Trouvez votre prochaine offre d’emploi ou de mission freelance Security Information Event Management (SIEM)

Votre recherche renvoie 117 résultats.
Freelance
CDI

Offre d'emploiSpécialiste DLP (luxembourg)

EXMC
Publiée le
Prévention des pertes de données (DLP)
Security Information Event Management (SIEM)

6 mois
Luxembourg
Le candidat devra avoir le profil suivant : · Expert dans l'installation, la configuration et l'exploitation d'outils DLP Entreprise (endpoint, network, cloud) · Bonne compréhension des mécanismes de détection DLP : o Regex, fingerprinting, EDM/IDM, classification basée ML · Expérience dans le tuning des polices DLP (réduction des faux positifs / faux négatifs) · Expertise dans l'administration de suites bureautiques cloud ; expérience approfondie M365 fortement recommandée · Expérience en Blue Team, notamment en réponse à incidents liés à la fuite de données · Bonne connaissance des concepts réseaux (Layer 4–7), Web Security Gateway, TAP, firewall, inspection TLS, SMTP, HTTP(S), ICAP… · Bonne compréhension des mécanismes DLP Endpoint, y compris leurs limitations techniques · Bonne compréhension des problématiques SaaS et Shadow IT · Bonne compréhension des concepts de gestion des données (classification, labellisation, cycle de vie) · Connaissance des écosystèmes SIEM, ITSM, CASB · Expérience du secteur bancaire et compréhension des enjeux métiers associés · Capacité à vulgariser et sensibiliser les métiers aux problématiques DLP · Capacité d'automatisation appréciée (PowerShell, Python, APIs REST, intégration SIEM) · Des capacités organisationnelles et rédactionnelles ainsi que de la rigueur dans le travail sont des prérequis · Français courant, bonne maîtrise de l'anglais. Sa mission comprendra les tâches suivantes : · Participation active dans l'évolution de nos solutions de Data Security · Définition et optimisation des polices et stratégies de détection et de prévention · Assister l'équipe TDR (Threat Detection and Response) dans la conception et l'amélioration des technologies de protection des données de la banque · Collaboration de manière transversale avec la Blue Team et les équipes de production pour une amélioration continue de notre cyberdéfense · Gestion des alertes DLP dans le cadre de la phase projet · Diagnostic et résolution des incidents techniques liés à nos plateformes de Data Protection.
Voir cette offre
Freelance
CDI

Offre d'emploiDirecteur de Projet IA & Cybersécurité H/F

WINDJ
Publiée le
CyberSoc
Cybersécurité
Direction de projet

6 mois
Paris, France
Dans le cadre d'un programme stratégique de transformation, nous recherchons un(e) Directeur(trice) de Projet IA & Cybersécurité pour piloter une initiative visant à préparer et adapter le système d'information face aux nouveaux enjeux liés à l'essor de l'intelligence artificielle appliquée à la cybersécurité. Vous interviendrez sur un projet à forte visibilité, impliquant de nombreuses parties prenantes et plusieurs entités, avec pour objectif de renforcer les capacités de résilience, d'anticipation et de réponse face aux nouvelles menaces. Vos missions En qualité de Directeur de Projet, vous serez responsable de : Piloter l'ensemble du projet, de son cadrage jusqu'à la livraison des différents chantiers. Définir la stratégie projet, construire la roadmap et assurer le suivi des jalons. Coordonner les équipes métiers, techniques et les différentes entités impliquées. Évaluer l'exposition du système d'information aux nouvelles menaces liées à l'intelligence artificielle. Définir et piloter les plans d'amélioration des capacités de détection, de remédiation et de gestion des vulnérabilités. Accompagner l'évolution des dispositifs de supervision, de réponse aux incidents et d'automatisation des processus de cybersécurité. Mettre en place une gouvernance adaptée aux enjeux de transformation et de gestion de crise. Identifier, suivre et maîtriser les risques techniques, organisationnels et cybersécurité. Assurer l'alignement du projet avec les initiatives existantes en matière de sécurité, d'infrastructure et de transformation digitale. Consolider les livrables, produire les reportings et suivre les indicateurs de performance. Être force de proposition sur les orientations stratégiques liées à l'usage de l'IA dans les dispositifs de cybersécurité.
Voir cette offre
Freelance
CDI

Offre d'emploiAnalyste SOC L2/L3 (H/F)

virtualbrains
Publiée le
Cortex XSOAR
Palo Alto
Security Information Event Management (SIEM)

1 an
40k-45k €
400-420 €
Nanterre, Île-de-France
Dans le cadre du renforcement d'une équipe SOC RUN L2, notre client recherche un Analyste SOC confirmé à senior afin d'assurer la supervision, l'analyse et le traitement des incidents de sécurité dans un environnement international. Vous intégrerez une équipe spécialisée dans la détection et la réponse aux menaces, avec un rôle clé dans l'amélioration continue des capacités de surveillance et de protection du système d'information. Vos missions principales :Superviser en temps réel les alertes de sécurité générées par Splunk Enterprise Security (ES). Analyser et qualifier les alertes afin d'identifier les incidents potentiels. Réaliser des investigations approfondies à partir des logs et événements de sécurité. Effectuer des recherches avancées dans Splunk ES pour confirmer ou écarter les incidents. Identifier la cause, l'impact et le périmètre des incidents détectés. Optimiser les règles de corrélation et améliorer les dashboards Splunk. Participer à l'évolution des procédures et processus SOC. Assurer l'escalade des incidents critiques vers les équipes spécialisées. Documenter les incidents, analyses réalisées et actions de remédiation. Utiliser Microsoft MDx dans le cadre d'investigations avancées. Mettre en œuvre des mécanismes d'orchestration via Palo Alto XSOAR. Rédiger des rapports d'incidents destinés au suivi client. Participer aux réunions avec des équipes internationales en anglais. Assurer une veille permanente sur les nouvelles menaces et technologies cybersécurité. Compétences attenduesSplunk Enterprise Security (ES) : Expert Microsoft MDx : Expert Palo Alto XSOAR : Expert Analyse SOC niveau L2/L3 Investigation d'incidents de sécurité Analyse de logs et événements SIEM Threat Detection & Incident Response Anglais professionnel écrit et oral
Voir cette offre
Freelance
CDI

Offre d'emploiCONSULTANT SOC SIEM ELASTIC SECURITY H/F

Cheops Technology
Publiée le
Elasticsearch
Security Information Event Management (SIEM)
XDR (Extended Detection & Response)

6 mois
40k-45k €
400-490 €
Rouen, Normandie
Détection et analyse des menaces Le prestataire devra notamment :  Identifier, analyser, qualifier et prioriser les alertes de sécurité détectées ;  Évaluer la criticité et l'impact potentiel des alertes sur le système d'information ;  Notifier les alertes de sécurité aux parties prenantes et assurer leur escalade si nécessaire ;  Mener des activités de recherche de compromission (Threat Hunting) afin d'identifier des comportements suspects non détectés automatiquement. Réaction et accompagnement face aux menaces Le prestataire assurera :  La transmission des plans d'action aux équipes responsables du traitement des alertes ;  Un support technique et méthodologique concernant les correctifs ou mesures de contournement à mettre en oeuvre ;  La formulation de recommandations sur les mesures immédiates à appliquer pour limiter les risques ;  L'accompagnement et le suivi du traitement des alertes jusqu'à leur résolution complète. Mise en place des cas d'usage et des outils Le prestataire assurera :  Le développement et le maintien des règles de détection d'événements de sécurité (SIEM, Trend Vision One, etc.) ;  Le maintien opérationnel des dispositifs de supervision Cyber
Voir cette offre
Offre premium
CDI

Offre d'emploiSenior IT Infrastructure & Systems Lead

Nexus Jobs Limited
Publiée le
Administration Windows
Center for Internet Security (CIS)
LAN

£70k-75k
Cité de Westminster, Royaume-Uni
Senior IT Infrastructure & Systems Lead Our Client a bank, in Central London are looking for an experienced IT Infrastructure professional who is ideally looking for their next challenge in a dynamic and regulated financial services environment. We are seeking a highly skilled Senior IT Infrastructure Officer to lead the management, security, and continuous improvement of our enterprise IT infrastructure. The Senior IT Infrastructure Officer will be playing a key role in ensuring the availability, resilience, and performance of critical systems while supporting technologies across servers, networks, cloud services, cybersecurity, and business-critical financial applications. The candidate must have strong technical expertise in Windows/Linux, VMware, Microsoft 365, networking, cybersecurity, and infrastructure management who also enjoys solving complex challenges and driving operational excellence. Must have 7 years' experience in enterprise infrastructure, ideally within banking or financial services, and be passionate about delivering secure, reliable IT services.. The role will be Monday to Friday, 9:30am to 5:30pm and reporting into the Head of IT & Data. Due to the nature of the role, the individual is expected to work in our offices, 5 days per week, during their probationary period This role is totally hands-on. Role Description The Senior IT Infrastructure & Systems Lead is a full-time hybrid role based in London, with flexibility for some work-from-home arrangements. This role is responsible for overseeing the day-to-day operation, maintenance, and improvement of the company's IT infrastructure, including networks, servers, and core systems. The person in this role will lead and mentor technical staff, manage system performance and availability, and coordinate responses to incidents and service requests. Typical tasks include monitoring network and system health, implementing security measures, resolving technical complex issues, planning upgrades, and collaborating with stakeholders to align technology solutions with business needs. The role also involves vendor management, documentation of infrastructure and procedures, and contributing to IT strategy and roadmap decisions. Qualifications · Candidates should possess strong skills in Network Administration and Information Technology for managing and optimizing infrastructure and systems. · Candidates should possess solid Technical Support and Troubleshooting skills to diagnose, resolve, and prevent complex IT issues. · Candidates should possess expertise in Network Security to implement, monitor, and improve security controls and practices. · Extensive experience in leading IT infrastructure projects, including planning, implementation, and migration activities. · Proven ability to manage and mentor IT teams, with strong communication and stakeholder management skills. · Experience with server and cloud technologies, virtualization, backup and recovery, and IT monitoring tools. · Relevant professional certifications (eg, CompTIA Network+, CCNA, MCSE, or similar) are beneficial. · Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Infrastructure & Systems Management · Administer, maintain, and optimize Windows and Linux server environments. · Manage VMware virtualized infrastructure (vSphere 8 and above). · Oversee enterprise backup and disaster recovery solutions using Veeam Backup & Replication. · Manage Veeam ONE monitoring and Veeam Recovery Orchestrator (VRO) environments. · Administer endpoint security and encryption solutions, including Symantec Endpoint Protection (SEP) and Symantec Endpoint Encryption (SEE). · Support endpoint DLP, SIEM, and security monitoring tools (eg, Splunk, Tenable). · Manage patching processes using ManageEngine Patch Manager Plus. · Support Microsoft 365 services and related cloud technologies. · In depth understanding of Cyber ​​security · Monitor system performance, capacity, availability, and infrastructure health. · Ensure compliance with IT governance, security policies, and operational standards. End-User Computing & Branch Support · Provide advanced desktop, laptop, printer, Mobile device (iOS) and branch office IT support. · Deliver AV support for meeting rooms, conferencing, presentations, and collaboration systems. · Manage OS deployment, imaging, image creation, maintenance, and software packaging. · Administer Active Directory (AD), Group Policy Objects (GPOs) and user provisioning and NTFS permissions. · Support Microsoft 365 applications including Outlook, Teams, OneDrive, and SharePoint. · Resolve technical incidents and service requests in line with agreed SLAs. Enterprise Applications & Financial Systems Support · Support and administer business-critical applications, including: · Bloomberg FXT and Refinitiv Eikon, Murex Treasury System, SWIFT Alliance Access (SAA), 1AML, SIBS, GFMS, COP · Support enterprise file synchronization and replication solutions (eg, Syncovery, other SFTP). Networking • Configure and support Cisco switches and routers. • Administer FortiGate firewall environments. • Strong network fundamentals: DNS, DHCP, TCP/IP, LAN/WAN, Routing and connectivity troubleshooting. Monitor network performance, availability, and security posture. Security & Endpoint Management · Support vulnerability management using tools such as Tenable. · Manage security monitoring and log analysis tools (eg, Splunk). · Perform SSL/TLS certificate lifecycle management using OpenSSL. · Create and manage CSRs, certificate chains, and private keys. · Ensure adherence to cybersecurity policies, standards, and regulatory requirements. · Support physical access control systems (eg, Paxton) Operating Systems · Windows 11 · Windows Server 2019/2022 (or equivalent enterprise environments) Red Hat Linux Infrastructure & Virtualization · VMware vSphere / vCenter (v8.0.3 and above) Veeam Backup & Replication Veeam ONE, VRO Microsoft Office 365 · ManageEngine Patch Manager Plus SaaS solutions SQL Server Security · Symantec Endpoint Protection (SEP) · Symantec Endpoint Encryption (SEE) SentinelOne – EDR/XDR Endpoint DLP solutions Firewall administration · Vulnerability management tools (eg, Tenable) SIEM tools (e.g., Splunk) Networking Cisco Switches and Routers · FortiGate Firewalls · LAN/WAN networking and routing Hardware & Storage Dell PowerEdge Servers · Dell PowerVault SAN Storage Education Bachelor or Master's degree or professional qualification in relevant discipline (IT/Information Systems/Computer Science/Technology/Programming/Information Science/System Engineering/Computing) The role is based in Central London and initially will be 5 days per week in the office. This is a 12 month FTC position. The salary for the role will be around £70K - £75K. Do send your CV to us in Word format along with your salary and availability.
Voir cette offre
Freelance
CDI

Offre d'emploiExpert en Cybersécurité - Senior

ALLEGIS GROUP
Publiée le
Cortex XSOAR
Endpoint detection and response (EDR)
Security Information Event Management (SIEM)

3 mois
Villeneuve-d'Ascq, Hauts-de-France
Vous êtes le pivot entre le terrain et le management. Vous incarnez la crédibilité technique tout en portant une vision de service mature et mesurable : Leadership & Management opérationnel Animer, encadrer, organiser le dispositif SecOps composé d'ingénieurs et experts cyber Structurer le traitement des alertes (rotations, priorisation) Être le point de référence technique pour l'équipe, capable de trancher sur les cas complexes Fédérer autour d'une culture de l'amélioration continue Pilotage de la performance Définir, suivre et améliorer les indicateurs clés de performance du dispositif : ex MTTD, MTTR, taux de faux positifs, ... Produire des reportings réguliers à destination du management Identifier les axes d'optimisation et proposer des plans d'action concrets Contribuer activement à la professionnalisation du service Excellence opérationnelle – RUN Superviser l'investigation des alertes de cybersécurité (SIEM, EDR, NDR, threat intelligence...) Garantir la qualité et la cohérence des analyses produites par l'équipe Participer aux crises cyber sur le périmètre France et international Innovation & Build Contribuer à l'implémentation de nouvelles technologies et capacités de détection Challenger les règles de détection et des playbooks de réponse Être force de proposition sur l'évolution du stack technique Vision & Stratégie Effectuer une veille technologique et réglementaire active Collaborer avec les autres domaines de la cybersécurité (IT, métier, ...)
Voir cette offre
CDI

Offre d'emploiArcSight SIEM Engineer (DV Security Clearance)

CGI
Publiée le

Basingstoke, Angleterre, Royaume-Uni
At CGI, we're redefining how technology protects the nation. As an ArcSight SIEM Engineer, you'll play a vital role in a major defence programme—modernising secure data platforms, driving automation, and strengthening the UK's cyber resilience. Working at the forefront of national security, you'll design and support cutting-edge systems that enable faster, smarter threat detection and decision-making. You'll be part of a close-knit team that thrives on collaboration, innovation, and technical excellence—where you'll have the freedom to take ownership of your work, the opportunity to create lasting impact, and the support of a global organisation committed to your growth. CGI was recognised in the Sunday Times Best Places to Work List 2025 and has been named a UK 'Best Employer' by the Financial Times. We offer a competitive salary, excellent pension, private healthcare, plus a share scheme (3.5% + 3.5% matching) which makes you a CGI Partner not just an employee. We are committed to inclusivity, building a genuinely diverse community of tech talent and inspiring everyone to pursue careers in our sector, including our Armed Forces, and are proud to hold a Gold Award in recognition of our support of the Armed Forces Corporate Covenant. Join us and you'll be part of an open, friendly community of experts. We'll train and support you in taking your career wherever you want it to go. Due to the secure nature of the programme, you will need to hold UK Security Clearance or be eligible to go through this clearance. This is a full-time onsite position in Basingstoke (no hybrid/remote working).
Voir cette offre
Freelance

Mission freelanceExpert en cybersécurité

Coriom Conseil
Publiée le
Endpoint detection and response (EDR)
Security Information Event Management (SIEM)
SOC (Security Operation Center)

12 mois
400-550 €
Lille, Hauts-de-France
Définir, suivre et améliorer les indicateurs clés de performance du dispositif Être le point de référence technique pour l'équipe, capable de trancher sur les cas complexes Structurer le traitement des alertes (rotations, priorisation) Compétences techniques SOC, SIEM - Confirmé - Impératif EDR, SOAR - Confirmé - Important IT, Infra - Confirmé - Important Connaissances linguistiques: Anglais Professionnel (Impératif) Description détaillée Vous êtes le pivot entre le terrain et le management. Vous incarnez la crédibilité technique tout en portant une vision de service mature et mesurable : Leadership & Management opérationnel Animer, encadrer, organiser le dispositif SecOps composé d'ingénieurs et experts cyber Structurer le traitement des alertes (rotations, priorisation) Être le point de référence technique pour l'équipe, capable de trancher sur les cas complexes Fédérer autour d'une culture de l'amélioration continue Pilotage de la performance Définir, suivre et améliorer les indicateurs clés de performance du dispositif : ex MTTD, MTTR, taux de faux positifs, ... Produire des reportings réguliers à destination du management Identifier les axes d'optimisation et proposer des plans d'action concrets Contribuer activement à la professionnalisation du service
Voir cette offre
Freelance

Mission freelanceLead SecOps

ESENCA
Publiée le
Endpoint detection and response (EDR)
Infrastructure
SecOps

1 an
Lille, Hauts-de-France
Contexte de la missionDans le cadre du renforcement de son dispositif de cybersécurité, notre client recherche un Responsable SecOps pour piloter une équipe d'experts techniques et garantir l'efficacité opérationnelle du SOC. Véritable référent technique, vous assurez le lien entre les équipes opérationnelles et le management, tout en contribuant à l'amélioration continue des capacités de détection et de réponse aux incidents. Vos missionsPilotage opérationnelAnimer et coordonner une équipe d'ingénieurs et d'experts SecOps. Organiser le traitement des alertes (priorisation, rotations, escalades). Être le référent technique de l'équipe et intervenir sur les incidents les plus complexes. Développer une culture d'amélioration continue et d'excellence opérationnelle. Suivi de la performanceDéfinir, suivre et faire évoluer les indicateurs de performance (MTTD, MTTR, taux de faux positifs, SLA, etc.). Produire des tableaux de bord et reportings à destination du management. Identifier les axes d'amélioration et piloter les plans d'actions associés. Participer à la montée en maturité du dispositif SecOps. Exploitation et gestion des incidents (RUN)Superviser les investigations menées sur les alertes de cybersécurité. Garantir la qualité des analyses et des réponses apportées par l'équipe. Participer à la gestion des incidents majeurs et des crises cyber, en France comme à l'international. Veiller au maintien en conditions opérationnelles des outils de sécurité. Amélioration continue & InnovationParticiper à l'intégration de nouvelles technologies de détection et de réponse. Optimiser les règles de détection, les cas d'usage SIEM et les playbooks SOAR. Être force de proposition sur les évolutions techniques et organisationnelles du dispositif. Gouvernance & CollaborationAssurer une veille technologique et réglementaire. Collaborer avec les équipes Infrastructure, Réseau, IT et les autres domaines de la cybersécurité. Contribuer à la définition de la stratégie de sécurisation des environnements. Environnement techniqueSIEM (impératif) SOC EDR SOAR Infrastructures IT Outils de Threat Intelligence et de détection
Voir cette offre
Offre premium
CDI

Offre d'emploiIT Support Analyst/Engineer with Level 1 and Level 2

Nexus Jobs Limited
Publiée le
DHCP (Dynamic Host Configuration Protocol)
LAN
Microsoft SQL Server

£55k-60k
Cité de Westminster, Royaume-Uni
IT Support Analyst/Engineer with Level 1 and Level 2 Role Description This full-time IT Support Analyst/Engineer role covers both Level 1 and Level 2 support and is offered on a hybrid basis, with work primarily in London and some work from home flexibility. Day-to-day responsibilities include handling incoming support tickets, responding to user queries, and providing first-line technical assistance for hardware, software, and network issues. The role also involves performing more advanced second-line diagnostics, resolving complex incidents, escalating problems when required, and updating documentation and knowledge bases. The IT Support Analyst/Engineer will install and configure systems, manage user accounts and access permissions, monitor system performance, and assist with routine maintenance tasks and upgrades. Collaboration with other IT team members and clear communication with non-technical users are key aspects of the position. Qualifications · Candidates should possess strong Technical Support and Information Technology skills, including experience with common operating systems, hardware, and business applications. · Candidates should possess solid Analytical Skills and Troubleshooting abilities to diagnose issues, identify root causes, and deliver effective solutions. · Candidates should possess clear and professional Communication skills, with the ability to explain technical concepts to users at different levels of technical understanding. · Relevant certifications such as CompTIA A+, Network+, Microsoft, or similar credentials are beneficial, along with experience in Level 1 and Level 2 support environments. · Ability to work in a hybrid setting, manage priorities in a busy service desk environment, and maintain a customer-focused, inclusive approach when supporting diverse user groups. For this position you will have at least 5 years experience in IT as an IT Support Engineer with 1st and 2nd Level support experience - ideally in the Banking/Financial industry. In-depth knowledge of and troubleshooting experience with Windows, Office applications and conferencing applications. Responsible for the support and maintenance of the IT infrastructure and to provide IT support to staff and other group colleagues. To assist in the response to service outages and other IT related problems as well as maintenance and upkeep of for security of the systems in place. · To provide IT Support and assistance to the branch's staff in a timely manner. · Responsible for the maintenance of the IT infrastructure of the Branch by providing first & Second line support of software, hardware and networking that includes installation, configuration and troubleshooting. Support endpoint security standards (antivirus/firewall/patching/two-factor authentication). · Provide day to day support to the Admin and HR function to cover: joiners/leavers/movers process, CCTV & Paxton Card Access. · Assist the IT Manager in delivering various IT related projects by managing the day to day operational aspects of such projects. · End User Computing support for all staff. (eg Install, configure, and maintain desktops, laptops, printers, Phones/Mobiles and other IT equipment.) · Networking Fundamentals – DNS, DHCP, TCP/IP, and LAN/WAN. · Good understanding of cybersecurity measures · Coordinator between the London Users and Group IT Security on all requests for systems access and to ensure that such permissions are provided promptly, are regularly updated and that the Group Access Matrix Protocol is followed at all times. · Preserve the Assets of the Office by implementing Disaster Recovery and back up procedures and ensuring that the standards comply with Group requirements. · Provide IT support to ensure the smooth running of daily and periodic reports for the London Compliance team to ensure adherence to the Anti Money Laundering Provisions. · Undertake Data Extraction for reporting requirements for all the other stakeholders at the branch. · To hold Administrator function for some of the systems housed at the Office. Responsible for the granting of access and maintenance of system matrixOverall networking equipment monitoring (ie Network Switches, Firewall and other appliances) and support inclusive of the server room. · To plan and carry out maintenance checks to ensure IT Operations, infrastructures are running smoothly and ensure daily routine task completeness. · Manage inventory of computers, network equipment including tracking of purchased equipment and services. · To maintain and ensure that the BCP site is always ready for continuous bank operations · Important Business Services - IBS owner is to ensure the resilience of the IBS they are responsible for (Ensure appropriate RCSAs, CETs, KRIs are in place to monitor procedures and controls within their units) · Assist the HOD/Manager with implementing/putting in place, any applicable training/guidance/SOPs to staff relating to cyber security & operational resilience. · To maintain the branch Avaya IP Office Phone system and to ensure that the recording system is always up and running at all times. · To perform monthly infrastructure test and report for Risk Assessment. · Manage Incident Handling procedure (This includes monitoring as well as post-incident follow up). · Respond to IT service requests and incidents in a timely manner, prioritizing based on business impact, especially for critical banking functionsSupport the Branch operations as and when needed and any other tasks assigned by Management of the Branch. Data Integrity and Compliance Operationalize data strategy and communicate to the Data Owner or the Management any changes in their BAU requirements which involve data. · To ensure all data worked on and or/shared with internal/external clients are accurate, compliant and maintained in accordance with Company's data quality standards. · Handle all data in strict alignment with the General data protection Regulations (GDPR) principles. · Keep track of documents created by the team. · Escalate any suspected data breaches or privacy issues to the DPO promptly and without delays. · Ensuring any data sharing requests are discussed with HOD/DPO so that prior authorization is given and follows GDPR / department's SOPs. · Collaborate with DPO on data Protection Impact Assessment when introducing new systems or processes to ensure privacy risks are mitigated at the outset. Technical Skills Required - Proficient in common operating systems (Windows 11 and Linux, Server 2016 and later) - Providing AV support for branches - Software proficiency – O365, Onedrive, Teams, Sharepoint, Bloomberg, FXT, SEP, SEE, ME Endpoint Protection, Murex, Swift, 1AML, SIBS, GFMS, COP, Refinitiv, Syncovery, SQL Server, Paxton, VBR, VRO and VeeamOne - Proficient in Imaging windows machines, image creation & management, GPO, and AD - Networking Fundamentals – DNS, DHCP, TCP/IP, and LAN/WAN. - Good understanding of Vmware; ESXI, vSphere, vCenter, Fortigate Firewalls, Cisco Switches - Good understanding of patching practices and troubleshooting - Install, configure, and maintain desktops, laptops, printers, Phones/Mobiles and other IT equipment. - AV support (conference phones, Logitech meeting room solutions etc.) - Proficient in programming languages - Project management - Data analysis and reporting Bachelor or Master's degree or professional qualification in relevant discipline (IT/Information Systems/Computer Science/Technology/Programming/Information Science/System Engineering/Computing) This is a 5 days in the office role in Central London. Salary for this role will be around £55K - £60K. Do send your CV to us in Word format along with your salary and availability.
Voir cette offre
Offre premium
CDI

Offre d'emploiIT Infrastructure & Systems Manager

Nexus Jobs Limited
Publiée le
Microsoft Windows
Security Information Event Management (SIEM)
SWIFT

£60k-65k
Cité de Westminster, Royaume-Uni
IT Infrastructure & Systems Manager We are seeking an experienced and highly motivated Senior IT Infrastructure Manager with at least 7 to 10 years experience to oversee, manage, and continuously improve the organization's IT infrastructure, enterprise systems, network environment, and end-user computing services. The successful candidate will ensure the availability, security, performance, and resilience of critical business systems while leading technical teams and supporting key stakeholders across the organization. This role requires a strong blend of technical expertise, leadership capability, operational excellence, and stakeholder management skills, within a complex enterprise environment that includes financial, trading, and treasury systems. Role Description The IT Infrastructure & Systems Manager is a full-time role based in London with a hybrid working arrangement, combining on-site presence with some work from home. This role is responsible for managing and maintaining the organization's core IT infrastructure, including servers, networks, storage, and cloud services. Day-to-day tasks include overseeing system administration, monitoring performance and availability, implementing security best practices, and coordinating backup and disaster recovery processes. The role involves leading and supporting IT operations, resolving complex technical issues, and ensuring that systems, applications, and services remain stable and secure. The IT Infrastructure & Systems Manager will collaborate with internal stakeholders, manage vendors and service providers, contribute to IT strategy and roadmaps, and document procedures, standards, and configuration changes. Qualifications · Strong foundation in Information Technology and IT Operations, including infrastructure design, capacity planning, and service management. · Hands-on experience with System Administration and Troubleshooting across Windows and/or Linux environments, virtualization, and cloud platforms. · Proficiency in Network Security, including firewalls, VPNs, endpoint protection, access control, and security monitoring. · Proven ability to manage IT projects, prioritize tasks, and deliver improvements on time and within scope. · Excellent communication and stakeholder management skills, with the ability to explain technical concepts to non-technical audiences. · Experience leading or mentoring IT team members or support staff is highly desirable. · Relevant certifications (eg, ITIL, Microsoft, Cisco, CompTIA, or cloud certifications) are an advantage. · Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Infrastructure & Systems Management Administer, maintain, and optimize Windows and Linux server environments. Manage VMware virtualized infrastructure (vSphere 8 and above). Oversee enterprise backup and disaster recovery solutions using Veeam Backup & Replication. Manage Veeam ONE monitoring and Veeam Recovery Orchestrator (VRO) environments. Administer endpoint security and encryption solutions, including Symantec Endpoint Protection (SEP) and Symantec Endpoint Encryption (SEE). Support endpoint DLP, SIEM, and security monitoring tools (eg, Splunk, Tenable). Manage patching processes using ManageEngine Patch Manager Plus. Support Microsoft 365 services and related cloud technologies. In depth understanding of Cyber ​​security Monitor system performance, capacity, availability, and infrastructure health. Ensure compliance with IT governance, security policies, and operational standards. End-User Computing Support Provide advanced desktop, laptop, printer, Mobile device (iOS) and branch office IT support. Deliver AV support for meeting rooms, conferencing, presentations, and collaboration systems. Manage OS deployment, imaging, image creation, maintenance, and software packaging. Administer Active Directory (AD), Group Policy Objects (GPOs) and user provisioning and NTFS permissions. Support Microsoft 365 applications including Outlook, Teams, OneDrive, and SharePoint. Resolve technical incidents and service requests in line with agreed SLAs. Enterprise Applications & Financial Systems Support Support and administer business-critical applications, including: Bloomberg FXT and Refinitiv Eikon, Murex Treasury System, SWIFT Alliance Access (SAA), 1AML, SIBS, GFMS, COP Support enterprise file synchronization and replication solutions (eg, Syncovery, other SFTP). Networking Configure and support Cisco switches and routers. Administer FortiGate firewall environments. Strong network fundamentals: DNS, DHCP, TCP/IP, LAN/WAN, Routing and connectivity troubleshooting. Monitor network performance, availability, and security posture. Security & Endpoint Management Support vulnerability management using tools such as Tenable. Manage security monitoring and log analysis tools (eg, Splunk). Perform SSL/TLS certificate lifecycle management using OpenSSL. Create and manage CSRs, certificate chains, and private keys. Ensure adherence to cybersecurity policies, standards, and regulatory requirements. Support physical access control systems (eg, Paxton) Governance, Documentation & Process Improvement Develop, maintain, and enforce IT policies, standards, and operational procedures. Produce system architecture diagrams, technical documentation, SOP's, and performance reports. Identify and drive opportunities for automation and service improvement. Support technology planning, infrastructure modernization, and transformation initiatives. Operating Systems Windows 11 Windows Server 2019/2022 (or equivalent enterprise environments) Red Hat Linux Infrastructure & Virtualization VMware vSphere / vCenter (v8.0.3 and above) Veeam Backup & Replication Veeam ONE, VRO Microsoft Office 365 ManageEngine Patch Manager Plus SaaS solutions SQL Server Security Symantec Endpoint Protection (SEP) Symantec Endpoint Encryption (SEE) SentinelOne – EDR/XDR Endpoint DLP solutions Firewall administration Vulnerability management tools (eg, Tenable) SIEM tools (e.g., Splunk) Networking Cisco Switches and Routers FortiGate Firewalls LAN/WAN networking and routing Hardware & Storage Dell PowerEdge Servers Dell PowerVault SAN Storage Technical Competencies Data analysis and operational reporting Desktop and laptop support Infrastructure monitoring and performance management Certificate lifecycle management (SSL/TLS) Windows imaging and deployment, GPO, NTFS PowerShell scripting SQL Server administration Understanding of software development lifecycle (SDLC) and deployment processes Architecture review and systems optimization Asset management 7+ years of experience in enterprise IT infrastructure and systems administration. Experience within financial services, banking, trading, or treasury environments. Proven experience managing mission-critical infrastructure and applications. Experience operating within regulated and security-focused environments. Able to provide support to VIP stakeholders This is a hybrid role with 3 days at the office in Central London. Salary for this role will be in the range £60K - £65K. Do send your CV to us in Word format along with your salary and availability.
Voir cette offre
Freelance
CDI

Offre d'emploiConsultant Senior Cloud Security AWS – SOC

PSSWRD
Publiée le
AWS Cloud
Cloud
CyberSoc

6 mois
Issy-les-Moulineaux, Île-de-France
Cher réseau bonjour, 👀 Dans le cadre du renforcement d'un SOC, je recherche un consultant Expérimenté Cloud Security AWS pour l'un de nos clients basé à Issy-Les-Moulineaux (92), qui sera le référent technique sur les problématiques de sécurité des environnements AWS. Il interviendra sur la définition, la mise en œuvre et l'amélioration continue des capacités de détection et de réponse aux incidents de sécurité sur les environnements Cloud, en cohérence avec les processus opérationnels du SOC. 🏁 MISSION • Le consultant a pour mission de développer et d'industrialiser les capacités opérationnelles du SOC sur le périmètre AWS. Il construit les processus de réponse aux incidents Cloud, assure l'intégration des mécanismes de détection AWS au sein du SOC et contribue à l'amélioration continue de la visibilité et de la posture de sécurité des environnements Cloud. • Il travaille en étroite collaboration avec les équipes SOC, Cloud, DevSecOps, Infrastructure et le Vulnerability Operations Center (VOC). 💪 PÉRIMÈTRE • Le périmètre couvre exclusivement les activités de détection, qualification, investigation et réponse aux incidents de sécurité sur AWS ; • Les problématiques de misconfiguration (CSPM), bien qu'identifiées notamment par Wiz, ne relèvent pas du SOC ni du VOC. Elles sont hors périmètre de cette fonction et sont prises en charge par les équipes DevSecOps selon les processus de remédiation établis ; • Le consultant peut contribuer à la qualification initiale afin de déterminer si une alerte relève d'un incident de sécurité ou d'une simple erreur de configuration, puis orienter celle-ci vers l'équipe compétente. 🎯 RESPONSABILITÉS PRINCIPALES 1. Construction des capacités SOC Cloud • Définir et mettre en œuvre le processus de réponse aux incidents de sécurité sur AWS ; • Concevoir les playbooks et runbooks dédiés aux incidents Cloud ; • Intégrer les processus Cloud aux procédures opérationnelles existantes du SOC ; • Définir les workflows entre le SOC, les équipes Cloud, DevSecOps et les équipes d'exploitation ; • Participer à l'amélioration continue des capacités de détection et de réponse. 2. Détection et investigation • Exploiter les détections de sécurité issues de Wiz relatives aux menaces, compromissions et comportements suspects ; • Qualifier les alertes afin de distinguer les incidents de sécurité des constats de configuration ; • Développer de nouveaux cas d'usage de détection adaptés aux environnements AWS ; • Réaliser les investigations de sécurité sur les incidents Cloud ; • Identifier les causes racines et proposer les actions de confinement et de remédiation. 3. Exploitation des journaux AWS • Définir les sources de logs AWS à intégrer au SIEM ; • Exploiter les journaux AWS (CloudTrail, GuardDuty, VPC Flow Logs, CloudWatch, etc.) afin d'améliorer les capacités de détection ; • Développer les règles de corrélation et les cas d'usage SOC autour des événements AWS ; • Garantir la qualité et la couverture des données de sécurité Cloud. 4. Réponse aux incidents • Piloter les investigations de sécurité sur les environnements AWS ; • Accompagner les équipes techniques lors des opérations de confinement, d'éradication et de remédiation ; • Participer aux cellules de crise lors des incidents majeurs impliquant le Cloud ; • Produire les rapports d'incident, les analyses de causes racines et les retours d'expérience. 5. Gouvernance et amélioration continue • Définir les indicateurs de performance des activités SOC Cloud ; • Contribuer à l'évolution des standards opérationnels de sécurité Cloud ; • Assurer une veille sur les menaces ciblant AWS ; • Être le référent technique Cloud Security auprès des analystes SOC. 6. Contribution au Vulnerability Operations Center (VOC) En complément de ses activités principales, l'expert contribue ponctuellement au Vulnerability Operations Center (VOC) dans les situations nécessitant une expertise Cloud, notamment pour : • l'analyse des vulnérabilités affectant les ressources AWS ; • la qualification du risque associé aux vulnérabilités détectées ; • l'évaluation de leur exploitabilité dans le contexte de l'entreprise ; • le support aux équipes de remédiation lorsque l'expertise Cloud est requise. Le traitement des misconfigurations (CSPM), des écarts de conformité et des recommandations de durcissement identifiés par Wiz ne relève pas du SOC ni du VOC et est pris en charge par les équipes DevSecOps. 💪 LIVRABLES ATTENDUS • Processus de réponse aux incidents AWS ; • Playbooks et runbooks SOC Cloud ; • Catalogue des cas d'usage de détection AWS ; • Règles de corrélation SIEM basées sur les logs AWS ; • Documentation opérationnelle SOC Cloud ; • Tableaux de bord et indicateurs de performance ; • Rapports d'investigation et retours d'expérience.
Voir cette offre
Freelance

Mission freelanceCoordinateur Cybersécurité Opérationnelle

LOIC CAROLI SAS
Publiée le
AWS Cloud
Azure
sailpoint

6 mois
500-710 €
Nantes, Pays de la Loire
Missions principales : Assurer le reporting mensuel de l'activité Sécurité au travers d'un dashboard mensuel (SOC, VOC, Sectools, IAM) Contribuer au bon fonctionnement des activités Sécurité (SOC, VOC, Sectools, IAM) au sein de la DSI en assurant la coordination entre les parties prenantes Être le point de contact principal pour les questions Sécurité (RSSI, Audit Interne & Externe…) et la contribution aux réponses d'audit sur le périmètre cyber Proposer des améliorations pour optimiser les ressources existantes et leur organisation Travailler en binome avec le Service Manager afin d'assurer un delivery de qualité de la part du partenaire en charge du périmètre. Travailler en binome avec l'Architecte Sécurité afin d'assurer le traitement des workflows nécessitant une validation Sécurité et contribuer à la sécurité dans les projets Gestion des incidents de sécurité Contribuer et accompagner l'équipe SOC dans le traitement des incidents Être le point de contact transverse pour les sollicitations nécessitant une investigation par les équipes Sécurité (Signalement Interne, DPO, Equipes IT, Business…) Assurer la remontée et le traitement des incidents liés à la surveillance externe Gestion des vulnérabilités Contribuer et accompagner l'équipe VOC dans le pilotage et le suivi des demandes de remédiations liées aux vulnérabilités identifiées sur le périmètre Applicatif, Système, Middleware et dans le code déployé au sein des infrastructures Outillage Sécurité Assurer la coordination des activités du fournisseur avec les différents services de l'entreprise Contribuer au suivi auprès des partenaires en cas de demande d'évolution sur les technologies de sécurité Veille Cyber Assurer une veille externe sur les nouvelles technologies de cybersécurité
Voir cette offre

Au service des talents IT

Free-Work est une plateforme qui s'adresse à tous les professionnels des métiers de l'informatique.

Ses contenus et son jobboard IT sont mis à disposition 100% gratuitement pour les indépendants et les salariés du secteur.

Free-workers
Ressources
A propos
Espace recruteurs
2026 © Free-Work / AGSI SAS
Suivez-nous