Junior Application Security Consultant
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, IT Consultant
It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents.
All of this is built on four fundamental values that define who we are:
We are Proud, We Break Barriers, We Care and No BS!
As a Junior Application Security Consultant
, you will join a team focused on helping clients build and maintain secure applications by integrating security into their development lifecycle. You will work closely with experienced consultants and progressively take ownership of tasks as your skills grow.
Your role is strongly oriented towards the defensive side of application security
, with a particular focus on threat modeling
, secure design, and security maturity improvements.
Projects you will contribute to include:
- Supporting threat modeling activities by helping analyze architectures, data flows, assets, trust boundaries, and security assumptions together with senior consultants.
- Participating and also lead workshops with developers, product owners, and architects to identify and understand how an attacker would carry out malicious actions on one or more systems of any kind (IoT, OT, IT, etc.).
- Contributing to application and software architecture security reviews.
- Supporting maturity assessments (e.g. OWASP SAMM, DSOMM, CyFun) and helping clients understand their current maturity and improvement priorities.
- Assisting in the preparation of technical security tests and penetration tests based on the identified threats, including helping define test scopes, relevant attack paths, and security assumptions to be validated.
- Supporting senior consultants during technical testing activities by mapping test results back to identified threats and risk scenarios.
- Helping prepare and deliver security awareness or secure coding sessions with other experts.
You will always be supported by senior team members and progressively gain autonomy as your understanding of application security, threat modeling, and consulting grows.
Requirements- Eligibility for NATO CLEARANCE (details here );
- You have a genuine interest in IT security and secure software development.
- Basic understanding of application architectures, development frameworks, and authentication mechanisms (e.g. OAuth, OpenID Connect).
- Some familiarity with development practices and programming concepts; hands-on coding experience is a plus but not mandatory.
- Initial exposure to build and CI/CD tools (e.g. Jenkins, Azure Dev Ops/TFS, Maven, or similar).
- Foundational knowledge of the Secure Development Lifecycle (SDLC) and an interest in how security requirements, design, and testing fit into it.
- Awareness of common application security risks and vulnerabilities (e.g. OWASP Top 10).
- Interest in application threat modeling, secure architecture, and identifying design or business logic flaws under guidance.
- Ability to communicate clearly with technical stakeholders and willingness to develop confidence when interacting with clients.
- Positive, team- and mission-oriented attitude.
- Strong interpersonal and verbal/written communication skills, enabling effective collaboration in a consulting environment.
- Excellent English communication skills, both verbal and written;
Dutch and/or French is a plus. - You are ambitious, curious, and motivated to help clients improve their security posture.
- You are willing to learn and become a better version of yourself, everyday;
- Candidates must recognize and deal appropriately with confidential and sensitive information
At NVISO, we care. We are committed to offering you a highly competitive remuneration package including financial and non-financial components:
- A training budget of 10.000€ and 10 days every 2 years
- Company car and Belgian fuel card
- Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (Black Hat, BruCON, OWASP, etc) and all of our technical staff can acquire…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).