Trouvez votre prochaine offre d’emploi ou de mission freelance Security by design

Ce qu’il faut savoir sur Security by design

Intégrer la sécurité dès la conception des applications permet de prévenir les vulnérabilités avant leur exploitation. Le security by design consiste à implémenter des mesures de protection tout au long du cycle de développement, tandis que le security by design réduit significativement les risques et les coûts de correction en production.

Votre recherche renvoie 36 résultats.
CDI
Freelance

Offre d'emploiIngénieur Sécurité Confirmé H/F

CONSORT GROUP
Publiée le
Active Directory
Azure
CrowdStrike

1 mois
45k-55k €
Vierzon
Chaque moment compte. Surtout ceux que vous vivez à fond. Bienvenue chez Consort Group. Consort Group, accompagne depuis plus de 30 ans les entreprises dans la valorisation de leurs données et infrastructures. Elle s'appuie sur deux leaders, Consortis et Consortia, et place l'humain et la responsabilité sociétale au cœur de ses valeurs. C'est votre future équipe Créée en 2010, l'agence Ouest rassemble aujourd'hui près de 230 collaborateurs. Elle s'est fortement orientée vers les expertises en intégration applicative et en testing, en s'appuyant sur ses Centres de Services. Le tout dans un esprit de convivialité et de proximité, au service des régions de Nantes, Rennes et Angers. Ingénieur Sécurité Confirmé H/F C'est votre missionVous êtes passionné·e par la cybersécurité et la protection des systèmes d'information ? Ce poste est fait pour vous. En tant qu'Ingénieur Sécurité Confirmé, vous êtes responsable du renforcement de la posture de sécurité et de l'intégration des bonnes pratiques cyber au sein d'un environnement multisites combinant infrastructures IT, cloud et environnements industriels. Côté build :Intégrer la sécurité dans les projets DSI selon une approche Security by Design. Réaliser des revues d'architecture, analyses de risques et recettes de sécurité. Participer au durcissement des environnements Windows, Linux, Active Directory, Microsoft 365 et Azure. Contribuer à la sécurisation des environnements industriels OT/IoT des sites de production. Participer aux projets de mise en conformité NIS2 et aux audits internes ou externes. Faire évoluer les outils de sécurité du groupe : EDR/XDR, pare-feu, proxy, WAF, filtrage des messageries. Côté run :Administrer et maintenir les solutions de sécurité du SI. Piloter le programme de gestion des vulnérabilités : scans, priorisation et suivi de remédiation. Assurer le suivi des alertes remontées par le SOC et qualifier les incidents de sécurité. Participer aux investigations, actions de containment et plans de remédiation. Maintenir et tester les procédures de réponse à incident ainsi que le plan de continuité SI. Produire les indicateurs, tableaux de bord et KPI sécurité à destination du RSSI et de la direction. Mener des actions de sensibilisation auprès des utilisateurs et des filiales. C'est votre parcoursVous avez au moins 4 ans d'expérience en cybersécurité opérationnelle, idéalement au sein d'environnements multisites ou industriels. Vous aimez relever les défis liés à la sécurisation des systèmes d'information tout en accompagnant les équipes dans l'évolution des pratiques. Vous recherchez un environnement où expertise technique, autonomie et collaboration avancent ensemble. C'est votre expertiseInfrastructures réseaux : TCP/IP, segmentation réseau, VPN. Systèmes Windows, Linux et Active Directory. Solutions EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender ou équivalent). Pare-feu et solutions de sécurité réseau (Fortinet, Palo Alto, Stormshield). SIEM (Microsoft Sentinel, Splunk, QRadar). Outils de gestion des vulnérabilités (Tenable, Qualys). Environnements Microsoft Azure, Entra ID et Microsoft 365 Security. Référentiels ISO 27001, NIST, guides ANSSI et réglementation NIS2. Scripting PowerShell et/ou Python. Une connaissance des environnements OT/ICS (IEC 62443) constitue un atout. C'est votre manière de faire équipeAutonomie et sens des priorités dans un environnement multi-entités. Esprit d'analyse et rigueur dans la gestion des risques et incidents. Réactivité et capacité à prendre des décisions en contexte sensible. Excellentes qualités relationnelles et pédagogiques auprès d'interlocuteurs techniques et métiers. Capacité à vulgariser les enjeux de cybersécurité et à fédérer les équipes. Anglais technique permettant la lecture et l'exploitation de documentations spécialisées. C'est notre engagementChez Consort Group, vous êtes un·e expert·e qu'on accompagne pour que chaque mission devienne une étape qui compte. Un onboarding attentif et humain. Une vraie proximité managériale. Des formations accessibles en continu. Des engagements concrets : inclusion, égalité, solidarité. Un package RH complet : mutuelle, carte TR, CSE, prévoyance. Une culture du feedback et des projets qui font sens. C'est clairLe process de recrutement : Un premier échange téléphonique avec notre team recrutement. Un entretien RH ainsi qu'un échange métier avec un·e Ingénieur·e d'Affaires. Un test ou un échange technique avec un·e de nos expert·e·s. Un dernier point avec votre futur·e manager ou responsable de mission. Et si on se reconnaît : on démarre ensemble. C'est bon à savoirLieu : Angers Contrat : CDI Télétravail : 2 jours/semaine Salaire : De 45 K€ à 55 K€ brut annuel (selon expérience) Famille métier : Cybersécurité / Infrastructure & Sécurité des SI Ce que vous ferez ici, vous ne le ferez nulle part ailleurs. Ce moment, c'est le vôtre.
Voir cette offre
Freelance
CDI

Offre d'emploiExpert Sécurité de l'Intelligence Artificielle — Gouvernance, Conformité et Stratégie

R&S TELECOM
Publiée le
Microsoft Access

12 mois
40k-48k ¤
400-480 ¤
Île-de-France, France
Contexte de la mission Notre client, acteur bancaire de premier plan, structure la sécurité de l'intelligence artificielle au sein de son entité IT. Le besoin porte sur un profil senior capable de tenir à la fois l'expertise technique — architectures IA et agentiques, threat modeling, patterns de sécurisation — et le volet conformité et risques Cyber & IA dans un environnement fortement réglementé. Le/la consultant(e) intervient sur trois piliers : l'expertise technique et la veille, l'accompagnement sécurité des projets métier et socles techniques du cadrage à l'implémentation, et la stratégie (roadmap sécurité Cyber & IA, standards et directives, modèle d'opérationnalisation de la sécurité IA dans l'entreprise). Il/elle est l'interlocuteur sécurité IT opérationnel vis-à-vis des projets et des acteurs LoD2, en lien avec les équipes Data & IA et les équipes projets métier et infrastructure. Le poste implique une capacité de restitution au niveau du top management. Anglais professionnel indispensable. Objectifs et livrables Objectifs et livrables Analyses de risques et threat modeling appliqués aux systèmes d'IA (empoisonnement des données, évasion et vol de modèle, prompt injection) Définition des patterns d'architecture sécurisés pour l'IA et les architectures agentiques, et techniques de remédiation associées Traduction des exigences réglementaires et sécuritaires en contrôles techniques de sécurité Évaluation des risques tiers (Third-Party AI) et des solutions de sécurité IA du marché Élaboration et suivi de la roadmap stratégique sécurité Cyber & IA Rédaction des standards, directives et procédures encadrant l'usage de l'IA Définition du modèle d'opérationnalisation de la sécurité IA & Cyber Restitutions et supports de décision à destination du top management Compétences demandées Sécurité de l'IA Sécurité des systèmes d'IA et de Machine Learning Architecture de sécurité IA et Cyber Sécurité des architectures agentiques Threat modeling IA (empoisonnement de données, évasion de modèle, vol de modèle, prompt injection) Filtrage IA et garde-fous applicatifs MLOps / LLMOps Validation et évaluation de modèles Sécurisation des API et du protocole MCP Conformité, risques et gouvernance Conformité et risques Cyber & IA Conformité réglementaire IA, dont l'AI Act européen Gouvernance, risques et conformité (GRC) Évaluation des risques tiers (Third-Party AI) Politiques, standards et directives de sécurité Modèle des trois lignes de défense (LoD1 / LoD2) Référentiels normatifs (ISO 27001, NIST, OWASP, SOC 2) Roadmap et stratégie SSI Cybersécurité Architecture de sécurité applicative Cryptographie IAM / gestion des identités et des accès Intégration de la sécurité dans les projets (security by design) Analyse de risques, exigences et mesures de sécurité Secteur et formation Environnements réglementés : banque, finance, assurance ou santé Formation Bac+5 en cybersécurité et/ou intelligence artificielle Minimum 5 ans d'expérience en cybersécurité, dont 3 à 4 ans appliqués à l'IA Langues Anglais professionnel, à l'écrit comme à l'oral Français courant Savoir-être Restitution et communication au niveau top management Vulgarisation de concepts techniques complexes auprès de populations non techniques Posture de facilitateur et excellent relationnel Autonomie, rigueur et forte curiosité intellectuelle
Voir cette offre
CDI

Offre d'emploiIT Systems Security Manager

Nexus Jobs Limited
Publiée le

£75k-85k
Grand Londres, Royaume-Uni
IT Security Manager Our Client is a large international organisation who are looking to recruit an IT Security Manager with at least 5 to 8 years proven expertise. Provide advice, support and guidance to all Company Corporate functions to assist them to maintain and improve their information security maturity. To work collaboratively with all areas of the Company Corporate and build networks and relationships to promote Information Security. Act as subject matter expert on for IT Security, including legal and regulatory compliance Advise Company Corporate functions on how to achieve the required controls and assist with solutions to support them. Eg Support in the development of standards and their application in line with Group security policies. Participate in Company BU's Projects giving support, guidance, control validation and overall security assurance. This could also involve sitting on major project steering committees. Support and encourage the ethos and methodology of security by design. Aid GRC to build, implement and facilitate a mechanism to aid BU's to assess and measure their security compliance to policies. Drive the development of BU/Divisional security roadmaps. Giving oversight of key non-conformities to feed into the CISO roadmap. Coach, train and educate the Company IT and Functions to up skill and increase the security maturity in BU's. Be an active member of the Company's IS Security community, contributing to and leveraging the experience and lessons learned from other BU's Produce, implement and standardise protocol and guidance material to support Business unit activities – examples – Asset register templates, third party due-diligence. Facilitate and chair the security working group meetings Engage and manage third party relationships to support the Company and its affiliates Aid Procurement and the tendering process Raising the security baseline controls and standardising where it makes sense to do so. Understanding the different business requirements and aligning to their objectives Support Security operations to continuously improve information security awareness across the group, including phishing campaigns and associated reporting Experience Experience in an information security risk leadership role within a large organisation. Confident in presenting, discussing and championing ideas and concepts with senior stakeholders. Experience of running information security risk governance processes and structures Familiarity with relevant industry standards for information security (e.g. ISO27001, NIST CSF) Experience of creating, implementing and assessing against information security policies and standards Creativity Able to analyse complex, ambiguous problems and summarise clearly with a view to establishing practical solutions Able to “bridge the gap” between technologists and business-people, bringing to life information security risks to the business, while maintaining a pragmatic outlook on likelihood and impact of the risk and cost/complexity of the mitigation. Ensuring initiatives/programmes are anchored in best practice whilst still being highly practical/pragmatic. Ability to defuse situations and resolve conflict to a win-win outcome Influence others understand their views and agree ways of working that are acceptable to all parties. Business acumen to understand business risks and the information security implications Able to identify when information security risks need to be escalated to achieve the right level of management visibility. Able to prioritise security risks and controls, differentiating the essential from the “nice to have”. Able to judge how to communicate messages to people to maximise buy-in and/or understanding. Able to analyse data with rigour & reach sound conclusions Can assess when further data gathering, or analysis will bring diminishing returns. Can place appropriate weight on prevailing (sometimes conflicting) evidence. Support and manage budget Responsibility Responsibility of information security incident management Responsibility for security assessments and assurance activities (e.g. penetration testing) and when to use them. Oversee and management of security compliance management and reporting in relation to any relevant regulatory or legal requirements Operational responsibility of management of third parties Responsibility for managing change management around project and change leadership. Able to judge the political and other people aspects of a situation, and tailor messages and approach to bring people along. Able to work with others, setting challenging but realistic targets for team members, and through coaching and appropriate guidance, securing a successful outcome. A positive collegiate approach to developing relationships and networks at all levels across the Company and the gravitas to work persuasively with senior stakeholders. Is aware of different styles of stakeholders and can adjust own leadership style successfully to bridge any gaps. The Client and the role is based in Central London – and you will be required to be in the office at least 3 days week. The salary for this position will be £75K + £85K plus Benefits. Please do send your CV to us in Word format for this exciting new position along with your salary and availability.
Voir cette offre
CDI

Offre d'emploiIT Security Manager

Nexus Jobs Limited
Publiée le

£75k-85k
Grand Londres, Royaume-Uni
IT Security Manager Our Client is a large international organisation who are looking to recruit an IT Security Manager with at least 5 to 8 years proven expertise. Provide advice, support and guidance to all Company Corporate functions to assist them to maintain and improve their information security maturity. To work collaboratively with all areas of the Company Corporate and build networks and relationships to promote Information Security. Act as subject matter expert on for IT Security, including legal and regulatory compliance Advise Company Corporate functions on how to achieve the required controls and assist with solutions to support them. Eg Support in the development of standards and their application in line with Group security policies. Participate in Company BU's Projects giving support, guidance, control validation and overall security assurance. This could also involve sitting on major project steering committees. Support and encourage the ethos and methodology of security by design. Aid GRC to build, implement and facilitate a mechanism to aid BU's to assess and measure their security compliance to policies. Drive the development of BU/Divisional security roadmaps. Giving oversight of key non-conformities to feed into the CISO roadmap. Coach, train and educate the Company IT and Functions to up skill and increase the security maturity in BU's. Be an active member of the Company's IS Security community, contributing to and leveraging the experience and lessons learned from other BU's Produce, implement and standardise protocol and guidance material to support Business unit activities – examples – Asset register templates, third party due-diligence. Facilitate and chair the security working group meetings Engage and manage third party relationships to support the Company and its affiliates Aid Procurement and the tendering process Raising the security baseline controls and standardising where it makes sense to do so. Understanding the different business requirements and aligning to their objectives Support Security operations to continuously improve information security awareness across the group, including phishing campaigns and associated reporting Experience Experience in an information security risk leadership role within a large organisation. Confident in presenting, discussing and championing ideas and concepts with senior stakeholders. Experience of running information security risk governance processes and structures Familiarity with relevant industry standards for information security (e.g. ISO27001, NIST CSF) Experience of creating, implementing and assessing against information security policies and standards Creativity Able to analyse complex, ambiguous problems and summarise clearly with a view to establishing practical solutions Able to “bridge the gap” between technologists and business-people, bringing to life information security risks to the business, while maintaining a pragmatic outlook on likelihood and impact of the risk and cost/complexity of the mitigation. Ensuring initiatives/programmes are anchored in best practice whilst still being highly practical/pragmatic. Ability to defuse situations and resolve conflict to a win-win outcome Influence others understand their views and agree ways of working that are acceptable to all parties. Business acumen to understand business risks and the information security implications Able to identify when information security risks need to be escalated to achieve the right level of management visibility. Able to prioritise security risks and controls, differentiating the essential from the “nice to have”. Able to judge how to communicate messages to people to maximise buy-in and/or understanding. Able to analyse data with rigour & reach sound conclusions Can assess when further data gathering, or analysis will bring diminishing returns. Can place appropriate weight on prevailing (sometimes conflicting) evidence. Support and manage budget Responsibility Responsibility of information security incident management Responsibility for security assessments and assurance activities (e.g. penetration testing) and when to use them. Oversee and management of security compliance management and reporting in relation to any relevant regulatory or legal requirements Operational responsibility of management of third parties Responsibility for managing change management around project and change leadership. Able to judge the political and other people aspects of a situation, and tailor messages and approach to bring people along. Able to work with others, setting challenging but realistic targets for team members, and through coaching and appropriate guidance, securing a successful outcome. A positive collegiate approach to developing relationships and networks at all levels across the Company and the gravitas to work persuasively with senior stakeholders. Is aware of different styles of stakeholders and can adjust own leadership style successfully to bridge any gaps. The Client and the role is based in Central London – and you will be required to be in the office at least 3 days week. The salary for this position will be £75K + £85K plus Benefits. Please do send your CV to us in Word format for this exciting new position along with your salary and availability.
Voir cette offre

Au service des talents IT

Free-Work est une plateforme qui s'adresse à tous les professionnels des métiers de l'informatique.

Ses contenus et son jobboard IT sont mis à disposition 100% gratuitement pour les indépendants et les salariés du secteur.

Free-workers
Ressources
A propos
Espace recruteurs
2026 © Free-Work / AGSI SAS
Suivez-nous