team
  • Ability to communicate with highly technical and less technical profiles
  • Ability to promote security and development concepts convincingly
  • Active knowledge of Dutch or French
  • English is nice to have
  • ITIL knowledge is nice to have

Technical skills

  • Minimum 3 years of experience reviewing security architectures
  • Minimum 3 years of experience in DevSecOps
  • Agile / Lean Software Development
  • Security frameworks such as CyFun and SAMM
  • Quality Assurance and Testing, including test-driven development
  • Strong security knowledge combined with application architecture, or strong application-development knowledge combined with security architecture
  • Experience implementing and analyzing required changes in a development process and mapping and documenting them clearly
  • SAMM framework familiarity is nice to have
  • CyFun framework familiarity is nice to have
  • Java knowledge is nice to have
  • Angular knowledge is nice to have
  • Oracle knowledge is nice to have
  • Web Services technology knowledge is nice to have
  • Service Bus technology knowledge is nice to have

Tools

  • Minimum 3 years of experience setting up SCA tooling in a CI/CD chain
  • Minimum 3 years of experience setting up SAST tooling in a CI/CD chain
  • Minimum 3 years of experience setting up DAST tooling in a CI/CD chain
  • Experience with CI/CD chains