- Company Name
- SECURINFOR
- Job Title
- Consultant cybersécurité – Projet & Run
- Job Description
-
Job title: Cybersecurity Consultant – Projects & Run
Role Summary:
Provide security expertise across operational and project domains: manage DLP, SOC/CTI incidents, phishing campaigns, vulnerability scans, and Red Team activities; lead security governance initiatives, update PSSI, align controls to NIST CSF 2.0 & NIST 800‑53 rev 5; embed security into IT projects; oversee third‑party security assessments; manage security projects, reporting, and stakeholder communication.
Expactations:
- Drive continuous improvement of security posture within the organization.
- Serve as a bridge between IT, business units, and external partners.
- Deliver clear, actionable insights and recommendations to senior leadership and investors.
Key Responsibilities:
- Operate DLP (Microsoft Purview), SOC, and CTI for incident detection and response.
- Conduct phishing simulations and user awareness programs.
- Monitor Red Team and penetration testing results; manage vulnerability remediation via Qualys VMDR/WAS and BoardOfCyber.
- Contribute to change‑management security reviews (openings of new flows, applications).
- Update and evolve the PSSI and related policies; implement NIST‑aligned controls.
- Design KPIs and dashboards for security performance.
- Integrate security controls into project lifecycles (ISP).
- Evaluate third‑party security (PAS, contract clauses, pre‑qualification).
- Coordinate with IT, business units, and external stakeholders.
- Lead security project planning, budgeting, resource allocation, and execution.
- Facilitate steering committees, deliver reports, and communicate findings to diverse audiences.
Required Skills:
- DLP, SOC, CTI, phishing, user awareness, Red Team, Pen‑Test, Qualys, BoardOfCyber.
- Security governance (PSSI), NIST CSF 2.0, NIST 800‑53 rev 5.
- Project management, risk assessment, stakeholder engagement.
- Strong written French communication; presentation skills for technical and non‑technical audiences.
- Critical thinking, results orientation, teamwork.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Professional certifications such as CISSP, CISM, CEH, or equivalent preferred.