Description Du Poste Within the Cybersecurity Department of a major Luxury Group, the Security Integration in Projects (ISP) team ensures that security requirements are proactively and effectively embedded across all IT projects within the Group. The ISP acts as a key player in the cybersecurity framework to reduce exposure to cyber risks, ensure regulatory compliance, enforce internal security standards, and promote a strong Security by Design culture.
Main Activities
Security integration from project initiation: participation in Kick-Off Meetings, project criticality assessment, identification of security stakes, and triggering of required analyses.
Risk analysis and treatment: execution of Business Impact Analysis (BIA) and CATIS, identification of threat scenarios, risk evaluation (custom methodology aligned with ISO 27005 & EBIOS RM), definition and follow-up of mitigation measures.
Pentest coordination and follow-up: planning and coordination with external providers, analysis of test reports, and monitoring of vulnerability remediation.
Validation of new applications/tools: risk assessment, compliance verification against internal standards, definition of compensating controls where needed, and issuance of formal security opinions.
Technical architecture challenge: security review of proposed architectures (network segmentation, IAM, encryption, APIs, logging, interconnections) and formulation of recommendations prior to production go-live.
Votre Profil Confirmed to Senior Profile (minimum 4 years of experience) with strong expertise in cybersecurity and risk assessment activities.
Technical Skills
Strong knowledge of Information Security principles
Risk analysis expertise (ISO 27005 / EBIOS RM aligned)
Blueteam and security control expertise
Architecture security (on-premise and cloud environments)
Application security
Network and Infrastructure security
Vulnerability management
Understanding of modern IT environments
Expertise in AI, Cloud security, payment systems security would be highly appreciated
Project environments include: AS400, Headless architectures, SAP, data platforms, new retail points of sale, Cloud AWS, Azure, GCP, Alibaba, Salesforce
Certifications could be an advantage: CCSP, ISO27001, CISA, CRISC, CEH, CISSP, CCNA Cisco,...
Facultative: Redteam culture or experiences
Soft Skills
Ability to challenge stakeholders diplomatically
Strong analytical and structured mindset
Leadership capabilities
Strong synthesis and reporting skills
High level of autonomy
Proactive and solution-oriented mindset
Languages
English: mandatory
French: recommended
Inclusion We value diversity and inclusion. All our offers are open to people with disabilities.
#J-18808-Ljbffr
Procure outros empregos
Descrição do cargo
Criar um alerta de emprego para esta pesquisa
Cybersecurity Consultant M/F • Porto, Portugal