Business application audit consultant
Context and Objectives: The mission aims to assess and secure the business applications of the information system, to manage risks, and to improve their governance, architecture, operation, and compliance. – Identify risks, vulnerabilities, and compliance gaps; – Evaluate the effectiveness of controls, processes, and service level agreements; – Formulate prioritized and measurable operational recommendations.
Main responsibilities: The consultant conducts audits of applications in development or production, particularly during a redesign, major upgrade, security review, intrusion risk assessment, or regulatory change. Their work covers governance, processes, functionalities, data, flows, interfaces, architecture, access rights, security, development, and testing.
Activities and expected deliverables- Define the scope of the mission, analyze the documentation and develop the work program; Conduct interviews, investigations, checks and tests on documents or on site; Evaluate the risks and the quality of the controls, then formalize substantiated findings; Facilitate feedback sessions and ensure follow-up on recommendations.
- Scoping note and audit plan; Risk and control matrix, application mapping and evidence file; Register of findings and reporting support; Provisional and final reports, action plan and monitoring table.
- Proficiency in IT audit methodologies, risk analysis, and control assessment; Expertise in application architectures, APIs, data flows, databases, cloud computing, access rights management, application security, and secure development practices; Ability to review code, configurations, logs, and test results, qualify vulnerabilities, and rule out false positives; Proficiency with audit and security tools, including Burp Suite, OWASP ZAP, Postman, Nessus, Qualys, Open
VAS, Sonar
Qube, Checkmarx, Fortify, Snyk, Nmap, Wireshark, Microsoft Sentinel, Splunk, or equivalent;- Excellent analytical, writing, presentation, and facilitation skills, with rigor, autonomy, diplomacy, and respect for confidentiality.
- ISO/IEC 27001, 27002 and 27005, ISO 19011 and ISO 9001; EBIOS Risk Manager, COBIT and ITIL; OWASP Top 10 and ASVS, CIS Controls and Benchmarks, NIST Cybersecurity Framework and ANSSI recommendations; GDPR and CNIL requirements.
- Experience: at least five years in application auditing of critical or complex business applications, with comparable references; Expertise: complete mastery of the audit cycle, risks, application security, tools and required frameworks; Quality of intervention: structured method, reasoned findings, pragmatic recommendations and actionable deliverables; Soft skills: autonomy, listening skills, teaching ability, respect for deadlines and ability to work with business, technical and managerial stakeholders.
Desired profile: Experienced consultant with at least five years of effective experience in application auditing. They must have conducted end-to-end missions — scoping, document analysis, interviews, testing, risk assessment and controls, reporting and follow-up — on applications in project or production, in collaboration with business, development, production, security and IT governance teams.
Application: CV + cover letter + copies of diplomas to be sent to
#J-18808-Ljbffr