Cyber Governance Consultant - Cloud Security - Freelance (M/F)
Must-have:CloudSecurityPrincipal
Machine translation — original language: French.Show original
CONTEXT
The client is seeking support services aimed at strengthening the Group's cyber governance work, with a primary focus on IT Continuity, Resilience, Backup & Restore, and Cloud Security themes, as well as the formalization of cyber requirements and procedures applicable to the Group's entities.
MISSIONS
- Drafting, revising, and structuring cyber requirements and Group procedures, particularly on IT Continuity, Resilience, Backup & Restore, and Cloud Security topics
- Support for Cloud Security work, including the interpretation and application of security and continuity requirements in cloud environments, taking into account cloud types, IaaS/PaaS/CaaS/SaaS service models, the shared responsibility model between the Group and Cloud Service Providers, as well as due diligence, reversibility, and compliance issues
- Support for cyber governance: needs analysis, formalization of deliverables, preparation of decision-making materials, and follow-up on actions with stakeholders
- Leading and facilitating workshops in English with Group entities and functions, in order to define expectations, share deliverables, and collect operational feedback
- Contribution to the alignment of requirements with reference frameworks, IT continuity/resilience best practices, Cloud Security, and applicable compliance expectations
WORKING CONDITIONS
- Long-term mission
- Fluent English mandatory, both spoken and written, as all workshops, scoping exchanges, and working documents are primarily conducted in English
- Solid knowledge and proven experience in IT Continuity and IT Resilience
- Mastery of Backup & Restore, including backup strategy principles, restoration, testing, and associated requirements
- Expertise in Cloud Security, including understanding of cloud models, cloud types, shared responsibilities between BNP Paribas / CSP, security requirements applicable to cloud environments, as well as continuity, resilience, backup/restoration, and reversibility issues in a cloud context
- Cyber governance skills, including the drafting of requirements, standards, procedures, and scoping deliverables
- Ability to work with cyber, IT, risk, production, and business entity stakeholders in an international Group environment
- Good understanding of cyber reference frameworks and best practices, without the need to be a technical expert in every field
- Previous experience in building or evolving Group cyber reference frameworks, procedures, or requirements is strongly desired
- Experience with Cloud Security procedures or requirements, particularly regarding the application of cyber requirements to IaaS, PaaS/CaaS, and SaaS environments, is highly appreciated
- Rigor, autonomy, good synthesis skills, and ease in cross-functional coordination
- Fluent English mandatory, both spoken and written