Expert Application Architect Security - SPF Justice - FOD Justitie
Description
FOD Justitie / SPF Justice is launching a Secure Development project to embed software security into daily development processes. The initiative is linked to NIS2 and the Belgian CyFun framework, including expectations for secure development of critical systems and components. OWASP SAMM will serve as an important reference model for improving software security through best practices and measurable objectives. The consultant will help turn these requirements into practical, repeatable ways of working.
The consultant will support existing teams in adopting secure development and SecDevOps practices. Responsibilities include documenting methodologies, training teams, establishing application-security dashboards and defining routines for continuous improvement. Key deliverables include a standard secure-development guideline covering internal projects and external suppliers, plus a security matrix for assessing external projects. The work is intended to raise both application security and the overall security maturity of development teams.
The assignment also requires project leadership because the initiative is at its launch stage. The consultant will participate in follow-up meetings, report on planning and progress, document the selected methodologies and their implementation, and may design and deliver secure-development training. As an expert architect, the consultant will assess and comment on technical designs and provide substantiated advice on hardware, software and working methodologies. The initial engagement runs full-time and hybrid in Brussels from July through December 2027.
Top Reasons to Apply
Launch security program
Shape secure development
Lead DevSecOps adoption
Raise security maturity
Train technical teams
Detailed Responsibilities and Skills
Additional Responsibilities
- Define security improvement routines
- Create secure development guideline
- Create external security matrix
- Lead secure development project
- Attend project follow-up meetings
- Report planning and progress
- Document methodology implementation
- Design secure development training
- Deliver secure development training
- Assess technical architecture designs
- Comment technical architecture designs
- Advise hardware software infrastructure
- Advise working methodologies
General skills
- Demonstrated experience in similar projects in an environment comparable in scale to FOD Justitie / SPF Justice
- Knowledge of project management
- Result orientation, client orientation and sense of responsibility
- Planning and organizational ability, including steering, controlling and adjusting
- Negotiation ability and relationship orientation
- Ability to build, lead and supervise a team
- Ability to communicate with highly technical and less technical profiles
- Ability to promote security and development concepts convincingly
- Active knowledge of Dutch or French
- English is nice to have
- ITIL knowledge is nice to have
Technical skills
- Minimum 3 years of experience reviewing security architectures
- Minimum 3 years of experience in DevSecOps
- Agile / Lean Software Development
- Security frameworks such as CyFun and SAMM
- Quality Assurance and Testing, including test-driven development
- Strong security knowledge combined with application architecture, or strong application-development knowledge combined with security architecture
- Experience implementing and analyzing required changes in a development process and mapping and documenting them clearly
- SAMM framework familiarity is nice to have
- CyFun framework familiarity is nice to have
- Java knowledge is nice to have
- Angular knowledge is nice to have
- Oracle knowledge is nice to have
- Web Services technology knowledge is nice to have
- Service Bus technology knowledge is nice to have
Tools
- Minimum 3 years of experience setting up SCA tooling in a CI/CD chain
- Minimum 3 years of experience setting up SAST tooling in a CI/CD chain
- Minimum 3 years of experience setting up DAST tooling in a CI/CD chain
- Experience with CI/CD chains