{"id":1485588,"url":"https://alion.io/job/salt-application-security-controls-specialist-dora-programme","title":"Application Security & Controls Specialist (DORA Programme)","company":{"id":1935342,"name":"Salt","domain":"welovesalt.com","url":"https://alion.io/company/welovesalt","size_band":"201-500","is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":{"grade":"C","score":64,"open_postings":1440,"ghost_share":0.608,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":["GB"],"hiring_countries_total":1,"salary":{"min":600,"max":800,"currency":"EUR","period":"day","gross":null,"usd_annual":227000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"SBOM","optional":false}],"status":"live","first_seen_at":"2026-02-20T00:00:00Z","employer_posted_date":"2026-02-20","last_verified_at":"2026-09-29T22:22:26Z","board_verified":true,"closed_at":null,"days_open":223,"trust":{"level":"ghost","repost_count":0,"flags":["stale","company_stale"],"days_open":223},"description":"Back to all jobs\nApplications are now closed.\nApplication Security & Controls Specialist (DORA Programme)\nRef: JO-2602-359338\nUnited Kingdom, London \n\nCyber Security and Risk, Technology \n\nIT \n\n5,000+ Employees \n\n€600.00 - €800.00 per day \n\nEnvironment:\n\nHybrid \n\nContract Type:\n\nContract \n\nStarts:\n\nASAP \n\nSenior Application Security & Controls Specialist (DORA Programme) - Banking Client - Brussels / Paris\nDuration: 1 year contract\nRate: Flexible\nHybrid Working - 8 days onsite per month in the Paris or Brussels office, the rest is remote working\nAbout the Role:\nWe are looking for an experienced and dynamic Senior Security Analyst to support DORA transformation through the design, implementation, and embedding of new transversal security controls across the organization.\nIn this role, you will contribute to the definition, rollout, and continuous improvement of security capabilities in domains such as software supply chain security, SBOM management, security code review, data classification, database encryption, cryptography policy implementation, and code integrity management.\nTo achieve this, you will work closely with multi-functional teams across the organization and will be exposed to a diversified set of topics, business areas, and technologies.\nYour responsibilities:\nEmbedding & Operationalisation of new security controls\nWork with IT, Engineering, Architecture, and CISO teams to integrate new controls into existing processes, tools, and platforms.\nSupport teams in understanding threats, risks, and compliance expectations related to software supply chain, cryptography, and application security.\nIdentify gaps between current capabilities and new DORA requirements and provide clear, actionable remediation recommendations.\nContribute to the rollout, adoption, and continuous improvement of newly introduced security controls.\nSecurity Advisory\nPerform targeted security assessments on applications, processes, and technical components to evaluate compliance with the new security controls.\nMap system architectures, technology stacks, and data flows to validate control applicability.\nProvide expert-level advisory on secure implementation across different environments (on-prem, mainframe, cloud).\nCollaborate closely with architects, engineers, developers, risk teams, and control owners to support remediation plans and technical decisions.\nExperience\n5-10 years of hands-on experience in designing or implementing information security controls, frameworks, or processes.\nProven experience in security risk assessment, application security, or security governance.\nStrong expertise in at least several of the following areas: \nSoftware Supply Chain Security \nSBOM management \nCode integrity and build pipeline security\nSAST / DAST / code analysis / ASPM (Application Security Posture Management) \nData classification \nDatabase encryption & key management \nCryptography governance & implementation \nSolid knowledge of cybersecurity frameworks (ISO 27001, CIS, NIST, DORA) \nGood understanding of financial-sector IT security regulatory requirements, especially DORA, ESMA, and outsourcing regulation is a plus.\nFluency in English. \nCertification such as CISSP, CSSLP, CCSP, CISM, CISMP, GCIH, CEH, etc. is an advantage.\nStrong communication and coordination skills, with the ability to engage effectively with stakeholders across diverse teams (Supply Chain, CISO, IT, etc.).\nProactive and self-motivated, comfortable working in a dynamic and continuously evolving environment.\nStrong analytical capabilities combined with creative problem-solving skills.\nStructured and synthetic, able to deliver clear, concise, and relevant responses to requests.\nCalm, organized, and efficient under pressure, maintaining clarity even in situations of uncertainty.\nCollaborative mindset, able to work effectively with executives, business leaders, and technical teams.\nAutonomous and well-organized, with strong prioritization and time-management abilities.\nSoft Skills\nStrong communication and coordination skills, with the ability to engage effectively with stakeholders across diverse teams (Supply Chain, CISO, IT, etc.).\nProactive and self-motivated, comfortable working in a dynamic and continuously evolving environment.\nStrong analytical capabilities combined with creative problem-solving skills.\nStructured and synthetic, able to deliver clear, concise, and relevant responses to requests.\nCalm, organized, and efficient under pressure, maintaining clarity even in situations of uncertainty.\nCollaborative mindset, able to work effectively with executives, business leaders, and technical teams.\nAutonomous and well-organized, with strong prioritization and time-management abilities.\nPlease do send an up to date CV to \n*Rates depend on experience and client requirements","description_format":"text","description_chars":4828,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":["Hybrid work"],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security"],"lifecycle":[{"event":"open","at":"2026-09-29T22:19:05Z"}],"liveness":{"score":3,"band":"cold","label":"Long shot","p_open":1,"p_active":0.113,"p_room":0.28,"age_days":223,"expected_fill_days":41,"reasons":["conf:31","agency","stale_co","urgency","velocity","ghost","win:tail","crowd:brand"],"computed_at":"2026-10-01T05:45:00Z"},"pay":{"stated_usd_annual":227000,"is_top_pay":true},"html_url":"https://alion.io/job/salt-application-security-controls-specialist-dora-programme","json_url":"https://alion.io/job/salt-application-security-controls-specialist-dora-programme.json","meta":{"generated_at":"2026-10-01T10:58:48Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2243,"day_limit":5000,"remaining_today":2757,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}