- Company Name
- Apave
- Job Title
- Auditeur - Responsable d'Audit Cybersécurité H/F
- Job Description
-
**Job title**
Cybersecurity Audit Manager (ISO 27001 Lead Auditor)
**Role Summary**
Lead and conduct cybersecurity audits for clients to validate compliance with ISO 27001 and related standards. Drive continuous improvement of security processes, manage client relationships, and deliver audit findings and recommendations.
**Expectations**
• 8+ years of cybersecurity audit experience, preferably in certification contexts.
• Demonstrated expertise in ISO 27001, ISO 27005, ISO 17065, ISO 17021‑1, ISO 27006, ISO 19011, and related regulatory frameworks (RGPD, eIDAS, LPM, etc.).
• Strong written and oral communication, leadership, and project‑management skills.
• B2 level English; French preferred but not mandatory.
• Ability to travel within France as required.
**Key Responsibilities**
1. Plan, execute, and close ISO 27001 audits for client organizations, ensuring alignment with industry best practices.
2. Prepare audit plans, questionnaires, and reports; present findings to client stakeholders.
3. Advise clients on remediation actions, risk treatment, and control implementation.
4. Maintain up‑to‑date knowledge of emerging cyber threats, regulatory changes, and certification schemas.
5. Foster strong client relationships, manage expectations, and support business development activities.
6. Mentor junior auditors and contribute to internal audit methodology improvements.
7. Coordinate with cross‑functional teams to integrate audit recommendations into broader security programs.
**Required Skills**
- Technical: ISO 27001/27005/17065/17021‑1/27006/19011 knowledge, cyber‑security governance, risk management, audit tools, security architecture assessment.
- Regulatory: RGPD, eIDAS, LPM, IGI‑1300, II‑901, RGS, etc.
- Behavioral: Excellent writing and presentation, leadership, client‑facing communication, teamwork, project management, analytical thinking, adaptability, and rigor.
- Commercial: Ability to manage client engagement and support sales cycles.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or related field.
- Lead Auditor or Lead Implementer ISO 27001 (mandatory) and ISO 27005 (preferred).
- Additional certifications such as ISO 19011, ISO 27006, or sector‑specific (e.g., eIDAS, SecNumCloud) are advantageous.