This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Strengthen cyber risk management system, in a context of evolving threats, increased requirements from regulators and the continuous transformation of business infrastructures and services. The service covers the entire cyber risk analysis cycle, and includes support for projects, operational teams, and security governance.
Job Responsibility:
Strengthen cyber risk management system
Cyber Risk Analysis
identification and assessment of vulnerabilities
definition of remediation plans
support for project and operational teams in risk management
Carrying out risk analyses on applications, infrastructures, flows, IT projects and exposed devices
Assessment of threat scenarios, business impacts, and probability of occurrence
Analysis of deviations from internal standards and recommendations
Review of the risks related to service providers, SaaS/IaaS/PaaS providers
Evaluation of the security measures taken, risk scoring, definition of action plans
TPRM Steering Support
Integration of security requirements (Secure by Design)
Participation in architecture workshops, approvals, and design reviews
Recommendations on technical choices
Updating of risk registers
Follow-up of actions, decisions, acceptances and justifications
Contribution to safety committees
Cyber monitoring (technical, regulatory and sectoral)
Participation in the updating of safety policies, standards and guides
Requirements:
10 to 15 years experience
Risk analysis methodologies (ISO 27005, NIST RMF, optional EBIOS RM)
In-depth knowledge of network, application and cloud architecture
Security best practices (OWASP, CIS Benchmarks, NIST SP 80053)
Understanding of IAM/PAM, DevSecOps, API security
CRISC / CISSP certified
ISO 27005 / CISM
Ability to analyze and formalize
Autonomy, strength of proposal
Pedagogy and effective communication
Good Communication & Stakeholder Management skills
Engineering graduate - preferably B.E. /B.Tech in IT or Computer Engineering