JustJoin.IT Praca zdalna Senior

Business & Security Analyst (m/f/n)

Shimi Sp. z o.o.

⚲ Warszawa

9 450 - 11 340 EUR netto (B2B)

Wymagania

  • BPMN
  • UML
  • Jira
  • API
  • SOAP

Opis stanowiska

Currently, for one of our Partners, we are looking for an experienced eDelivery Business & Security Analyst (m/f/n) to support a long-term project in an international public sector environment.

Offer
• Contract: B2B via SHIMI Poland.
• Mostly remote, services must be performed from within the EU. Occasional travelling to Brussels may be required (the client may request onsite presence in Brussels with 7 days’, at contractor’s cost). 2 physical meetings with the customer are foreseen per 12-month period, maximum 2 days each. These planned meetings are at the contractor’s cost.
• Rate: 450–540 EUR/MD nett + VAT
• Long-term cooperation

Requirements


Business analysis experience: at least 8 years.



Security work experience: at least 5 years.

• Experience with analysis and modelling techniques, including user stories, use cases, acceptance criteria, state diagrams and entity-relationship models: at least 5 years.
• Experience writing functional requirements: at least 5 years.
• Experience with BPMN, UML or equivalent modelling standards: at least 5 years.
• Experience with requirements management tools such as Jira or GitLab: at least 5 years.
• Experience working with APIs, including REST, SOAP or OpenAPI: at least 5 years.
• Experience with encryption protocols and technologies, including TLS/SSL, IPSec, AES, RSA or PKI: at least 3 years.
• Experience with collaboration platforms such as Confluence or SharePoint: at least 3 years.
• Experience in business analysis related to eDelivery specifications, including eDelivery AS4, eDelivery SMP, eDelivery BDXL and eDelivery ebCore PartyId.
• Experience with eDelivery products such as Domibus, DomiSMP and DomiSML.
• Experience with the eDelivery Conformance Testing Service.
• Experience in eliciting, validating and documenting business needs using structured techniques.
• Experience in preparing Business Requirements Documents, Functional Specifications, User Stories and acceptance criteria.
• Experience in defining and managing acceptance criteria, supporting test case design and User Acceptance Testing.
• Experience in maintaining requirements traceability and managing change requests throughout the lifecycle.
• Experience in documenting non-functional requirements, including performance, security and usability.
• Experience in developing and implementing security policies and procedures.
• Experience in defining, implementing and monitoring security plans.
• Experience in guiding development teams throughout the Software Development Lifecycle to build and operate software securely.
• Experience with security standards and industry best practices, including OWASP Top 10.
• Experience in conducting security inspections, code reviews and risk assessments for internally developed and SaaS applications.
• Experience in monitoring systems for security breaches and incidents.
• Experience in analysing and responding to security threats and vulnerabilities, including managing remediation processes through to closure.
• Experience in designing and deploying security solutions for data centre and cloud environments.
• Experience in collaborating with IT and business teams to ensure compliance with security standards.
• Experience in data protection and privacy through encryption and access controls.
• Experience in managing and configuring security tools.
• Experience in leading security incident response, including containment, eradication, recovery and post-incident analysis and reporting.


English: minimum C1 level, with strong written and oral communication skills.

Nice to have
• Business analysis experience above 10 years.
• Security work experience above 7 years.
• Experience with key eDelivery standards: OASIS ebMS3, AS4, SMP, BDXL and ebCore PartyId.
• Experience with eDelivery profiles: eDelivery AS4 profile, eDelivery SMP profile, eDelivery BDXL profile and eDelivery ebCore PartyId profile.
• Experience with integrating security into DevSecOps pipelines, including SAST, DAST and software supply chain security tools.
• Experience with cloud security architectures and controls.
• Experience with diagramming, modelling and wireframing tools such as Microsoft Visio, Lucidchart, UML, BPMN, Axure, Balsamiq or Pencil.
• Experience with secure coding practices and common vulnerabilities, including OWASP Top 10.
• Experience with vulnerability assessment and penetration testing methodologies and tools such as Nessus, Qualys, Burp Suite, Metasploit or OWASP ZAP.
• Recognised certification in information systems security.
• Experience working in an international or intergovernmental organisation, European Institutions or large public administration.
• Experience preparing business analysis deliverables.
• Experience tailoring communication to business and technical audiences.
• Experience producing structured technical documentation, specifications and presentations in English.
• French: B2 level

Tasks
• Perform business analysis duties related to eDelivery specifications (eDelivery AS4, eDelivery SMP, eDelivery BDXL and eDelivery ebCore PartyId), products (Domibus, DomiSMP, DomiSML) and the eDelivery Conformance Testing Service.
• Monitor and coordinate and assist the implementation of all relevant security measures to ensure a strong security posture of the eDelivery product development lifecycle and of the eDelivery infrastructure.
• Evaluate business context, drivers, and expected outcomes to ensure alignment with strategic goals and stakeholder expectations.
• Elicit, validate, and document business needs using structured techniques to ensure clarity and traceability.
• Assess current and target business models to identify value streams, capabilities, and operational impacts.
• Map and evaluate existing processes to identify inefficiencies, bottlenecks, and improvement opportunities using industry-standard techniques.
• Create visual representations of workflows using standard notations to support analysis, communication, and solution design.
• Compare current and desired states to identify capability gaps, improvement areas, and potential solutions.
• Convert business requirements into functional specifications that guide solution design and development.
• Identify, assess, and document risks related to business processes, systems, and change initiatives, including mitigation strategies.
• Contribute to strategic documentation that defines scope, objectives, value proposition, and governance for initiatives (e.g. business cases, vision documents, charters, and security plans).
• Develop clear deliverables such as Business Requirements Documents (BRDs), Functional Specifications, and User Stories with acceptance criteria.
• Define and manage acceptance criteria and support test case design and user acceptance testing (UAT) to ensure requirements are met.
• Maintain requirements traceability (e.g., story/feature to test case) and manage change requests throughout the lifecycle.
• Document non-functional requirements (NFRs) (e.g., performance, security, usability) alongside functional requirements.
• Facilitate cross-functional communication among stakeholders, developers, and testers to ensure shared understanding and alignment.
• Develop and implement security policies and procedures.
• Define, implement and monitor security plans
• Guide development teams throughout the Software Development Lifecycle (SDLC) to build and operate software securely, following EC standards and industry best practices (e.g., OWASP Top 10).
• Conduct security inspections, code reviews, and risk assessments for internally developed as well as SaaS (Software-as-a-Service) applications.
• Monitor systems for security breaches and incidents.
• Analyse and respond to security threats and vulnerabilities, including managing the remediation process through to closure.
• Design and deploy security solutions and technologies for internal EC Data Centre and Cloud environments.
• Collaborate with IT and business teams to ensure compliance with security standards.
• Ensure data protection and privacy through encryption and access controls.
• Conduct security training and awareness programs for staff.
• Stay updated on the latest security trends and emerging threats.
• Manage and configure security tools.
• Lead the response to security incidents, including containment, eradication, recovery, and post-incident analysis and reporting.

🔍 Dekoder Ogłoszenia

🔴
Mostly remote, services must be performed from within the EU. Occasional travelling to Brussels may be required (the client may request onsite presence in Brussels with 7 days’, at contractor’s cost). 2 physical meetings with the customer are foreseen per 12-month period, maximum 2 days each. These planned meetings are at the contractor’s cost.
Praca jest głównie zdalna, ale potencjalne nieprzewidziane wizyty w Brukseli oraz zaplanowane spotkania będą na Twój koszt, co może znacząco zwiększyć wydatki.
🟡
Long-term cooperation
Może oznaczać stabilność, ale równie dobrze może być próbą zatrzymania pracownika na projekcie bez jasnych perspektyw rozwoju czy podwyżek.
🟡
450–540 EUR/MD nett + VAT
Podana stawka netto jest atrakcyjna, ale należy pamiętać o dodatkowych kosztach związanych z prowadzeniem działalności gospodarczej i potencjalnych podatkach.
🟡
experienced eDelivery Business & Security Analyst
Poszukiwany jest specjalista z konkretnym doświadczeniem w obszarze e-dostarczania, co może zawężać zakres potencjalnych kandydatów lub sugerować specyficzne wymagania projektu.
🟡
international public sector environment
Praca w sektorze publicznym może oznaczać stabilność i przewidywalność, ale także potencjalnie wolniejsze procesy decyzyjne i biurokrację.