Business & Security Analyst (m/f/n)

9450 - 11.3k PLN/ mies.B2B
SeniorFull-time·B2B
#392827·Dodano 5 dni temu·0
Źródło: Shimi
Aplikuj teraz

Tech Stack / Keywords

SecurityUMLJiraGitLabRESTSOAPTestingSoftware Development

Firma i stanowisko

SHIMI Sp. z o.o.

Wymagania

  • Education: EQF 6 minimum; EQF 7 will be considered an advantage.
  • At least 8 years of business analysis experience.
  • At least 5 years of security work experience.
  • Experience with analysis and modelling techniques including user stories, use cases, acceptance criteria, state diagrams and entity-relationship models (5 years).
  • Experience writing functional requirements (5 years).
  • Experience with BPMN, UML or equivalent modelling standards (5 years).
  • Experience with requirements management tools such as Jira or GitLab (5 years).
  • Experience working with APIs including REST, SOAP or OpenAPI (5 years).
  • Experience with encryption protocols and technologies including TLS/SSL, IPSec, AES, RSA or PKI (3 years).
  • Experience with collaboration platforms such as Confluence or SharePoint (3 years).
  • Experience with eDelivery specifications like eDelivery AS4, eDelivery SMP, eDelivery BDXL and eDelivery ebCore PartyId.
  • Experience with eDelivery products such as Domibus, DomiSMP and DomiSML.
  • Experience with the eDelivery Conformance Testing Service.
  • Experience in developing and implementing security plans and policies.
  • Experience with security standards and industry best practices including OWASP Top 10.
  • Strong English skills at minimum C1 level, written and oral.

Nice to have:

  • Business analysis experience above 10 years.
  • Security work experience above 7 years.
  • Experience with key eDelivery standards: OASIS ebMS3, AS4, SMP, BDXL and ebCore PartyId.
  • Experience with eDelivery profiles such as eDelivery AS4 profile, SMP profile, BDXL profile and ebCore PartyId profile.
  • Experience integrating security into DevSecOps pipelines, including SAST, DAST and software supply chain security tools.
  • Experience with cloud security architectures and controls.
  • Experience with diagramming, modelling and wireframing tools such as Microsoft Visio, Lucidchart, UML, BPMN, Axure, Balsamiq or Pencil.
  • Experience with secure coding practices and vulnerabilities including OWASP Top 10.
  • Experience with vulnerability assessment and penetration testing tools such as Nessus, Qualys, Burp Suite, Metasploit or OWASP ZAP.
  • Recognised certification in information systems security.
  • Experience working in international or intergovernmental organisations, European Institutions or large public administration.
  • Experience tailoring communication to business and technical audiences.
  • Experience producing structured technical documentation and presentations in English.
  • French language skills at B2 level.

Obowiązki

  • Eliciting, validating and documenting business needs using structured techniques.
  • Preparing Business Requirements Documents, Functional Specifications, User Stories and acceptance criteria.
  • Defining and managing acceptance criteria, supporting test case design and User Acceptance Testing.
  • Maintaining requirements traceability and managing change requests throughout the lifecycle.
  • Documenting non-functional requirements, including performance, security and usability.
  • Developing and implementing security policies and procedures.
  • Defining, implementing and monitoring security plans.
  • Guiding development teams throughout the Software Development Lifecycle to build and operate software securely.
  • Conducting security inspections, code reviews and risk assessments for internally developed and SaaS applications.
  • Monitoring systems for security breaches and incidents.
  • Analyzing and responding to security threats and vulnerabilities, including managing remediation processes through to closure.
  • Designing and deploying security solutions for data centre and cloud environments.
  • Collaborating with IT and business teams to ensure compliance with security standards.
  • Managing and configuring security tools.
  • Leading security incident response, including containment, eradication, recovery and post-incident analysis and reporting.

Benefity

  • Contract: B2B via SHIMI Poland.
  • Mostly remote / far-site work within the EU.
  • Occasional travel to Brussels may be required with 7 days’ notice.
  • Maximum 2 physical meetings per 12-month period, up to 2 days each, at contractor’s cost; additional travel reimbursed only if approved.
  • Rate: 450–540 EUR per man-day.

Inne informacje

Services must be performed from within the EU. CV must be provided in Europass format.

SHIMI sp. z o.o.

SHIMI sp. z o.o.

106 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz