cover image
SERMA SAFETY & SECURITY

SERMA SAFETY & SECURITY

www.serma-safety-security.com

10 Jobs

199 Employees

About the Company

SERMA Safety & Security is your single point of contact for the security and dependability of your products and systems.

Because Cybersecurity and Dependability are intricately linked, and the Security of connected objects has to be managed at system level, SERMA Safety & Security has developed a one-stop comprehensive offer incorporating Expertise, Evaluation,Consultancy and Training , covering hardware, software and information systems.

Created in 2015, SERMA Safety & Security, known as S3, is renowned for its expertise in the field of safety and security - the result of over 20 years' experience:

> The security lab, created in 1998 , which carries out several hundred security evaluations each year in France and abroad (ranging from electronic chips to the full electronic system)
> A specialised business line devoted to Consultancy, Training and Expertise, carried over from Surlog and OPALE Security, two firms that have since been integrated into the company


The company provides support to every sector and application cases for which data confidentiality, assets protection, service security, service availability & integrity, operations safety, etc. are of prime importance. Typical applications as embedded and connected systems, product and industrial security, internet of things, information systems are the kind of subjects that SERMA experts are accustomed to manage.

SERMA's offer is organized with the following activities:

> Security formal evaluation, provided by a security laboratory licensed by the French ANSSI security agency
> Security expertize and consulting
> Safety expertize and consulting


WE ARE HIRING !
Do you want to find out more about our business lines? Our projects? The benefits of being part of SERMA?
Get in touch with our employees on LinkedIn or contact us!

Listed Jobs

Company background Company brand
Company Name
SERMA SAFETY & SECURITY
Job Title
Ingénieur Build SOC H/F - (KSC/PSC/102025)
Job Description
**Job Title:** SOC Build Engineer **Role Summary:** Build and optimize SOC environments using SPLUNK and FireEye IDS technologies for a cybersecurity-focused organization. Focus on integration, automation, and advanced threat detection. **Expectations:** - Minimum of 3 years in SOC build/run environments. - Advanced proficiency in SPLUNK (integrating, administering, and developing use cases). - Strong technical expertise in FireEye IDS sensor deployment and management. **Key Responsibilities:** - Design, implement, and maintain SPLUNK-based monitoring and detection solutions. - Deploy and configure IDS/IPS sensors (primary: FireEye). - Develop and refine SOC use cases, dashboards, and correlation rules for threat detection. - Automate data collection, analysis workflows, and SOC operational processes. - Collaborate with operations teams to enhance monitoring efficiency. - Create technical documentation and transfer knowledge to stakeholders. **Required Skills:** - Advanced SPLUNK integration, administration, and development. - FireEye IDS sensor expertise. - Network protocols and cybersecurity frameworks (ISO 27001, NIST, EBIOS). - Technical documentation and cross-team collaboration. - Cybersecurity threat analysis and automation tools proficiency. **Required Education & Certifications:** - Bachelor’s or master’s degree in computer science, information security, or related field. - SPLUNK certifications (e.g., SPLK-3001) or equivalent experience. - FireEye sensor or SOC-focused certifications beneficial. - Familiarity with cybersecurity standards (ISO 27001, NIST) preferred.
Toulouse, France
On site
Senior
26-09-2025
Company background Company brand
Company Name
SERMA SAFETY & SECURITY
Job Title
Expert sécurité cloud GCP (H/F) - (KSC/PSC/102025)
Job Description
Job title: GCP Cloud Security Expert (M/F) Role Summary: Provide advanced security consulting for a major banking client transitioning to Google Cloud Platform. Evaluate, design, and implement security controls for GCP services, ensuring compliance with regulatory standards and best practices. Expectations: - Demonstrate deep expertise in GCP security architecture and operations. - Exhibit strong analytical, autonomous, and proactive problem‑solving skills. - Communicate effectively in professional English and collaborate cross‑functionally. Key Responsibilities: - Assess current GCP security architecture, focusing on data projects. - Analyze evolving GCP services (e.g., Private Service Connect) and recommend tailored solutions. - Identify vulnerabilities in Vertex AI, Workflows, Dataflow, Apigee, GKE, Composer, and other services. - Draft and implement security recommendations, integrating controls into tools such as CSMP. - Participate in internal and external audits, contributing to compliance readiness. - Mentor and support engineering teams on secure GCP practices. Required Skills: - Expert level GCP security (IAM, Identity, Networking, Logging, Monitoring). - Strong network security knowledge (firewalls, proxies, NSGs, WAFs). - Proficiency in Terraform and Python for infrastructure automation. - Experience with GCP security best practices in regulated/banking environments. - Professional English communication skills. Required Education & Certifications: - Bachelor’s or Master’s degree in Computer Science, Information Security, or related field. - GCP Professional Cloud Security Engineer certification or equivalent preferred. - Additional security certifications (e.g., CISSP, CISM) are advantageous.
Île-de-france, France
Hybrid
Senior
17-10-2025
Company background Company brand
Company Name
SERMA SAFETY & SECURITY
Job Title
Consultant cybersécurité des systèmes embarqués (KSC/IEC/112025)
Job Description
**Job title**: Embedded Systems Cybersecurity Consultant **Role Summary** Provide expert assessment and mitigation of cybersecurity risks for embedded and industrial control systems. Apply industry‑recognised risk‑analysis frameworks and standards to ensure compliance and resilience across automotive, aerospace, IoT, and industrial sectors. Collaborate with engineering teams to embed security throughout the development lifecycle. **Expectations** - Deliver comprehensive risk assessments and actionable security recommendations on a project basis. - Maintain up‑to‑date knowledge of evolving cybersecurity standards and regulations. - Operate independently while effectively coordinating with cross‑functional technical teams. **Key Responsibilities** - Conduct security risk evaluations using methodologies such as EBIOS 2010, EBIOS RM, and TARA. - Propose and validate security controls aligned with ISO 21434, IEC 62443, UN R155, NIST frameworks, and other relevant references. - Enable continuous improvement of embedded system security posture by integrating best‑practice solutions. - Advise stakeholders on security requirements, compliance status, and mitigation strategies. - Support diverse industry clients, tailoring security insights to specific domain needs (automotive, aerospace, IoT, industrial). **Required Skills** - Proven experience in embedded systems security risk analysis. - Deep familiarity with ISO 21434, IEC 62443, UN R155, NIST, and related standards. - Proficiency with risk assessment tools and methodologies (EBIOS, TARA). - Strong analytical, problem‑solving, and communication abilities. - Ability to work autonomously and collaboratively in multidisciplinary teams. **Required Education & Certifications** - Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Electrical Engineering, or related field. - Relevant cybersecurity certifications (e.g., ISO 21434 Lead Implementer, CISSP, CISM, or equivalent). - Optional: additional certifications in embedded systems design or specific industry standards.
Île-de-france, France
On site
Senior
30-10-2025
Company background Company brand
Company Name
SERMA SAFETY & SECURITY
Job Title
AMOA IAM (H/F) - (KSC/PSC/112025)
Job Description
Job Title: IAM PMO Assistant (Assistant Project Manager – IAM) **Role Summary** Support the operation of privileged account authorizations through the IAM platform IDENT‑IT, including profile modelling, documentation, testing, coordination with the IAM team, and ongoing maintenance. Manage privileged account lifecycle, tool updates, user training, incident resolution, and technology watch to ensure secure and compliant access management. **Expectations** - Deliver accurate modelling of privileged profiles and related authorisations. - Maintain up‑to‑date technical documentation and procedures. - Conduct test‑case writing and acceptance testing. - Prioritise and adapt IAM tooling (Sailpoint/IDENT‑IT) to evolving requirements. - Provide stable, operational support for security infrastructure. - Keep abreast of IAM security trends and best practices. **Key Responsibilities** 1. Model and document privileged user profiles on IDENT‑IT. 2. Gather client requirements and translate them into technical specifications. 3. Draft test cases, execute tests, and perform acceptance reviews. 4. Coordinate with the IAM department and other stakeholders. 5. Oversee privileged account request, review, and lifecycle management. 6. Adapt and optimise the Sailpoint IAM tool for privileged accounts. 7. Classify and manage technical accounts’ privilege levels. 8. Train users, application owners, and security personnel on IDENT‑IT. 9. Ensure continuous operation of the IAM tool and associated security infrastructure. 10. Resolve incidents, troubleshoot issues, and perform configuration updates. 11. Conduct ongoing technology and threat intelligence surveillance. **Required Skills** - Proven experience in IAM security, especially privileged account management. - Proficiency in scripting/programming (e.g., PowerShell, Python, Bash). - Strong communication, problem‑solving, and risk‑analysis abilities. - Team collaboration and independent work capability. - Excellent organisational skills and attention to detail. - Curiosity and commitment to continuous learning in IAM and cybersecurity. **Required Education & Certifications** - Degree from an engineering school or university in Computer Science, Information Systems, or Information Security. - Relevant certifications preferred: CISSP, CISM, CBK, or IAM‑specific (e.g., Identity Management Professional).
Toulouse, France
Hybrid
Senior
30-10-2025