Find your next tech and IT Job or contract ISO 27001

Your search returns 86 results.
Contractor
Permanent

Job VacancyAppSec & DevSecOps Senior H/F

ALLEGIS GROUP
Published on
DevOps
Web Application Firewall (WAF)

3 months
Paris, France
Le consultant interviendra notamment sur : Sécurité applicative Réalisation des analyses de risques SSI. Accompagnement sécurité des projets et évolutions applicatives. Participation aux phases de cadrage, conception et développement. DevSecOps Animation de la démarche DevSecOps. Sensibilisation des développeurs aux bonnes pratiques de développement sécurisé. Promotion de l'adoption des outils de sécurité dans les pipelines CI/CD. Veille sécurité et diffusion des bonnes pratiques. Pilotage des vulnérabilités Gestion des vulnérabilités applicatives. Suivi des plans de remédiation. Reporting auprès des parties prenantes. Organisation et suivi des audits et pentests. Gouvernance Participation aux PI Planning. Participation aux Roadmaps Produits. Présence aux comités d'arbitrage. Contribution à la feuille de route AppSec / DevSecOps. Environnement Technique Technologies principales Java Cloud (AWS, Azure, On-Premise) CI/CD Outils Snyk SonarCloud SonarQube Outils SAST / SCA Référentiels OWASP ANSSI ISO 27001 L'environnement se caractérise par : Une forte maturité Cloud et CI/CD. Une organisation Agile à l'échelle avec participation aux PI Planning. Une dimension importante de gouvernance, d'acculturation et de pilotage. Un périmètre d'environ 5 produits majeurs. De nombreux projets autour de l'IA.
View this job
Contractor
Permanent

Job VacancyArchitecte Solution - Finance/AML

VISIAN
Published on
Apache Kafka
AWS Cloud
DevOps

1 year
Paris, France
MissionsAlignement stratégique & métier • Définition de la vision de la solution : traduction des objectifs business en un périmètre de définition de la trajectoire architecturale (court et long terme). • Compréhension des objectifs métier : collaboration avec les Product Owners, Business Analysts et la Direction pour le recueil des exigences fonctionnelles et non fonctionnelles, des indicateurs clés (KPIs) et des attentes de ROI. • Identification des opportunités : identification des lacunes, des technologies émergentes et des axes d'innovation susceptibles de créer un avantage concurrentiel ou des gains d'efficacité. Conception et architecture de la solution • Contribution à la conception du blueprint : élaboration de modèles logiques, physiques et de données, des schémas d'intégration, des modèles de sécurité et des topologies de déploiement. • Choix technologique : évaluation et recommandation de plateformes, frameworks, services (on prem, cloud, hybride) en fonction de la pertinence fonctionnelle, du coût, de la scalabilité, de la conformité et du risque de verrouillage propriétaire. • Définition des standards : établissement et garantie du respect des normes, des architectures de référence, des bonnes pratiques et des politiques de gouvernance technique. Expertise technique & collaboration transversale • Travail en équipe multidisciplinaire : collaboration étroite avec les développeurs, DevOps, QA, ingénieurs data, designers UX/UI et les équipes d'exploitation tout au long du cycle de vie du projet. • PoC & prototypage : pilotage des preuves de concept afin de la validation des hypothèses, du test de la viabilité technologique et l'atténuation des risques critiques. • Soutien technique aux équipes : accompagnement des équipes de développement sur les principes d'architecture, les patterns de conception et les standards de qualité ; promotion d'une culture d'apprentissage continu. Pilotage de la mise en œuvre • Suivi de la livraison : apport d'un soutien technique pendant les phases de réalisation pour la garantie du respect de l'architecture définie, des objectifs de performance et des exigences de sécurité. • Résolution d'incidents : rôle de point d'escalade pour les problèmes techniques complexes, contribution à l'établissement de la cause des incidents de productions et proposition d'actions correctives. • Gestion du changement : évaluation de l'impact des demandes de modification, mise à jour des artefacts architecturaux et coordination avec les instances de contrôle des changements. Gouvernance, sécurité et conformité • Gestion des risques : identification des risques architecturaux (sécurité, confidentialité, scalabilité…) et conception de stratégies d'atténuation. • Conformité réglementaire : garantie du respect du GAFI, FATF, 5-AMLD, EU AML D, US-Patriot Act, RGPD, ISO-27001, etc. Intégration des exigences de reporting (SAR, CTR) dans les pipelines. • Maintien et mise à jour des supports documentaires : maintien des diagrammes d'architecture (C4, ArchiMate), de la documentation des décisions techniques et rédaction des manuels d'opération et registres de conformité. Performance, suivi et optimisation • Planification de capacité : modélisation et prévision de l'usage des ressources ; conception d'architectures évolutives. • Stratégie d'observabilité : définition des métriques, logs, traces et alarmes nécessaires (détection de faux positifs, taux de couverture AML) et techniques (latence de pipeline, taux d'erreur). Implémentation d'un monitoring proactif (PagerDuty, OpsGenie). • Amélioration continue : analyse des données de production, conduite de revues post implémentation et proposition de refontes ou optimisations (répartition de partitions Kafka, redesign du data model, migration vers un set-up serverless).
View this job
Permanent

Job VacancyIT Operations Platforms and Security Lead

Nexus Jobs Limited
Published on

£85k-100k
London, England, United Kingdom
IT Operations Platforms and Security Lead This role requires excellent management of a small team in IT along with managing stakeholders and vendors. You must be hands-on technically in IT Infrastructure. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third-party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third-party vendors to deliver a high-quality Global IT services. Working in line with the Architecture defined IT principle of a "buy before build" environment, the individual will need to ensure that outsourced and cloud-based services are robust, cost-effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero-trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud-first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge, Microsoft AD (Entra), Server and SQL experience, O365 administration and design Global Software Patching and estate management via Intune Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience Software Defined Networking (Cisco, Meraki, Versa) Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD-WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL-based service management, automating operational tasks, and optimising service delivery. Operational & Leadership Skills: IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third-party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost-effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Soft Skills & Mindset: Problem-Solving & Decision-Making: Capable of making informed decisions and resolving complex IT issues in a fast-paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non-technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security-first approach. Summary of Skills Required: Global Enterprise level Infrastructure Management position for the last 5 years, Global team management (human resources, strategic delivery, operational service, audit lead for Infra, budget..) Key - 3 party operational infrastructure vendor management - i.e management of managed service partners, Migration of Legacy VM based estates to SaaS and Cloud services platforms, Legacy tech to Azure knowledge/experience, Prior to the last 5 years, a technical infrastructure engineering level background, working on Windows Server, AD , SQL environments, Firewalls/SDWAN, and Networks (WAN &/or LAN). The Client is based in the City of London. This is a hybrid position with 3 days in the office. The salary for this role will be in the range £85K - £100K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
View this job
Permanent

Job VacancyIT Operations and Security Lead

Nexus Jobs Limited
Published on

£85k-95k
London, England, United Kingdom
IT Operations Platforms and Security Lead In summary the Client is looking to recruit an all-round individual with expert knowledge and hands-on experience of IT Infrastructure coupled with Security, Compliance & Risk Management You must have upwards of 10 years hands-on expertise in IT Infrastructure combined with Security and Risk – ideally from within the banking or insurance sector. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third-party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third-party vendors to deliver a high-quality Global IT services. Working in line with the Architecture defined IT principle of a "buy before build" environment, the individual will need to ensure that outsourced and cloud-based services are robust, cost-effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity of the estate, current transformation activities and team size, the role requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles/services as a requirement, across multiple technical areas. Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero-trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud-first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge, Microsoft AD (Entra), Server and SQL experience, O365 administration and design Global Software Patching and estate management via Intune Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience Software Defined Networking (Cisco, Meraki, Versa) Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD-WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL-based service management, automating operational tasks, and optimising service delivery. Operational & Leadership Skills: IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third-party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost-effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Skills & Mindset: Problem-Solving & Decision-Making: Capable of making informed decisions and resolving complex IT issues in a fast-paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non-technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security-first approach. The Client is a financial organisation based in the City of London. This is a hybrid position with 3 days in the office. Must have a Bachelor's degree in IT or similar. The salary for this role will be in the range £85K - £95K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
View this job
Contractor
Permanent

Job VacancyIngénieur Systèmes, Réseaux, Cybersécurité & Stockage

Gamme solutions
Published on
Storage

1 year
Paris, France
Dans le cadre du renforcement de notre équipe Infrastructure & Production IT, nous recherchons un Ingénieur Systèmes, Réseaux, Cybersécurité & Stockage pour intervenir sur des environnements critiques liés à la production audiovisuelle, la postproduction et au stockage média haute disponibilité. 🎯 Missions🔐 Cybersécurité Administration et évolution des solutions de sécurité : Firewalls, IDS/IPS, EDR/XDR, antivirus, SIEM. Gestion des accès, MFA et sécurisation des flux. Analyse et traitement des incidents de sécurité en collaboration avec les équipes SOC. Gestion des vulnérabilités, patch management et plans de remédiation. Hardening et amélioration continue du niveau de sécurité des infrastructures. 🛡️ Gouvernance & conformité Contribution aux démarches ISO 27001, TPN et SMSI. Participation aux audits internes, externes et clients. Mise en œuvre et amélioration des politiques et procédures de sécurité. 💻 Systèmes & Infrastructure Administration des environnements Windows Server et Linux. Administration et évolution des infrastructures VMware et Hyper-V. Supervision, sauvegarde et maintien en condition opérationnelle des infrastructures critiques. Automatisation et industrialisation des tâches d'administration. 💾 Stockage & infrastructures média Administration d'environnements de stockage haute performance. Expertise attendue sur Dell EMC PowerScale / Isilon, Avid Nexis, SAN et NAS. Gestion de la performance, réplication, disponibilité et sécurisation des données. Participation aux projets d'évolution des architectures de stockage à forte volumétrie. 🌐 Réseaux & Connectivité Administration des infrastructures LAN/WAN, VLAN, VPN, Wi-Fi et interconnexions multi-sites. Administration du routage, switching, DNS, DHCP et firewalling. Supervision des équipements réseau et résolution des incidents. Conception et évolution des architectures réseau et Datacenter. Mise en place de la segmentation réseau et sécurisation des flux.
View this job

Connecting Tech-Talent

Free-Work, THE platform for all IT professionals.

Free-workers
Resources
About
Recruiters area
2026 © Free-Work / AGSI SAS
Follow us