Find your next tech and IT Job or contract Security Information Event Management (SIEM)

Your search returns 31 results.
Contractor
Permanent

Job VacancyCONSULTANT SOC SIEM ELASTIC SECURITY H/F

Cheops Technology
Published on
Elasticsearch
Security Information Event Management (SIEM)
XDR (Extended Detection & Response)

6 months
40k-45k €
400-490 €
Rouen, Normandy
Détection et analyse des menaces Le prestataire devra notamment :  Identifier, analyser, qualifier et prioriser les alertes de sécurité détectées ;  Évaluer la criticité et l'impact potentiel des alertes sur le système d'information ;  Notifier les alertes de sécurité aux parties prenantes et assurer leur escalade si nécessaire ;  Mener des activités de recherche de compromission (Threat Hunting) afin d'identifier des comportements suspects non détectés automatiquement. Réaction et accompagnement face aux menaces Le prestataire assurera :  La transmission des plans d'action aux équipes responsables du traitement des alertes ;  Un support technique et méthodologique concernant les correctifs ou mesures de contournement à mettre en oeuvre ;  La formulation de recommandations sur les mesures immédiates à appliquer pour limiter les risques ;  L'accompagnement et le suivi du traitement des alertes jusqu'à leur résolution complète. Mise en place des cas d'usage et des outils Le prestataire assurera :  Le développement et le maintien des règles de détection d'événements de sécurité (SIEM, Trend Vision One, etc.) ;  Le maintien opérationnel des dispositifs de supervision Cyber
View this job
Contractor

Contractor jobExpert Observabilité IA & Plateforme Agentique (SOC) - H/F

Groupe Ayli
Published on
API REST
AWS Bedrock
AWS Cloud

6 months
620-700 €
Ile-de-France, France
Dans le cadre de l'industrialisation de solutions d'IA générative et d'architectures agentiques, nous recherchons un Expert Observabilité IA & Cyber. Vous interviendrez sur la conception, l'implémentation et l'exploitation des mécanismes de supervision, monitoring, évaluation, sécurité et gouvernance de systèmes d'IA générative. Votre objectif sera de garantir la fiabilité, la sécurité, la performance et la traçabilité des agents IA déployés au sein d'un environnement SOC. Vous contribuerez notamment à l'observabilité de bout en bout des workflows IA, à la détection des comportements anormaux, à l'identification des hallucinations et dérives de modèles, ainsi qu'au suivi des performances des agents et des LLM. Vos missionsObservabilité des systèmes IA Définir et mettre en œuvre la stratégie d'observabilité d'une plateforme agentique. Mettre en place le monitoring des agents IA, chaînes de raisonnement et workflows LangChain / LangGraph. Collecter et corréler les métriques techniques, fonctionnelles et métier. Construire des dashboards temps réel permettant de suivre les performances et la qualité des agents. Concevoir les mécanismes de traçabilité des interactions avec les systèmes IA. AI Reliability Engineering Mettre en place des frameworks d'évaluation continue des agents IA. Définir les KPI de qualité et de fiabilité. Garantir le respect des SLA / SLO de la plateforme. Identifier les dérives et contribuer à l'amélioration continue de la qualité des réponses produites. Sécurité & gouvernance des systèmes IA Superviser les risques liés à l'utilisation de l'IA. Définir les mécanismes de gouvernance autour des agents. Détecter les comportements anormaux ou potentiellement dangereux. Participer aux analyses de risques IA. Contrôler les accès, permissions et échanges entre les différents agents et composants. Intégration Observabilité & SOC Intégrer les événements de la plateforme IA dans Splunk. Concevoir les dashboards d'exploitation. Développer les alertes de détection liées aux systèmes IA. Mettre en place des corrélations entre événements cyber et événements IA. Produire les indicateurs de supervision destinés aux équipes opérationnelles. RUN & amélioration continue Assurer le maintien en condition opérationnelle de la plateforme d'observabilité. Investiguer les incidents liés aux agents IA. Identifier les causes racines des défaillances. Optimiser les performances, les coûts et les niveaux de service.
View this job
Contractor
Permanent

Job VacancyAnalyste SOC L2/L3 (H/F)

virtualbrains
Published on
Cortex XSOAR
Palo Alto
Security Information Event Management (SIEM)

1 year
40k-45k €
400-420 €
Nanterre, Ile-de-France
Dans le cadre du renforcement d'une équipe SOC RUN L2, notre client recherche un Analyste SOC confirmé à senior afin d'assurer la supervision, l'analyse et le traitement des incidents de sécurité dans un environnement international. Vous intégrerez une équipe spécialisée dans la détection et la réponse aux menaces, avec un rôle clé dans l'amélioration continue des capacités de surveillance et de protection du système d'information. Vos missions principales :Superviser en temps réel les alertes de sécurité générées par Splunk Enterprise Security (ES). Analyser et qualifier les alertes afin d'identifier les incidents potentiels. Réaliser des investigations approfondies à partir des logs et événements de sécurité. Effectuer des recherches avancées dans Splunk ES pour confirmer ou écarter les incidents. Identifier la cause, l'impact et le périmètre des incidents détectés. Optimiser les règles de corrélation et améliorer les dashboards Splunk. Participer à l'évolution des procédures et processus SOC. Assurer l'escalade des incidents critiques vers les équipes spécialisées. Documenter les incidents, analyses réalisées et actions de remédiation. Utiliser Microsoft MDx dans le cadre d'investigations avancées. Mettre en œuvre des mécanismes d'orchestration via Palo Alto XSOAR. Rédiger des rapports d'incidents destinés au suivi client. Participer aux réunions avec des équipes internationales en anglais. Assurer une veille permanente sur les nouvelles menaces et technologies cybersécurité. Compétences attenduesSplunk Enterprise Security (ES) : Expert Microsoft MDx : Expert Palo Alto XSOAR : Expert Analyse SOC niveau L2/L3 Investigation d'incidents de sécurité Analyse de logs et événements SIEM Threat Detection & Incident Response Anglais professionnel écrit et oral
View this job
Contractor
Permanent

Job VacancyIngénieur Senior Sécurité IAM & SIEM (Luxembourg)

EXMC
Published on
Cybersecurity
IAM
Privileged Access Management (PAM)

6 months
Luxembourg
L'Ingénieur Senior Sécurité – IAM & SIEM est responsable de la conception, de la mise en œuvre et de la gestion opérationnelle de l'infrastructure de gouvernance des identités ainsi que des capacités de supervision de la sécurité de l'organisation. Position Summary : The Senior Security Engineer – IAM & SIEM is responsible for the design, implementation, and operational management of the organization's identity governance infrastructure and security monitoring capabilities. The role operates at the intersection of preventive control (IAM) and detective control (SIEM), requiring deep technical expertise, cross-functional leadership, and a strong understanding of regulatory frameworks applicable to the financial sector. The incumbent acts as a subject-matter expert across the full IAM lifecycle and SIEM pipeline, from architecture design to incident triage, and is expected to autonomously drive projects from initiation to delivery with minimal supervision. Key Responsibilities · Identity & Access Management o Design, deploy, and maintain enterprise IAM platforms (e.g., CyberArk, SailPoint, Microsoft Entra ID, Okta), including PAM, IGA, and federation services. o Define and enforce access governance policies: RBAC, ABAC, SoD controls, and privileged access workflows. o Lead IAM integration projects with critical systems (, cloud platforms, LDAP/AD, …) using standards such as SCIM, SAML 2.0, OAuth 2.0, and OpenID Connect. o Conduct IAM risk assessments and remediate audit findings related to access control deficiencies. · SIEM & Security Monitoring o Architect, tune, and operate SIEM platforms (e.g.,Splunk,) including data ingestion, normalization, and correlation rule engineering. o Develop and maintain detection content aligned with MITRE ATT&CK: use-case catalogue, detection logic, false-positive suppression, and alert lifecycle management. o Define SIEM KPIs and ensure log coverage across critical assets (endpoints, network perimeter, IAM stack, cloud workloads). o Lead SIEM-driven investigations and provide L3 support during major incidents; participate in post-incident reviews and lessons-learned. o Collaborate with the SOC to improve SOAR playbook automation and reduce mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR). o Monitor and integrate threat intelligence feeds to enrich detection use cases. Cross-Functional & Governance · Contribute to the security architecture review for new projects and technology changes. · Participate in the development and maintenance of security policies, standards, and procedures within the scope of IAM and monitoring.
View this job
Contractor
Permanent

Job VacancyExpert en Cybersécurité - Senior

ALLEGIS GROUP
Published on
Cortex XSOAR
Endpoint detection and response (EDR)
Security Information Event Management (SIEM)

3 months
Villeneuve-d'Ascq, Hauts-de-France
Vous êtes le pivot entre le terrain et le management. Vous incarnez la crédibilité technique tout en portant une vision de service mature et mesurable : Leadership & Management opérationnel Animer, encadrer, organiser le dispositif SecOps composé d'ingénieurs et experts cyber Structurer le traitement des alertes (rotations, priorisation) Être le point de référence technique pour l'équipe, capable de trancher sur les cas complexes Fédérer autour d'une culture de l'amélioration continue Pilotage de la performance Définir, suivre et améliorer les indicateurs clés de performance du dispositif : ex MTTD, MTTR, taux de faux positifs, ... Produire des reportings réguliers à destination du management Identifier les axes d'optimisation et proposer des plans d'action concrets Contribuer activement à la professionnalisation du service Excellence opérationnelle – RUN Superviser l'investigation des alertes de cybersécurité (SIEM, EDR, NDR, threat intelligence...) Garantir la qualité et la cohérence des analyses produites par l'équipe Participer aux crises cyber sur le périmètre France et international Innovation & Build Contribuer à l'implémentation de nouvelles technologies et capacités de détection Challenger les règles de détection et des playbooks de réponse Être force de proposition sur l'évolution du stack technique Vision & Stratégie Effectuer une veille technologique et réglementaire active Collaborer avec les autres domaines de la cybersécurité (IT, métier, ...)
View this job
Premium Job
Permanent

Job VacancyIT Support Analyst/Engineer with Level 1 and Level 2

Nexus Jobs Limited
Published on
DHCP (Dynamic Host Configuration Protocol)
LAN
Microsoft SQL Server

£55k-60k
SW1V 1SW, London, England, United Kingdom
IT Support Analyst/Engineer with Level 1 and Level 2 Role Description This full-time IT Support Analyst/Engineer role covers both Level 1 and Level 2 support and is offered on a hybrid basis, with work primarily in London and some work from home flexibility. Day-to-day responsibilities include handling incoming support tickets, responding to user queries, and providing first-line technical assistance for hardware, software, and network issues. The role also involves performing more advanced second-line diagnostics, resolving complex incidents, escalating problems when required, and updating documentation and knowledge bases. The IT Support Analyst/Engineer will install and configure systems, manage user accounts and access permissions, monitor system performance, and assist with routine maintenance tasks and upgrades. Collaboration with other IT team members and clear communication with non-technical users are key aspects of the position. Qualifications · Candidates should possess strong Technical Support and Information Technology skills, including experience with common operating systems, hardware, and business applications. · Candidates should possess solid Analytical Skills and Troubleshooting abilities to diagnose issues, identify root causes, and deliver effective solutions. · Candidates should possess clear and professional Communication skills, with the ability to explain technical concepts to users at different levels of technical understanding. · Relevant certifications such as CompTIA A+, Network+, Microsoft, or similar credentials are beneficial, along with experience in Level 1 and Level 2 support environments. · Ability to work in a hybrid setting, manage priorities in a busy service desk environment, and maintain a customer-focused, inclusive approach when supporting diverse user groups. For this position you will have at least 5 years experience in IT as an IT Support Engineer with 1st and 2nd Level support experience - ideally in the Banking/Financial industry. In-depth knowledge of and troubleshooting experience with Windows, Office applications and conferencing applications. Responsible for the support and maintenance of the IT infrastructure and to provide IT support to staff and other group colleagues. To assist in the response to service outages and other IT related problems as well as maintenance and upkeep of for security of the systems in place. · To provide IT Support and assistance to the branch's staff in a timely manner. · Responsible for the maintenance of the IT infrastructure of the Branch by providing first & Second line support of software, hardware and networking that includes installation, configuration and troubleshooting. Support endpoint security standards (antivirus/firewall/patching/two-factor authentication). · Provide day to day support to the Admin and HR function to cover: joiners/leavers/movers process, CCTV & Paxton Card Access. · Assist the IT Manager in delivering various IT related projects by managing the day to day operational aspects of such projects. · End User Computing support for all staff. (eg Install, configure, and maintain desktops, laptops, printers, Phones/Mobiles and other IT equipment.) · Networking Fundamentals – DNS, DHCP, TCP/IP, and LAN/WAN. · Good understanding of cybersecurity measures · Coordinator between the London Users and Group IT Security on all requests for systems access and to ensure that such permissions are provided promptly, are regularly updated and that the Group Access Matrix Protocol is followed at all times. · Preserve the Assets of the Office by implementing Disaster Recovery and back up procedures and ensuring that the standards comply with Group requirements. · Provide IT support to ensure the smooth running of daily and periodic reports for the London Compliance team to ensure adherence to the Anti Money Laundering Provisions. · Undertake Data Extraction for reporting requirements for all the other stakeholders at the branch. · To hold Administrator function for some of the systems housed at the Office. Responsible for the granting of access and maintenance of system matrixOverall networking equipment monitoring (ie Network Switches, Firewall and other appliances) and support inclusive of the server room. · To plan and carry out maintenance checks to ensure IT Operations, infrastructures are running smoothly and ensure daily routine task completeness. · Manage inventory of computers, network equipment including tracking of purchased equipment and services. · To maintain and ensure that the BCP site is always ready for continuous bank operations · Important Business Services - IBS owner is to ensure the resilience of the IBS they are responsible for (Ensure appropriate RCSAs, CETs, KRIs are in place to monitor procedures and controls within their units) · Assist the HOD/Manager with implementing/putting in place, any applicable training/guidance/SOPs to staff relating to cyber security & operational resilience. · To maintain the branch Avaya IP Office Phone system and to ensure that the recording system is always up and running at all times. · To perform monthly infrastructure test and report for Risk Assessment. · Manage Incident Handling procedure (This includes monitoring as well as post-incident follow up). · Respond to IT service requests and incidents in a timely manner, prioritizing based on business impact, especially for critical banking functionsSupport the Branch operations as and when needed and any other tasks assigned by Management of the Branch. Data Integrity and Compliance Operationalize data strategy and communicate to the Data Owner or the Management any changes in their BAU requirements which involve data. · To ensure all data worked on and or/shared with internal/external clients are accurate, compliant and maintained in accordance with Company's data quality standards. · Handle all data in strict alignment with the General data protection Regulations (GDPR) principles. · Keep track of documents created by the team. · Escalate any suspected data breaches or privacy issues to the DPO promptly and without delays. · Ensuring any data sharing requests are discussed with HOD/DPO so that prior authorization is given and follows GDPR / department's SOPs. · Collaborate with DPO on data Protection Impact Assessment when introducing new systems or processes to ensure privacy risks are mitigated at the outset. Technical Skills Required - Proficient in common operating systems (Windows 11 and Linux, Server 2016 and later) - Providing AV support for branches - Software proficiency – O365, Onedrive, Teams, Sharepoint, Bloomberg, FXT, SEP, SEE, ME Endpoint Protection, Murex, Swift, 1AML, SIBS, GFMS, COP, Refinitiv, Syncovery, SQL Server, Paxton, VBR, VRO and VeeamOne - Proficient in Imaging windows machines, image creation & management, GPO, and AD - Networking Fundamentals – DNS, DHCP, TCP/IP, and LAN/WAN. - Good understanding of Vmware; ESXI, vSphere, vCenter, Fortigate Firewalls, Cisco Switches - Good understanding of patching practices and troubleshooting - Install, configure, and maintain desktops, laptops, printers, Phones/Mobiles and other IT equipment. - AV support (conference phones, Logitech meeting room solutions etc.) - Proficient in programming languages - Project management - Data analysis and reporting Bachelor or Master's degree or professional qualification in relevant discipline (IT/Information Systems/Computer Science/Technology/Programming/Information Science/System Engineering/Computing) This is a 5 days in the office role in Central London. Salary for this role will be around £55K - £60K. Do send your CV to us in Word format along with your salary and availability.
View this job
Contractor

Contractor jobExpert en cybersécurité

Coriom Conseil
Published on
Endpoint detection and response (EDR)
Security Information Event Management (SIEM)
SOC (Security Operation Center)

12 months
400-550 €
Lille, Hauts-de-France
Définir, suivre et améliorer les indicateurs clés de performance du dispositif Être le point de référence technique pour l'équipe, capable de trancher sur les cas complexes Structurer le traitement des alertes (rotations, priorisation) Compétences techniques SOC, SIEM - Confirmé - Impératif EDR, SOAR - Confirmé - Important IT, Infra - Confirmé - Important Connaissances linguistiques: Anglais Professionnel (Impératif) Description détaillée Vous êtes le pivot entre le terrain et le management. Vous incarnez la crédibilité technique tout en portant une vision de service mature et mesurable : Leadership & Management opérationnel Animer, encadrer, organiser le dispositif SecOps composé d'ingénieurs et experts cyber Structurer le traitement des alertes (rotations, priorisation) Être le point de référence technique pour l'équipe, capable de trancher sur les cas complexes Fédérer autour d'une culture de l'amélioration continue Pilotage de la performance Définir, suivre et améliorer les indicateurs clés de performance du dispositif : ex MTTD, MTTR, taux de faux positifs, ... Produire des reportings réguliers à destination du management Identifier les axes d'optimisation et proposer des plans d'action concrets Contribuer activement à la professionnalisation du service
View this job
Contractor
Permanent

Job VacancyConsultant Senior Cloud Security AWS – SOC

PSSWRD
Published on
AWS Cloud
Cloud
Cybersecurity

6 months
Issy-les-Moulineaux, Ile-de-France
Cher réseau bonjour, 👀 Dans le cadre du renforcement d'un SOC, je recherche un consultant Expérimenté Cloud Security AWS pour l'un de nos clients basé à Issy-Les-Moulineaux (92), qui sera le référent technique sur les problématiques de sécurité des environnements AWS. Il interviendra sur la définition, la mise en œuvre et l'amélioration continue des capacités de détection et de réponse aux incidents de sécurité sur les environnements Cloud, en cohérence avec les processus opérationnels du SOC. 🏁 MISSION • Le consultant a pour mission de développer et d'industrialiser les capacités opérationnelles du SOC sur le périmètre AWS. Il construit les processus de réponse aux incidents Cloud, assure l'intégration des mécanismes de détection AWS au sein du SOC et contribue à l'amélioration continue de la visibilité et de la posture de sécurité des environnements Cloud. • Il travaille en étroite collaboration avec les équipes SOC, Cloud, DevSecOps, Infrastructure et le Vulnerability Operations Center (VOC). 💪 PÉRIMÈTRE • Le périmètre couvre exclusivement les activités de détection, qualification, investigation et réponse aux incidents de sécurité sur AWS ; • Les problématiques de misconfiguration (CSPM), bien qu'identifiées notamment par Wiz, ne relèvent pas du SOC ni du VOC. Elles sont hors périmètre de cette fonction et sont prises en charge par les équipes DevSecOps selon les processus de remédiation établis ; • Le consultant peut contribuer à la qualification initiale afin de déterminer si une alerte relève d'un incident de sécurité ou d'une simple erreur de configuration, puis orienter celle-ci vers l'équipe compétente. 🎯 RESPONSABILITÉS PRINCIPALES 1. Construction des capacités SOC Cloud • Définir et mettre en œuvre le processus de réponse aux incidents de sécurité sur AWS ; • Concevoir les playbooks et runbooks dédiés aux incidents Cloud ; • Intégrer les processus Cloud aux procédures opérationnelles existantes du SOC ; • Définir les workflows entre le SOC, les équipes Cloud, DevSecOps et les équipes d'exploitation ; • Participer à l'amélioration continue des capacités de détection et de réponse. 2. Détection et investigation • Exploiter les détections de sécurité issues de Wiz relatives aux menaces, compromissions et comportements suspects ; • Qualifier les alertes afin de distinguer les incidents de sécurité des constats de configuration ; • Développer de nouveaux cas d'usage de détection adaptés aux environnements AWS ; • Réaliser les investigations de sécurité sur les incidents Cloud ; • Identifier les causes racines et proposer les actions de confinement et de remédiation. 3. Exploitation des journaux AWS • Définir les sources de logs AWS à intégrer au SIEM ; • Exploiter les journaux AWS (CloudTrail, GuardDuty, VPC Flow Logs, CloudWatch, etc.) afin d'améliorer les capacités de détection ; • Développer les règles de corrélation et les cas d'usage SOC autour des événements AWS ; • Garantir la qualité et la couverture des données de sécurité Cloud. 4. Réponse aux incidents • Piloter les investigations de sécurité sur les environnements AWS ; • Accompagner les équipes techniques lors des opérations de confinement, d'éradication et de remédiation ; • Participer aux cellules de crise lors des incidents majeurs impliquant le Cloud ; • Produire les rapports d'incident, les analyses de causes racines et les retours d'expérience. 5. Gouvernance et amélioration continue • Définir les indicateurs de performance des activités SOC Cloud ; • Contribuer à l'évolution des standards opérationnels de sécurité Cloud ; • Assurer une veille sur les menaces ciblant AWS ; • Être le référent technique Cloud Security auprès des analystes SOC. 6. Contribution au Vulnerability Operations Center (VOC) En complément de ses activités principales, l'expert contribue ponctuellement au Vulnerability Operations Center (VOC) dans les situations nécessitant une expertise Cloud, notamment pour : • l'analyse des vulnérabilités affectant les ressources AWS ; • la qualification du risque associé aux vulnérabilités détectées ; • l'évaluation de leur exploitabilité dans le contexte de l'entreprise ; • le support aux équipes de remédiation lorsque l'expertise Cloud est requise. Le traitement des misconfigurations (CSPM), des écarts de conformité et des recommandations de durcissement identifiés par Wiz ne relève pas du SOC ni du VOC et est pris en charge par les équipes DevSecOps. 💪 LIVRABLES ATTENDUS • Processus de réponse aux incidents AWS ; • Playbooks et runbooks SOC Cloud ; • Catalogue des cas d'usage de détection AWS ; • Règles de corrélation SIEM basées sur les logs AWS ; • Documentation opérationnelle SOC Cloud ; • Tableaux de bord et indicateurs de performance ; • Rapports d'investigation et retours d'expérience.
View this job
Contractor

Contractor jobCoordinateur Cybersécurité Opérationnelle

LOIC CAROLI SAS
Published on
AWS Cloud
Azure
sailpoint

6 months
500-710 €
Nantes, Pays de la Loire
Missions principales : Assurer le reporting mensuel de l'activité Sécurité au travers d'un dashboard mensuel (SOC, VOC, Sectools, IAM) Contribuer au bon fonctionnement des activités Sécurité (SOC, VOC, Sectools, IAM) au sein de la DSI en assurant la coordination entre les parties prenantes Être le point de contact principal pour les questions Sécurité (RSSI, Audit Interne & Externe…) et la contribution aux réponses d'audit sur le périmètre cyber Proposer des améliorations pour optimiser les ressources existantes et leur organisation Travailler en binome avec le Service Manager afin d'assurer un delivery de qualité de la part du partenaire en charge du périmètre. Travailler en binome avec l'Architecte Sécurité afin d'assurer le traitement des workflows nécessitant une validation Sécurité et contribuer à la sécurité dans les projets Gestion des incidents de sécurité Contribuer et accompagner l'équipe SOC dans le traitement des incidents Être le point de contact transverse pour les sollicitations nécessitant une investigation par les équipes Sécurité (Signalement Interne, DPO, Equipes IT, Business…) Assurer la remontée et le traitement des incidents liés à la surveillance externe Gestion des vulnérabilités Contribuer et accompagner l'équipe VOC dans le pilotage et le suivi des demandes de remédiations liées aux vulnérabilités identifiées sur le périmètre Applicatif, Système, Middleware et dans le code déployé au sein des infrastructures Outillage Sécurité Assurer la coordination des activités du fournisseur avec les différents services de l'entreprise Contribuer au suivi auprès des partenaires en cas de demande d'évolution sur les technologies de sécurité Veille Cyber Assurer une veille externe sur les nouvelles technologies de cybersécurité
View this job
Permanent
Contractor

Job VacancyAzure Cloud Security Architect (Maroc)

AVALIANCE
Published on
Azure
Azure Active Directory
Azure DevOps

3 years
Morocco
Contexte de la mission Dans le cadre d'un programme de transformation digitale et de migration vers le cloud (“Move to Cloud”), nous recherchons un(e) Architecte Cyber Cloud Azure afin d'accompagner la définition et la sécurisation de l'architecture cible sur Microsoft Azure. La mission s'inscrit dans un environnement hybride avec des enjeux forts autour de la sécurité, de la conformité, de la gouvernance cloud et de la sécurisation des workloads migrés vers Azure. Missions principales Définir l'architecture sécurité cible dans un contexte de migration vers Microsoft Azure Accompagner les projets Move to Cloud sur les volets cybersécurité et conformité Concevoir et mettre en œuvre les standards de sécurité cloud Azure Réaliser les analyses de risques et les revues d'architecture sécurité Définir les patterns de sécurisation des infrastructures et applications cloud Participer à la gouvernance sécurité du cloud : IAM / RBAC segmentation réseau chiffrement gestion des secrets logging & monitoring Zero Trust Mettre en place et maintenir les solutions de sécurité Azure : Microsoft Defender for Cloud Microsoft Sentinel Azure Policy Key Vault Entra ID Accompagner les équipes infrastructure, réseau, DevOps et applicatives Contribuer à l'industrialisation et à l'automatisation des contrôles sécurité Participer à la rédaction des standards, procédures et documentations techniques
View this job
Permanent

Job VacancyCyber Security Manager

Nexus Jobs Limited
Published on

£70k-80k
Paddington, England, United Kingdom
Cyber Security Manager Our Client to be secured and protected from increased cyber threats and compliant to industry standards. This role covers information protection, including data loss protection and data classification, and threat protection, including security information and event management (SIEM), user and entity behaviour analytics (UEBA), point products like anti-virus (AV) and intrusion detection system/intrusion prevention system (IDS/IPS) and penetration testing. The Service Delivery team consists of approximately 20 staff who support and operate the Company's services and there is an opportunity in that team for a Cyber Security Manager to oversee and govern all security services. Reporting Lines This role reports to Head of Service Delivery Main Accountabilities Technical leadership for all security solutions, including all the 3rd party managed services Maintain the overall security of Company's network, systems, and data Monitor security access and manage IDS/IPS configurations Establishing and implementing security 'best-practice' standards as well as departmental policies and procedures Responsible for Security scanning and the efficient remediation of vulnerabilities Responsible for analysing all security incidents to determine root cause Determine, recommend, and implement upgrade security measures and controls Delivery security responses for customer and client compliance requirements Developing and managing security plans with vendors Audit activities of administrators and conduct Security awareness training Requirements Demonstrable skills and capability in Security leadership and 3rd party management experience CISSP certification preferred. Compliance knowledge required in ISO27001, PCI and GDPR. Possibly a certified ethical hacker Knowledge of Security technologies is essential, such as network appliances, firewall administration, AD, IAM, PAM, SIEM, UEBA, AV, IDS/IPS and MDM solutions Understanding of common frameworks, such as ITIL or LEAN is preferred Good exposure of user environment management, including desktops/laptops, profile management, access control methodologies Must be very proactive in understanding and staying up to date with current security technologies and industry technology trends The job/Client is located at our head office in Paddington, London with hybrid working The Client holds a Licence to Sponsor (grade A) and will always consider sponsoring employees if needed We welcome applications from Ukrainian Refugees The salary for this position is circa £70K - £80K plus Benefits. Please do send your CV to us in Word format along with your salary.
View this job
Contractor

Contractor jobSC Security Platform Engineer - 12 Month Contract

LA International Computer Consultants Ltd
Published on

12 months
GU14 7SR, Rushmoor, England, United Kingdom
Security Platform Engineer Locations: London / Corsham / Farnborough As a Security Platform Engineer, you will play a role in designing, building, and managing cloud-native security platforms with a strong emphasis on Kubernetes-based environments. You'll be at the intersection of security and engineering, developing scalable tooling, automating security controls, and enabling robust detection and response capabilities across our cloud infrastructure. This is a hands-on, engineering-centric role that requires deep technical expertise in cloud environments, Kubernetes security, and platform automation. Responsibilities ● Deploy, configure, and manage cloud security platform tools and technologies, including Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS). ● Develop and implement security monitoring and logging strategies. ● Investigate and analyse security incidents, including identifying root causes, determining the scope of impact, and taking appropriate containment and remediation actions. ● Perform forensic analysis to identify and investigate suspicious activity. ● Automate security tasks and workflows to improve efficiency and effectiveness. Preferred Qualifications (PQs) ● Certifications in Security (e.g., GSEC, CISSP, CISM, OSCP). ● Experience with Kubernetes threat detection and anomaly detection. ● Familiarity with service mesh security concepts (e.g., Istio, Linkerd) and workload identity. ● Background in detection engineering, logging pipeline development, or SIEM tuning in containerised environments. ● Contributions to security-focused open-source projects or internal security platform toolin Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take a minimum 10 weeks. LA International is an award-winning partner of choice for many of the world's most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance. An award-winning organisation, having secured the prestigious Queens Award for Enterprise: International Trade over multiple years. We are committed to fostering an inclusive, equitable and accessible workplace where everyone feels valued and supported. We welcome applications from all individuals, regardless of background or identity, and we encourage candidates who may not meet every listed requirement to still apply. If you require any adjustments or support during the recruitment process, please let us know and we will work with you to ensure a fair and accessible experience. Please Note: If a high volume of applications is received, only candidates shortlisted will be contacted.
View this job

Connecting Tech-Talent

Free-Work, THE platform for all IT professionals.

Free-workers
Resources
About
Recruiters area
2026 © Free-Work / AGSI SAS
Follow us