IT/Cyber Risk Analyst - Technical Focus - Freelance (M/F)
This job is no longer listed
The source has removed this listing — applying via the original link is no longer possible.
Must-have:VueCloudSecurity
Machine translation — original language: French.Show original
CONTEXT
As part of strengthening a CISO team within a large financial group, we are looking for a consultant capable of conducting risk analyses while providing a real technical understanding of the studied environments. This is not a position exclusively oriented towards governance or compliance.
An initial training phase on internal practices and shadowing of approximately one month is planned.
Profiles primarily oriented towards governance, compliance, or steering, without significant technical experience, do not meet the requirement.
MISSIONS
- Perform risk analyses on internal applications, infrastructure components, Cloud environments, and third-party solutions
- Understand and challenge architectures, flows, authentication mechanisms, authorizations, and existing security controls
- Identify vulnerabilities, threat scenarios, impacts, and associated risks
- Evaluate gross and residual risks
- Propose concrete security measures, adapted to the risks and technically feasible
- Organize and facilitate workshops with business, IT, architecture, infrastructure, Cloud, and security teams
- Formalize and manage analyses in the EGERIE tool
- Apply an EBIOS RM type methodology
- Monitor progress, blockers, and validations with the ISP coordination manager
TOOLS & ENVIRONMENT
- Cybersecurity
- EBIOS RM methodology
- EGERIE tool
- Application architectures, infrastructures, networks, IAM, API, flows, Cloud environments, and SaaS solutions
WORKING CONDITIONS
- Mission location: Paris
- Start date: ASAP
- 2 days of remote work per week
- Professional English mandatory
- Required seniority: minimum 8 to 10 years of experience in performing end-to-end IT/cyber risk analyses
- Remuneration according to profile
- Minimum 8 to 10 years of experience in performing end-to-end IT/cyber risk analyses
- Strong technical culture in information systems security
- Good understanding of application architectures, infrastructures, networks, IAM, API, flows, Cloud environments, and SaaS solutions
- Ability to analyze existing security measures and identify their limitations
- Minimum 8 years of experience with ICT provider and third-party risks
- Mastery of EBIOS RM
- Operational knowledge of EGERIE is highly appreciated
- Ability to communicate with both technical teams and business stakeholders
- Writing skills, analytical mindset, autonomy, and ability to manage multiple subjects simultaneously