VOC/GRC Security Consultant M/F [P100525]
Nomios, a key player in the integration of security and network infrastructures, offers its clients tailor-made solutions regarding: audit and consulting, integration, support, managed services, SOC, GRC, long-term support, and training. Distributed across the entire national territory, Nomios ensures proximity and quality service to its clients. As part of the development of our VOC/GRC Business Unit, we are looking for a Security Consultant M/F to support our clients in strengthening their cybersecurity posture, both in operational and governance aspects. You will intervene in two complementary areas of expertise: Vulnerability Operations Center (VOC) and Governance, Risk & Compliance (GRC).
Your missions VOC Service Delivery Management (SDM) Guarantee compliance with contractual commitments to clients.
Ensure the follow-up of the remediation of identified vulnerabilities.
Analyze vulnerability scan results and formulate recommendations adapted to client contexts.
Support client teams in the continuous improvement of their security level.
Production of deliverables Prepare and lead project committees (COPROJ) with clients.
Produce monitoring and steering deliverables.
Write activity reports and summaries.
Ensure regular reporting on security indicators and action plans.
GRC Awareness and support Design and deploy cybersecurity awareness tools.
Lead phishing campaigns and analyze the results.
Support clients on consulting, acculturation, and training topics.
Participate in pre-sales activities and responses to calls for tender (RAO). Assessment and consulting Perform audits regarding data processing and attack techniques applicable to SOC environments.
Evaluate the maturity of security arrangements.
Write audit reports and recommendations concerning: security tools,
SOC activities,
information security policies and procedures,
cybersecurity best practices.
Crisis Management
- Development of processes and procedures, reflex sheets
- Conducting crisis exercises
- Integration of crisis management tools
Support clients in the definition and improvement of their security governance.
Profile sought With a higher education background in cybersecurity, IT, or risk management, you have at least 5 years of experience in similar roles. You are recognized for your analytical spirit, your interpersonal skills, and your ability to operate in demanding client environments.
Expected technical skills Vulnerability management and vulnerability scans.
Awareness and conducting phishing campaigns.
External Attack Surface Management (EASM).
Business Impact Analysis (BIA).
Awareness and phishing tools
MITRE ATT&CK Framework.
Qualities sought English B2 minimum
Excellent customer service sense.
Ability to popularize technical subjects.
Writing rigor.
Autonomy and initiative.
Ability to lead meetings and drive cross-functional actions.
Why join us? Varied missions combining technical expertise, consulting, and governance.
A stimulating environment at the heart of cybersecurity challenges.
Strong proximity to clients and expert teams.
Opportunities for evolution and skill development.
Do you want to actively contribute to securing our clients' information systems and participate in their maturity increase? Join us! Our values: Sébastien KHER, our CEO, has been developing his company since 2004, relying on mutual trust, autonomy, and listening to his employees, but also on good humor and the pleasure of sharing. Above all, we are looking for a candidate who shares our values: professionalism, flexibility, and benevolence. </body>