- Company Name
- Groupe iliad
- Job Title
- Architecte Cyber Sécurité - Paris - H/F
- Job Description
-
**Job Title:** Cyber Security Architect
**Role Summary:**
Provide strategic security architecture across all projects, embedding a Secure‑by‑Design approach within an environment governed by ISO 27001 and NIS2. Act as a senior security advisor and deliverable owner, ensuring that security controls are integrated from concept to deployment while aligning with business objectives and operational constraints.
**Expectations:**
- Develop and maintain a comprehensive Secure‑by‑Design methodology, including principles, processes, tools, and documentation.
- Lead security architecture for technical and business projects, advising project teams on risk mitigation and secure design.
- Drive continuous improvement of project security maturity, establishing metrics and reporting frameworks.
- Champion security culture across cross‑functional teams, facilitating governance, training, and stakeholder engagement.
**Key Responsibilities:**
- Define and document the Secure‑by‑Design framework, security requirements grids per project type (infrastructure, application, cloud, data).
- Deliver security architecture reviews, threat modeling, and risk assessments for high‑impact projects.
- Recommend and prototype secure solutions in cloud, IAM, networking, APIs, vulnerability management, and containerized environments.
- Monitor critical projects, track security KPIs, identify compliance gaps, and propose remediation or tooling enhancements.
- Lead security outreach initiatives, coordinate security champions, and deliver communication to project & product teams.
- Collaborate closely with SOC/CSIRT, IT, and functional heads to align defensive posture with project timelines.
**Required Skills:**
- Deep expertise in security architecture for SaaS, IaaS, on‑prem, networking, IAM, and data protection.
- Proven knowledge of ISO 27001, NIST, OWASP, EBIOS RM standards and frameworks.
- Strong background in DevSecOps: Python, secure CI/CD pipelines, automation, and tooling integration.
- Hands‑on experience with Windows/Linux system administration, Microsoft 365 security, and Kubernetes container security.
- Excellent written and verbal communication skills for technical documentation and stakeholder engagement.
- Demonstrated ability to lead cross‑functional initiatives and translate security concepts to non‑technical audiences.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (minimum).
- 7–10 years of experience in cybersecurity, with at least 3 years focused on security architecture.
- Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, or equivalent are strongly preferred.
- Proficiency in French required; professional technical English competency essential.