Architecture & CRA Compliance Services / Cybersecurity - Freelance (M/F)
Must-have:Security
Machine translation — original language: French.Show original
Daily rate (TJM): 545
Context:
As part of industrial projects in pharmaceutical and regulated environments, our client is looking for expertise in OT (Operational Technology) cybersecurity architecture and compliance with the Cyber Resilience Act (CRA). The mission aims to support project teams in the definition, evaluation, and implementation of cybersecurity requirements applicable to industrial systems, while ensuring alignment with the sector's regulatory constraints.
A hybrid organization is possible with up to 12 days of remote work per month depending on project needs.
2. Missions:
The consultant will specifically work on the following activities:
- Evaluate Cyber Resilience Act (CRA) requirements and identify compliance gaps.
- Define and evolve OT reference architectures:
- Purdue Model
- Segmentation into zones and conduits
- Industrial DMZ
- Perform cybersecurity risk analyses and threat modeling exercises.
- Provide expertise on Secure Software Development Lifecycle (Secure SDLC) practices and the definition of security frameworks.
- Support regulatory compliance activities related to pharmaceutical environments:
- GMP (Good Manufacturing Practices)
- FDA 21 CFR Part 11
- Advise on vulnerability management processes and preparation for regulatory audits.
- Participate in the definition and implementation of cybersecurity controls applicable to industrial systems.
Duration: 18 months
Experience:
- Engineer with 5 to 10 years of experience.
- Ideally 8 years of experience in industrial systems cybersecurity (ICS/OT).
- Ideally 3 years of experience within suppliers or companies in the pharmaceutical sector or highly regulated industries.
Technical Skills:
- Expertise in OT and ICS cybersecurity.
- Solid mastery of secure industrial architectures.
- Experience implementing IEC 62443 security controls.
- Good knowledge of regulatory requirements related to CRA, GMP, and FDA 21 CFR Part 11.
- Skills in vulnerability management, risk analysis, and threat modeling.
- Knowledge of Secure SDLC best practices.
Languages:
- Professional English, minimum B2 level.
Preferred Certifications:
- IEC 62443 Cybersecurity Expert
- GICSP
- CISSP or equivalent