Find your next tech and IT Job or contract NIST

Your search returns 15 results.
Premium Job
Contractor

Contractor job
Information Security Manager with Network Engineering Skills

Nexus Jobs Limited
Published on
Cisco
CISSP
Data governance

3 months
£500-650
W1A 1AA, London, England, United Kingdom
Information Security Manager with Network Engineering Skills Our Client is a bank based in Central London who are looking to recruit a seasoned professional with at least 7 to 10 years expertise level Information Security coupled with Hands-on Network Engineering. The role is mainly Information Security – Data Security and split circa 80% with 20% Network Engineering – so you do need to be hands-on technically. You will ideally have circa 5+ years of work experience with Network Engineering coupled with over 10 years experience with Cisco Systems Products Role Description The Information Security Manager with Network Engineering Skills is a full-time hybrid role based in London, with the flexibility to work from home part of the week. The role oversees the design, implementation, and continuous improvement of information security policies, procedures, and controls across networks and systems. Day-to-day responsibilities include managing the Information Security Management System (ISMS), monitoring cybersecurity and network security events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this role will collaborate with IT and business stakeholders to assess risks, implement technical and procedural safeguards, and support secure network architecture and configuration. Additional tasks include producing security documentation, leading security awareness initiatives, and providing guidance on secure network engineering practices. Qualifications · Strong skills in Information Security Management and Information Security, with experience defining and enforcing security policies and governance. · Hands-on expertise with Information Security Management Systems (ISMS), including implementation, maintenance, and audit readiness. · Proficiency in Cybersecurity and Network Security, covering threat detection, vulnerability management, network hardening, and incident response. · Demonstrated network engineering experience (eg, routing, switching, firewalls, VPNs, secure network design). · Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, or similar are beneficial. · Experience with regulatory and compliance frameworks (eg, ISO 27001, GDPR, NIST) and security best practices. · Ability to analyze complex technical environments, communicate clearly with both technical and non-technical stakeholders, and document security requirements and processes. · Bachelor's degree in computer science, information security, engineering, or a related field, or equivalent professional experience. Key Networking Skills Required: Cisco Network Switches Layer 2 and 3 (Catalyst 9K) – CCNP Level, Expert Level Preferred Routing protocol – OSPF (Catalyst 9K) – CCNP Level, Expert Level Preferred Cisco Switch Stacking (Cat 9K Switches 9600, 9300. 9200) Virtual Routing and Forwarding – (Catalyst 9600) Internetworking Troubleshooting - CCNP Level, Expert Level Preferred High Availability and Disaster Recovery - CCNP Level, Expert Level Preferred Security/Cyber ​​​​Security Skills Required: Cisco Firepower Firewalls (ASA, FTD) - CCNP Level, Expert Level Preferred Palo Alto Firewalls – Specialist Level, Architect Level Preferred Cisco Layer 2 Port Security Network Access Control including Cisco ISE, TACACS etc. Network Detection and Response Network Encryption (Site to Site VPN's) Cisco Secure Client (ASA) Network IPS (Trellix) Network Zero Day (Trellix NX or similar) Host Zero Day (Trellix HX or similar) Cyber ​​Security Network Control Incident Investigation with the assistance of group cyber security experts – Tier 1, Tier 2 to 3 preferred, using LogRhythm SIEM a bonus Host End Point Protection (Symantec) Host IPS Preferred Skills and Knowledge Vulnerability Management (Scanning for Vulnerabilities and classifying the risk, CIS Benchmark Scanning and compliance) – Using Rapid7 a bonus Knowledge of Penetration Testing, understanding of the types of testing and their advantages and disadvantages Security Zone Design and considerations Network and Security Architecture Design and Considerations Understanding of Information Security (Confidentiality, Integrity, Availability), MITER ATT&CK, NIST, ISO 27001, SIEM use cases for key controls etc Risk Management in Cyber ​​Security, SSL Blind spots, what causes them and how to mitigate Malware/Ransomware and how to mitigate along with Penetration testing concepts Understanding of White/Black/Grey Box penetration testing. Developing Security policies and procedures and conducting audits/risk assessments Handling crisis situations during security incidents The role is hybrid 3 days in the office in Central London. The rate for this role will be in the range £500 pd to £650 pd. This is a 3-month assignment. Do send your CV to us in Word format along with your salary and notice period.
View this job
Premium Job
Permanent

Job Vacancy
Information Security Manager with Network Engineering Skills

Nexus Jobs Limited
Published on
Cisco
CISSP
Cybersecurity

£85k-100k
W1A 1AA, London, England, United Kingdom
Information Security Manager with Network Engineering Skills Our Client is a bank based in Central London who are looking to recruit a seasoned professional with at least 7 to 10 years expertise level Information Security coupled with Hands-on Network Engineering. The role is mainly Information Security – Data Security and split circa 80% with 20% Network Engineering – so you do need to be hands-on technically. You will ideally have circa 5+ years of work experience with Network Engineering coupled with over 10 years experience with Cisco Systems Products Role Description The Information Security Manager with Network Engineering Skills is a full-time hybrid role based in London, with the flexibility to work from home part of the week. The role oversees the design, implementation, and continuous improvement of information security policies, procedures, and controls across networks and systems. Day-to-day responsibilities include managing the Information Security Management System (ISMS), monitoring cybersecurity and network security events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this role will collaborate with IT and business stakeholders to assess risks, implement technical and procedural safeguards, and support secure network architecture and configuration. Additional tasks include producing security documentation, leading security awareness initiatives, and providing guidance on secure network engineering practices. Qualifications · Strong skills in Information Security Management and Information Security, with experience defining and enforcing security policies and governance. · Hands-on expertise with Information Security Management Systems (ISMS), including implementation, maintenance, and audit readiness. · Proficiency in Cybersecurity and Network Security, covering threat detection, vulnerability management, network hardening, and incident response. · Demonstrated network engineering experience (eg, routing, switching, firewalls, VPNs, secure network design). · Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, or similar are beneficial. · Experience with regulatory and compliance frameworks (eg, ISO 27001, GDPR, NIST) and security best practices. · Ability to analyze complex technical environments, communicate clearly with both technical and non-technical stakeholders, and document security requirements and processes. · Bachelor's degree in computer science, information security, engineering, or a related field, or equivalent professional experience. Key Networking Skills Required: Cisco Network Switches Layer 2 and 3 (Catalyst 9K) – CCNP Level, Expert Level Preferred Routing protocol – OSPF (Catalyst 9K) – CCNP Level, Expert Level Preferred Cisco Switch Stacking (Cat 9K Switches 9600, 9300. 9200) Virtual Routing and Forwarding – (Catalyst 9600) Internetworking Troubleshooting - CCNP Level, Expert Level Preferred High Availability and Disaster Recovery - CCNP Level, Expert Level Preferred Security/Cyber ​​​​Security Skills Required: Cisco Firepower Firewalls (ASA, FTD) - CCNP Level, Expert Level Preferred Palo Alto Firewalls – Specialist Level, Architect Level Preferred Cisco Layer 2 Port Security Network Access Control including Cisco ISE, TACACS etc. Network Detection and Response Network Encryption (Site to Site VPN's) Cisco Secure Client (ASA) Network IPS (Trellix) Network Zero Day (Trellix NX or similar) Host Zero Day (Trellix HX or similar) Cyber ​​Security Network Control Incident Investigation with the assistance of group cyber security experts – Tier 1, Tier 2 to 3 preferred, using LogRhythm SIEM a bonus Host End Point Protection (Symantec) Host IPS Preferred Skills and Knowledge Vulnerability Management (Scanning for Vulnerabilities and classifying the risk, CIS Benchmark Scanning and compliance) – Using Rapid7 a bonus Knowledge of Penetration Testing, understanding of the types of testing and their advantages and disadvantages Security Zone Design and considerations Network and Security Architecture Design and Considerations Understanding of Information Security (Confidentiality, Integrity, Availability), MITER ATT&CK, NIST, ISO 27001, SIEM use cases for key controls etc Risk Management in Cyber ​​Security, SSL Blind spots, what causes them and how to mitigate Malware/Ransomware and how to mitigate along with Penetration testing concepts Understanding of White/Black/Grey Box penetration testing. Developing Security policies and procedures and conducting audits/risk assessments Handling crisis situations during security incidents The role is hybrid 3 days in the office in Central London. The salary for this role will be in the range £85K - £100K + Benefits. Do send your CV to us in Word format along with your salary and notice period.
View this job
Contractor

Contractor job
Security Champion

CAT-AMANIA
Published on
ISO 27001
NIST

1 year
600-700 €
Paris, France
Je suis à la recherche pour un de nos clients d'un Security Chamion. Dans le cadre de la mission, vous rejoindrez le Pôle Accompagnement Projets de l'équipe de Sécurité des SI du Client. Ce pôle est en charge d'accompagner les équipes de la DSI dans l'intégration de la sécurité dans les projets et de réaliser l'évaluation des risques SSI des systèmes d'information du Client sur les périmètres France et International. La DSI a entamé une transformation visant à basculer d'un modèle de gestion projets à un modèle de gestion par produits. A ce titre, l'équipe SSI recherche un profil de type Security Champion pour accompagner le domaine Dommage et contribuer à sa transformation en mode produits qui aura lieu fin 2026/début 2027. Le Security Champion assure l'alignement entre les exigences de sécurité et les réalités métiers. A ce titre, ses principales missions consistent à : - Intégrer les principes de cybersécurité dès la conception des produits et services du domaine selon une approche « security by design ». - Alimenter la roadmap d'évolutions sécurité des produits et services du domaine, en collaboration avec les équipes métier, les équipes architecture et les autres membres de l'équipe SSI. - Fournir, en appui à la prise de décision, une vision contextualisée et consolidée des risques associés aux différents produits et services ou domaine - Servir de point de contact privilégié auprès les équipes de son périmètre en assurant la redirection des demandes de sécurité auprès des interlocuteurs adéquats au sein de l'équipe SSI - Prendre en charge les analyses de risques de son domaine en menant les analyses les plus structurantes et pilotant celles déléguées au Centre de Services Accompagnement Projet. - Contribuer à la définition des nouveaux process de suivi de l'activité SSI du domaine - Contribuer à l'augmentation de la maturité cyber des équipes métier - Réaliser un reporting hebdomadaire de suivi auprès des CISO - Préparer les supports des différents comités effectués avec les équipes de pilotage du domaine et les équipes SSI. - Représenter le CISO auprès du domaine Les livrables attendus lors de cette prestation comprennent : - La réalisation des analyses de risques de son périmètre - La production des roadmap SSI de son domaine - La production et le maintien à jour d'un référentiel des risques de son domaine - La formalisation des nouveaux processus SSI sur son périmètre - Le reporting d'activité de son périmètre - Les supports de présentation des différentes réunions et des différents comités - Les CR des réunions Compétences techniques : - Une expérience dans un rôle de Security Champion ou de RSSI Métier - Bonne maîtrise des concepts de cybersécurité (IAM, réseau, cloud, applicatif) - Connaissance des frameworks (ISO 27001, NIST, CIS…) - Gestion des risques (EBIOS, ISO 27005…) - Compréhension des architectures IT et des environnements métiers Compétences comportementales : - Forte capacité de communication (traduction technique ↔ métier) - Esprit critique et capacité de challenge - Sens du compromis (sécurité vs business) - Leadership d'influence (sans lien hiérarchique direct) - Esprit de synthèse et de formalisation, pragmatique et organisé - Facilitateur des échanges (bon relationnel, bonne élocution) ; ouverture AUTRES : L'expérience dans la banque assurance serait un plus.
View this job
Contractor

Contractor job
Expert(e) Cybersécurité des IA Génératives

ABSIS CONSEIL
Published on
Azure AI
NIST
OWASP

6 months
610-700 €
Ile-de-France, France
Contexte Dans le cadre du renforcement de la sécurité de ses plateformes d'IA générative, notre client, acteur majeur du secteur bancaire et financier, recherche un(e) expert(e) en cybersécurité spécialisé(e) sur les environnements GenAI et l'écosystème Microsoft. Vous interviendrez au sein des équipes en charge de la cybersécurité des données (Cloud, IA, Big Data) pour sécuriser la conception, le déploiement et les usages des solutions d'IA générative, en France et à l'international. Vos missions Assistance sécurité aux centres de compétences sur les sujets GenAI Sécurisation des plateformes GenAI Microsoft (architecture, normes, standards) Production de dossiers de sécurité incluant des analyses de risques détaillées et les contre-mesures associées Revue de sécurité du code des composants développés Support sécurité aux Business Units et Service Units sur les projets GenAI Rédaction des chapitres sécurité des livrables projet (DAT, DAH, HLD, LLD, politiques, standards) Reporting et indicateurs de sécurité Compétences attendues Sécurité opérationnelle sur l'écosystème Microsoft : Microsoft 365, Azure Cognitive Services, Copilot, Fabric, Power Platform, Azure ML, code agentic Maîtrise des risques spécifiques aux LLM et services GenAI : prompt injection, data leakage, model poisoning, et leur évolution dans les cas d'usage agentic Frameworks de menaces IA : OWASP Top 10 LLM, MITRE ATLAS, NIST AI Outils de sécurité opérationnelle : Sentinel, Defender for Cloud, Purview Sécurisation des tenants Azure : RBAC, MFA, Conditional Access, Privileged Identity Management DevSecOps : CI/CD sécurisés, IaC (Terraform, Bicep) Scripting (PowerShell, Python), analyse de logs, automatisation de contrôles de sécurité Conception et déploiement de contrôles de sécurité en environnements IA hybrides
View this job
Contractor
Permanent
Fixed term

Job Vacancy
RSSI externalisé (RSSI as a Service)

R&S TELECOM
Published on
CISSP
EBIOS RM
GDPR

6 months
Meudon, Ile-de-France
Contexte de la mission La filiale du groupe , est un opérateur télécom B2B spécialisé dans les solutions de téléphonie cloud, de connectivité et de communications unifiées pour les entreprises. En tant que RSSI externalisé (RSSI as a Service), vous êtes le référent sécurité de la filiale et vous pilotez l'ensemble de la démarche de sécurité des systèmes d'information en relation avec le RSSI Groupe Objectifs et livrables Gouvernance et stratégie • Définir, formaliser et faire évoluer la politique de sécurité des systèmes d'information (PSSI) • Assurer l'alignement de la stratégie sécurité de Keyyo avec celle du groupe • Élaborer et suivre la feuille de route sécurité . Evaluer la maturité cyber (NIST2) • Assurer un reporting régulier auprès de la direction et du groupe Gestion des risques • Réaliser et maintenir l'analyse de risques (méthode EBIOS RM ou équivalent) • Identifier, évaluer et prioriser les risques cyber • Définir et suivre les plans de traitement et de remédiation Conformité et réglementaire • Garantir la conformité RGPD en lien avec le DPO • Anticiper et intégrer les exigences NIS2 Opérationnel et pilotage • Superviser la gestion des incidents et alertes de sécurité (lien avec le SOC / CERT Groupe) • Piloter les plans d'actions de remédiation suite audit • Encadrer la sécurité dans les projets (Security by Design) . Piloter les projets de transformation en relation avec le RSSI Groupe Sensibilisation • Diffuser la culture cybersécurité auprès des collaborateurs • Animer les actions de formation et de sensibilisation Profil recherché Formation & expérience Formation supérieure Bac+5 (école d'ingénieur, université, cursus spécialisé cybersécurité) Expérience confirmée de 7 ans minimum en cybersécurité, dont une expérience significative en tant que RSSI ou RSSI as a Service Expérience dans le secteur télécom / opérateur appréciée Compétences techniques Maîtrise des normes et référentiels : ISO 27001/27002, EBIOS RM, NIST Bonne connaissance des cadres réglementaires : RGPD, NIS2, réglementation télécom Compréhension des architectures cloud, réseaux et télécoms Connaissance des enjeux de gestion des incidents (SOC, CERT, réponse à incident) Compétences comportementales Leadership et capacité à embarquer les équipes Excellentes qualités de communication et de vulgarisation Vision stratégique et sens du business Autonomie, rigueur et capacité d'adaptation à un environnement de régie Certifications appréciées CISSP, CISM, ISO 27001 Lead Implementer / Lead Auditor, EBIOS RM
View this job
Contractor
Permanent

Job Vacancy
Consultant(e) en Gouvernance Risque et Conformité (GRC)

iDNA
Published on
Cybersecurity
DORA
Governance

6 months
60k-65k €
500-550 €
Ile-de-France, France
Nous recherchons pour le compte de notre client un(e) Consultant(e) en Gouvernance Risque et Conformité (GRC). Vous aurez un rôle clé dans la transformation et le développement des Systèmes d'information au sein du département Sécurité des Systèmes d'Information de notre client. Vous interviendrez à la fois comme correspondant(e) en système d'information et Consultant (e) GRC. A ce titre, la mission consistera à assister le directeur dans la définition de la politique Cyber, à définir un cadre de conformité, à le mettre en œuvre et à piloter son évolution. Le poste implique également la gouvernance des agréments, homologations et audits, la supervision des audits de conformité, la production de Reporting, l'interface avec les partenaires pour la mise en œuvre des procédures d'homologation, ainsi que la contribution à l'amélioration continue des référentiels et procédures. Missions Déploiement de la gouvernance SSI de notre client. Pilotage des processus d'instruction, d'évaluation et de délivrance des agréments et homologations. Supervision des audits de conformité en coordination avec les responsables opérationnels. Contribution à l'amélioration continue des référentiels, procédures, contrôles et outils associés. Préparation des inspections réglementaires et audits (planification, pilotage des prestataires, gestion du budget). Coordination de la collecte des preuves et éléments justificatifs. Référent sur les services supports à la signature électronique et la doctrine des inspections et audits cyber. Vérification des rapports d'audit et pilotage des plans de remédiation. Coordination entre les équipes cybersécurité, IT, métiers et fonctions de contrôle. Assurer la formation les collaborateurs dans une démarche de gouvernance cyber, afin qu'ils deviennent acteurs de la cybersécurité Rédaction et maintien des cahiers des charges relatifs aux agréments et homologations. Production de Reporting et d'indicateurs de suivi des activités d'agrément, d'homologation et d'audit. Veille technologique et réglementaire, gestion des partenariats Avantages & PerspectivesLocalisation : IDF avec une possibilité de distancielDémarrage : dès que possibleRémunération : +/-65K selon profil (Politique d'intéressement en place depuis 2015)
View this job
Contractor

Contractor job
Security consultant Migration CSPM /Anglais courant (H/F)

EXMC
Published on
AWS Cloud
Azure
Center for Internet Security (CIS)

1 year
Paris, France
Afin de soutenir les objectifs métiers et les initiatives de transformation digitale, le client met en place une pratique dédiée à la sécurité de l'information afin d'assurer une réponse coordonnée face à l'augmentation des menaces de cybersécurité dans les environnements Cloud publics. L'approche de sécurité de l'information vise à protéger les parties prenantes en sécurisant les actifs informationnels, en maîtrisant les risques cyber et en permettant la mise en œuvre de stratégies métiers efficaces et efficientes, soutenues par la direction exécutive et déployées à travers les différentes entités. Dans le cadre de cette stratégie, le client a décidé de remplacer la solution existante de Cloud Security Posture Management (CSPM). To support business objectives and digital transformation initiatives, the client is establishing a dedicated information security practice to ensure a coordinated response to the growing cybersecurity threats within Public Cloud environments. The information security approach aims to protect stakeholders by securing information assets, managing cyber risks, and enabling effective and efficient business strategies sponsored by executive leadership and supported across entities. As part of this strategy, the client has decided to replace the existing Cloud Security Posture Management (CSPM) solution. 2. Service Scope (not limited to): The primary objective of this mission is to drive the migration of security policies and the deployment of the new CSPM solution across entities. CSPM deployment phases: Preparation, Execution, Validation, and Run Phase. Description of main activities within the service: • Coordinate with Group Security (Security & Product teams) to ensure controls are correctly migrated and that resulting security scoring is accurate • Coordinate with Cloud product teams and IT stakeholders to ensure the solution's operational usability • Migrate the existing scope covering all Azure and AWS accounts across entities • Provide technical reference and subject-matter expertise related to the CSPM solution • Contribute to the design of operational target processes for run-mode deployment (including onboarding of new public cloud accounts) to ensure adequate risk coverage • Produce comprehensive documentation covering operational processes and transition to run mode
View this job
Contractor

Contractor job
Experts Cybersécurité IA / Azure Security

Comet
Published on
Azure
Cloud
Cybersecurity

210 days
500-650 €
Ile-de-France, France
Bonjour à tous et toutes notamment aux experts Cybersécurité IA / Azure Security 🔐🤖 🔎 Je cherche un/e Expert/e Cybersécurité IA pour rejoindre les équipes d'un grand groupe bancaire international et intervenir sur des sujets stratégiques autour de l'Intelligence Artificielle Générative et du Cloud Azure. Tu intégreras une équipe spécialisée en cybersécurité des données, du Cloud et de l'IA, avec un rôle central dans la sécurisation des plateformes GenAI déployées à l'échelle internationale. 💻 Ce que tu vas faire : Accompagner les projets IA Générative sur les volets cybersécurité Réaliser des analyses de risques et produire les dossiers de sécurité associés Définir et recommander des architectures sécurisées autour des services IA Microsoft Accompagner les équipes de développement et d'exploitation sur les bonnes pratiques de sécurité Participer à la sécurisation des plateformes GenAI utilisées dans des environnements bancaires et industriels Réaliser des revues de sécurité des composants développés Décliner les exigences sécurité dans les User Stories et les projets Contribuer à la définition des standards, normes et contrôles de sécurité Produire les reportings et indicateurs associés aux activités cybersécurité 🎯 Stack technique : Microsoft 365 / Azure Cognitive Services / Azure ML / Fabric / Power Platform / Copilot / Foundry / Bedrock / Sentinel / Defender for Cloud / Purview / Terraform / Bicep / PowerShell / Python / DevSecOps / CI-CD / LangChain / LangGraph 🕵️‍♀️ Profil recherché : Solide expérience en cybersécurité Cloud et Azure Expertise des services Microsoft liés à l'IA et à la donnée Bonne maîtrise des problématiques de sécurité des LLM et de l'IA Générative Connaissance des frameworks OWASP Top 10 LLM, MITRE ATLAS, NIST AI Expérience des environnements DevSecOps Capacité à produire des analyses de risques et recommandations d'architecture Aisance dans des environnements internationaux et anglophones Expérience en environnement Agile 🚀 Les plus de la mission : Sujet au cœur des enjeux actuels de l'IA Générative Forte visibilité auprès des équipes métiers et techniques Interventions sur des plateformes IA de nouvelle génération Contexte international Expertise stratégique et opérationnelle Mission longue durée 📍 IDF : 1 jours de TT 🏡 Qu'en penses-tu ? Une belle journée à tous ☀️
View this job
Contractor

Contractor job
GRC expert cyber

Groupe Aptenia
Published on
Governance, risk and compliance (GRC)
ISO 27001
NIS2

12 months
€500-700
Brussels, Brussels-Capital, Belgium
Strategy & Roadmap You develop and implement a cyber security policy that fits the customer's DNA. You outline clear long-term roadmaps. You translate abstract strategy into tactical action plans and supervise the execution. High-Level Governance You are the sparring partner at C-level and participate in board meetings and risk committees. You set up the security governance (who does what, how do we report?) and ensure cohesion between security, privacy, and business continuity. Risk Management & Compliance You initiate risk analyses (IT, OT, IoT) and make risks understandable for management. You guide customers through the landscape of laws and regulations (such as NIS2) and prepare them for audits and ISO certifications. Management of security incidents & Services In the event of serious incidents, you maintain oversight and calm. You coordinate the crisis communication while our operational teams close the leak. You advise customers on the optimal use of (our) SOC and monitoring services, and other security services. Impact & Communication You increase security awareness within the organisation and present clear reports on risks and maturity. You are the face of security: the central point of contact for all stakeholders. Who are you? You are a bridge builder. You combine in-depth substantive knowledge with the diplomatic skills of a top consultant.
View this job
Permanent
Contractor
Fixed term

Job Vacancy
Expert Cybersécurité H/F

INFOTEL CONSEIL
Published on
Architecture
Cloud
Cybersecurity

2 years
50k-65k €
500-650 €
Niort, Nouvelle-Aquitaine
Dans le cadre du développement de nos activités, nous recherchons un Architecte Sécurité / Expert Cybersécurité H/F pour intervenir chez l'un de nos clients grands comptes du secteur de l'assurance, basé à Niort. Au sein de l'équipe Sécurité des Systèmes d'Information, vous contribuerez à l'intégration de la sécurité dès la conception des solutions et accompagnerez la transformation du système d'information dans un environnement technologique riche et hétérogène (Cloud, Hybride, Multi-OS). Vous interviendrez auprès des équipes projets afin de définir, valider et faire évoluer les architectures de sécurité, tout en accompagnant les différents acteurs sur les enjeux de cybersécurité et de conformité. Vos principales responsabilités pourront être les suivantes : Concevoir et valider les architectures de sécurité des projets SI. Réaliser des analyses de risques et accompagner les projets dans le cadre du processus d'Instruction en Sécurité des Projets (ISP). Définir les exigences de sécurité et accompagner leur mise en œuvre. Conseiller les équipes de développement, les chefs de projet et les métiers sur les problématiques de cybersécurité. Participer à la sécurisation des applications, des infrastructures et des environnements Cloud et Hybrides. Définir des patterns, standards et bonnes pratiques de sécurité. Rédiger les dossiers d'architecture sécurité, les notes de cadrage, les analyses de risques et les avis de sécurité. Contribuer à l'évolution des politiques et des référentiels de sécurité. Participer à la cartographie des risques et au suivi des contrôles de sécurité. Apporter une expertise transverse sur les sujets liés à l'IAM, à la sécurité réseau, à la sécurité applicative et aux architectures Cloud. Vous évoluerez dans un environnement technique exigeant et collaboratif, au sein d'une équipe experte en cybersécurité intervenant sur des projets stratégiques de transformation du système d'information. La mission est basée à Niort avec 3 jours de présence sur site par semaine.
View this job
Contractor

Contractor job
Référent(e) Sécurité périmètre CXI

LeHibou
Published on
GDPR
ISO 27001
Risk management

36 months
700 €
Guyancourt, Ile-de-France
Notre client dans le secteur Banque et finance recherche un/une Référent(e) Sécurité périmètre CXI H/F Description de la mission : Contexte La/Le Référent(e) Sécurité du périmètre CXI intervient chez CACEIS / CA-GIP. Il/Elle est rattaché(e) hiérarchiquement au pôle Cyber Trust et Risk IT et fonctionnellement dans le Cluster d'accueil CIB. Missions principales Coordination des actions sécurité liées au SIS Point d'entrée des demandes pour le SIS (Risques IT, COC, client, recommandations IGL, etc.) Coordination des contributions nécessaires du SIS Correspondant des fonctions centrales sécurité Remontée d'évènements sécurité (en détail ou en synthèse) à Risques IT Contributeur de Risques IT sur l'implémentation de thématiques en Cluster (sensibilisation, dérogations, politique de sécurité, cartographie des risques, PCA, etc.) Suivi des vulnérabilités / non-conformités Étude des vulnérabilités / non-conformités détectées sur le périmètre CACEIS Contextualisation client / priorisation Obtention de l'accord client et si nécessaire d'un créneau de remédiation Coordination de la remédiation (pôle et/ou cluster et/ou COC) Présentation de la situation contextualisée aux entités Tableaux de bord / indicateurs Récupération des indicateurs et du tableau de bord générique établi par le COC Contextualisation pour présentation aux CISO des entités clientes Remontée d'éventuels nouveaux besoins au COC Négociation avec les entités des indicateurs de la convention de service si besoin Tests d'intrusion réalisés par le client Présence à la restitution des audits / tests d'intrusion concernant CIB Prise en compte et coordination des travaux de remédiation (Cluster / COC / pôles) SOC / Gestion des incidents de sécurité Le COC garde son point de contact unique (SPOC) chez le client Le référent sécurité est informé sans être bloquant dans la communication et la chaîne de traitement de l'incident Comités CRS (Comité Run Sécurité) : mensuel, interne, traite des indicateurs de sécurité de CIB Comité Sécurité CA-GIP / Client : animé par le référent sécurité, mensuel ou bimestriel selon le client — remontée des indicateurs et des besoins CISO Comité des Référents Sécurité : animé par Risques IT, mensuel, partage méthodologique entre référents Profil recherché Compétences techniques Communication et support impactant Gestion des priorités Bonne vision des sujets sécurité : identités et accès, réseaux, Cloud Frameworks de sécurité : ISO 27001, NIST Réglementations secteur bancaire, conduite d'audit, TI, RGPD, ARS Softskills Capacité d'analyse, de synthèse et de restitution Aisance relationnelle Animation et facilitation Adaptabilité Autonomie Anglais obligatoire. Compétences / Qualités indispensables : Sécurité des SI (identités/accès, réseaux, Cloud), Frameworks sécurité (ISO 27001, NIST), Réglementations bancaires (RGPD, ARS), Gestion des vulnérabilités et non-conformités, Communication et coordination multi-parties, Anglais courant (obligatoire) Informations concernant le télétravail : Oui — 2 jours/semaine
View this job
Permanent

Job Vacancy
Information Security Manager with Network Engineering Skills

Nexus Jobs Limited
Published on

£85k-100k
London, England, United Kingdom
Information Security Manager with Network Engineering Skills Our Client is bank based in Central London who are looking to recruit a seasoned professional with at least 7 to 10 years expertise level Information Security coupled with Hands-on Network Engineering. The role is mainly Information Security – Data Security and split circa 80% with 20% Network Engineering – so you do need to be hands-on technically. You will ideally have circa 5+ years of work experience with Network Engineering coupled with over 10 years experience with Cisco Systems Products Role Description The Information Security Manager with Network Engineering Skills is a full-time hybrid role based in London, with the flexibility to work from home part of the week. The role oversees the design, implementation, and continuous improvement of information security policies, procedures, and controls across networks and systems. Day-to-day responsibilities include managing the Information Security Management System (ISMS), monitoring cybersecurity and network security events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this role will collaborate with IT and business stakeholders to assess risks, implement technical and procedural safeguards, and support secure network architecture and configuration. Additional tasks include producing security documentation, leading security awareness initiatives, and providing guidance on secure network engineering practices. Qualifications Strong skills in Information Security Management and Information Security, with experience defining and enforcing security policies and governance. Hands-on expertise with Information Security Management Systems (ISMS), including implementation, maintenance, and audit readiness. Proficiency in Cybersecurity and Network Security, covering threat detection, vulnerability management, network hardening, and incident response. Demonstrated network engineering experience (e.g., routing, switching, firewalls, VPNs, secure network design). Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, or similar are beneficial. Experience with regulatory and compliance frameworks (e.g., ISO 27001, GDPR, NIST) and security best practices. Ability to analyze complex technical environments, communicate clearly with both technical and non-technical stakeholders, and document security requirements and processes. Bachelor's degree in computer science, information security, engineering, or a related field, or equivalent professional experience. Key Networking Skills Required: Cisco Network Switches Layer 2 and 3 (Catalyst 9K) – CCNP Level, Expert Level Preferred Routing protocol – OSPF (Catalyst 9K) – CCNP Level, Expert Level Preferred Cisco Switch Stacking (Cat 9K Switches 9600, 9300. 9200) Virtual Routing and Forwarding – (Catalyst 9600) Internetworking Troubleshooting - CCNP Level, Expert Level Preferred High Availability and Disaster Recovery - CCNP Level, Expert Level Preferred Security/Cyber Security Skills Required: Cisco Firepower Firewalls (ASA, FTD) - CCNP Level, Expert Level Preferred Palo Alto Firewalls – Specialist Level, Architect Level Preferred Cisco Layer 2 Port Security Network Access Control including Cisco ISE, TACACS etc Network Detection and Response Network Encryption (Site to Site VPN's) Cisco Secure Client (ASA) Network IPS (Trellix) Network Zero Day (Trellix NX or similar) Host Zero Day (Trellix HX or similar) Cyber Security Network Control Incident Investigation with the assistance of group cyber security experts – Tier 1, Tier 2 to 3 preferred, using LogRhythm SIEM a bonus Host End Point Protection (Symantec) Host IPS Preferred Skills and Knowledge Vulnerability Management (Scanning for Vulnerabilities and classifying the risk, CIS Benchmark Scanning and compliance) – Using Rapid7 a bonus Knowledge of Penetration Testing, understanding of the types of testing and their advantages and disadvantages Security Zone Design and considerations Network and Security Architecture Design and Considerations Understanding of Information Security (Confidentiality, Integrity, Availability), MITRE ATT&CK, NIST, ISO 27001, SIEM use cases for key controls etc Risk Management in Cyber Security, SSL Blind spots, what causes them and how to mitigate Malware/Ransomware and how to mitigate along with Penetration testing concepts Understanding of White/Black/Grey Box penetration testing. Developing Security policies and procedures and conducting audits/risk assessments Handling crisis situations during security incidents The role is hybrid 3 days in the office in Central London. The salary for this role will be in the range £85K - £100K + Benefits. Do send your CV to us in Word format along with your salary and notice period.
View this job
Contractor

Contractor job
Information Security Manager with Network Engineering Skills

Nexus Jobs Limited
Published on

£500-650
London, England, United Kingdom
Information Security Manager with Network Engineering Skills Our Client is bank based in Central London who are looking to recruit a seasoned professional with at least 7 to 10 years expertise level Information Security coupled with Hands-on Network Engineering. The role is mainly Information Security – Data Security and split circa 80% with 20% Network Engineering – so you do need to be hands-on technically. You will ideally have circa 5+ years of work experience with Network Engineering coupled with over 10 years experience with Cisco Systems Products Role Description The Information Security Manager with Network Engineering Skills is a full-time hybrid role based in London, with the flexibility to work from home part of the week. The role oversees the design, implementation, and continuous improvement of information security policies, procedures, and controls across networks and systems. Day-to-day responsibilities include managing the Information Security Management System (ISMS), monitoring cybersecurity and network security events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this role will collaborate with IT and business stakeholders to assess risks, implement technical and procedural safeguards, and support secure network architecture and configuration. Additional tasks include producing security documentation, leading security awareness initiatives, and providing guidance on secure network engineering practices. Qualifications Strong skills in Information Security Management and Information Security, with experience defining and enforcing security policies and governance. Hands-on expertise with Information Security Management Systems (ISMS), including implementation, maintenance, and audit readiness. Proficiency in Cybersecurity and Network Security, covering threat detection, vulnerability management, network hardening, and incident response. Demonstrated network engineering experience (e.g., routing, switching, firewalls, VPNs, secure network design). Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, or similar are beneficial. Experience with regulatory and compliance frameworks (e.g., ISO 27001, GDPR, NIST) and security best practices. Ability to analyze complex technical environments, communicate clearly with both technical and non-technical stakeholders, and document security requirements and processes. Bachelor's degree in computer science, information security, engineering, or a related field, or equivalent professional experience. Key Networking Skills Required: Cisco Network Switches Layer 2 and 3 (Catalyst 9K) – CCNP Level, Expert Level Preferred Routing protocol – OSPF (Catalyst 9K) – CCNP Level, Expert Level Preferred Cisco Switch Stacking (Cat 9K Switches 9600, 9300. 9200) Virtual Routing and Forwarding – (Catalyst 9600) Internetworking Troubleshooting - CCNP Level, Expert Level Preferred High Availability and Disaster Recovery - CCNP Level, Expert Level Preferred Security/Cyber Security Skills Required: Cisco Firepower Firewalls (ASA, FTD) - CCNP Level, Expert Level Preferred Palo Alto Firewalls – Specialist Level, Architect Level Preferred Cisco Layer 2 Port Security Network Access Control including Cisco ISE, TACACS etc Network Detection and Response Network Encryption (Site to Site VPN's) Cisco Secure Client (ASA) Network IPS (Trellix) Network Zero Day (Trellix NX or similar) Host Zero Day (Trellix HX or similar) Cyber Security Network Control Incident Investigation with the assistance of group cyber security experts – Tier 1, Tier 2 to 3 preferred, using LogRhythm SIEM a bonus Host End Point Protection (Symantec) Host IPS Preferred Skills and Knowledge Vulnerability Management (Scanning for Vulnerabilities and classifying the risk, CIS Benchmark Scanning and compliance) – Using Rapid7 a bonus Knowledge of Penetration Testing, understanding of the types of testing and their advantages and disadvantages Security Zone Design and considerations Network and Security Architecture Design and Considerations Understanding of Information Security (Confidentiality, Integrity, Availability), MITRE ATT&CK, NIST, ISO 27001, SIEM use cases for key controls etc Risk Management in Cyber Security, SSL Blind spots, what causes them and how to mitigate Malware/Ransomware and how to mitigate along with Penetration testing concepts Understanding of White/Black/Grey Box penetration testing. Developing Security policies and procedures and conducting audits/risk assessments Handling crisis situations during security incidents The role is hybrid 3 days in the office in Central London. The rate for this role will be in the range £500 pd to £650 pd. This is a 3 month assignment. Do send your CV to us in Word format along with your salary and notice period.
View this job

Connecting Tech-Talent

Free-Work, THE platform for all IT professionals.

Free-workers
Resources
About
Recruiters area
2026 © Free-Work / AGSI SAS
Follow us