Business & Security Analyst (m/f/n)
9450 - 11.3k PLN9450 - 11 340 PLN/ mies.B2B
SeniorFull-time·B2B
#392827·Dodano 5 dni temu·0
Źródło: ShimiTech Stack / Keywords
SecurityUMLJiraGitLabRESTSOAPTestingSoftware Development
Firma i stanowisko
SHIMI Sp. z o.o.
Wymagania
- Education: EQF 6 minimum; EQF 7 will be considered an advantage.
- At least 8 years of business analysis experience.
- At least 5 years of security work experience.
- Experience with analysis and modelling techniques including user stories, use cases, acceptance criteria, state diagrams and entity-relationship models (5 years).
- Experience writing functional requirements (5 years).
- Experience with BPMN, UML or equivalent modelling standards (5 years).
- Experience with requirements management tools such as Jira or GitLab (5 years).
- Experience working with APIs including REST, SOAP or OpenAPI (5 years).
- Experience with encryption protocols and technologies including TLS/SSL, IPSec, AES, RSA or PKI (3 years).
- Experience with collaboration platforms such as Confluence or SharePoint (3 years).
- Experience with eDelivery specifications like eDelivery AS4, eDelivery SMP, eDelivery BDXL and eDelivery ebCore PartyId.
- Experience with eDelivery products such as Domibus, DomiSMP and DomiSML.
- Experience with the eDelivery Conformance Testing Service.
- Experience in developing and implementing security plans and policies.
- Experience with security standards and industry best practices including OWASP Top 10.
- Strong English skills at minimum C1 level, written and oral.
Nice to have:
- Business analysis experience above 10 years.
- Security work experience above 7 years.
- Experience with key eDelivery standards: OASIS ebMS3, AS4, SMP, BDXL and ebCore PartyId.
- Experience with eDelivery profiles such as eDelivery AS4 profile, SMP profile, BDXL profile and ebCore PartyId profile.
- Experience integrating security into DevSecOps pipelines, including SAST, DAST and software supply chain security tools.
- Experience with cloud security architectures and controls.
- Experience with diagramming, modelling and wireframing tools such as Microsoft Visio, Lucidchart, UML, BPMN, Axure, Balsamiq or Pencil.
- Experience with secure coding practices and vulnerabilities including OWASP Top 10.
- Experience with vulnerability assessment and penetration testing tools such as Nessus, Qualys, Burp Suite, Metasploit or OWASP ZAP.
- Recognised certification in information systems security.
- Experience working in international or intergovernmental organisations, European Institutions or large public administration.
- Experience tailoring communication to business and technical audiences.
- Experience producing structured technical documentation and presentations in English.
- French language skills at B2 level.
Obowiązki
- Eliciting, validating and documenting business needs using structured techniques.
- Preparing Business Requirements Documents, Functional Specifications, User Stories and acceptance criteria.
- Defining and managing acceptance criteria, supporting test case design and User Acceptance Testing.
- Maintaining requirements traceability and managing change requests throughout the lifecycle.
- Documenting non-functional requirements, including performance, security and usability.
- Developing and implementing security policies and procedures.
- Defining, implementing and monitoring security plans.
- Guiding development teams throughout the Software Development Lifecycle to build and operate software securely.
- Conducting security inspections, code reviews and risk assessments for internally developed and SaaS applications.
- Monitoring systems for security breaches and incidents.
- Analyzing and responding to security threats and vulnerabilities, including managing remediation processes through to closure.
- Designing and deploying security solutions for data centre and cloud environments.
- Collaborating with IT and business teams to ensure compliance with security standards.
- Managing and configuring security tools.
- Leading security incident response, including containment, eradication, recovery and post-incident analysis and reporting.
Benefity
- Contract: B2B via SHIMI Poland.
- Mostly remote / far-site work within the EU.
- Occasional travel to Brussels may be required with 7 days’ notice.
- Maximum 2 physical meetings per 12-month period, up to 2 days each, at contractor’s cost; additional travel reimbursed only if approved.
- Rate: 450–540 EUR per man-day.
Inne informacje
Services must be performed from within the EU. CV must be provided in Europass format.
SHIMI sp. z o.o.
106 aktywnych ofert