Trouvez votre prochaine offre d’emploi ou de mission freelance Single Sign-on (SSO)

Votre recherche renvoie 71 résultats.
CDI

Offre d'emploiIT Operations and Security Lead

Nexus Jobs Limited
Publiée le

£85k-95k
Grand Londres, Royaume-Uni
IT Operations Platforms and Security Lead In summary the Client is looking to recruit an all-round individual with expert knowledge and hands-on experience of IT Infrastructure coupled with Security, Compliance & Risk Management You must have upwards of 10 years hands-on expertise in IT Infrastructure combined with Security and Risk – ideally from within the banking or insurance sector. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third-party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third-party vendors to deliver a high-quality Global IT services. Working in line with the Architecture defined IT principle of a "buy before build" environment, the individual will need to ensure that outsourced and cloud-based services are robust, cost-effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity of the estate, current transformation activities and team size, the role requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles/services as a requirement, across multiple technical areas. Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero-trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud-first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge, Microsoft AD (Entra), Server and SQL experience, O365 administration and design Global Software Patching and estate management via Intune Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience Software Defined Networking (Cisco, Meraki, Versa) Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD-WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL-based service management, automating operational tasks, and optimising service delivery. Operational & Leadership Skills: IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third-party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost-effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Skills & Mindset: Problem-Solving & Decision-Making: Capable of making informed decisions and resolving complex IT issues in a fast-paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non-technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security-first approach. The Client is a financial organisation based in the City of London. This is a hybrid position with 3 days in the office. Must have a Bachelor's degree in IT or similar. The salary for this role will be in the range £85K - £95K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
Voir cette offre
CDI

Offre d'emploiIT Operations Platforms and Security Lead

Nexus Jobs Limited
Publiée le

£85k-100k
Grand Londres, Royaume-Uni
IT Operations Platforms and Security Lead This role requires excellent management of a small team in IT along with managing stakeholders and vendors. You must be hands-on technically in IT Infrastructure. The IT Operational Platform and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi layered networking, security, data management, and third-party platforms that support global business operations and the associated applications estate. The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third-party vendors to deliver a high-quality Global IT services. Working in line with the Architecture defined IT principle of a "buy before build" environment, the individual will need to ensure that outsourced and cloud-based services are robust, cost-effective, and aligned with business needs and the Strategic IT vision. They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity Security, Compliance & Risk Management Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero-trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud-first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services. Oversee endpoint security, cloud network and API security for robust protection across all assets Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests. Technical Experience Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge, Microsoft AD (Entra), Server and SQL experience, O365 administration and design Global Software Patching and estate management via Intune Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience Software Defined Networking (Cisco, Meraki, Versa) Key Skills Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD-WAN, DNS security, endpoint protection, and cloud security controls. IT Service Management & Automation: Experience implementing ITIL-based service management, automating operational tasks, and optimising service delivery. Operational & Leadership Skills: IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery. Supplier & Vendor Management: Experience managing third-party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost-effectiveness. Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption. Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls. Soft Skills & Mindset: Problem-Solving & Decision-Making: Capable of making informed decisions and resolving complex IT issues in a fast-paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non-technical stakeholders, including senior leadership and business users. Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security-first approach. Summary of Skills Required: Global Enterprise level Infrastructure Management position for the last 5 years, Global team management (human resources, strategic delivery, operational service, audit lead for Infra, budget..) Key - 3 party operational infrastructure vendor management - i.e management of managed service partners, Migration of Legacy VM based estates to SaaS and Cloud services platforms, Legacy tech to Azure knowledge/experience, Prior to the last 5 years, a technical infrastructure engineering level background, working on Windows Server, AD , SQL environments, Firewalls/SDWAN, and Networks (WAN &/or LAN). The Client is based in the City of London. This is a hybrid position with 3 days in the office. The salary for this role will be in the range £85K - £100K plus Benefits. Do send your CV to us in Word format along with your salary and notice period.
Voir cette offre
CDI

Offre d'emploiHead of IT Infrastructure and Security

Nexus Jobs Limited
Publiée le

£85k-95k
Grand Londres, Royaume-Uni
Head of IT Infrastructure and Security In summary we are looking to recruit an all-round individual with expert knowledge and hands-on experience of IT Infrastructure coupled with Security, Compliance & Risk Management You must have upwards of 10 years hands-on expertise in IT Infrastructure combined with Security and Risk – ideally from within the banking or insurance sector. The Head of IT Infrastructure and Security Lead is responsible for overseeing the organisation's IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. Some of the key points to consider for this role are: Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data. Oversee the adoption of zero-trust security principles to enhance protection across cloud platforms. Manage identity and access management (IAM) in a cloud-first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Technology: Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge, Microsoft AD (Entra), Server and SQL experience, O365 administration and design Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel. Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices. Summary: Problem-Solving & Decision-Making: Capable of making informed decisions and resolving complex IT issues in a fast-paced environment. Stakeholder Engagement: Ability to communicate effectively with technical and non-technical stakeholders, including senior leadership and business users. The role will involve managing a Cloud environment in a team of 4 Technical people. Managing 6 different suppliers which include Security, IT Networks, Hosting and Servers and 3 party software. The aim of the role is to bring the MSP's (suppliers of hardware and software) to the same page for the stakeholders and the Board and ensure technology is running smoothly. The Client is a financial organisation based in the City of London. This is a hybrid position with 3 days in the office. Must have a Bachelor's degree in IT or similar. The salary for this role will be in the range £85K - £95K plus Excellent Benefits. Do send your CV to us in Word format along with your salary and notice period.
Voir cette offre
Freelance

Mission freelanceSenior Full Stack Développeur Data & AI Applications (H/F)

HOXTON PARTNERS
Publiée le
Large Language Model (LLM)
Python
React

12 mois
Paris, France
Hoxton Partners recherche un Senior Full Stack Developer spécialisé dans le développement d'applications Data & AI afin d'intervenir sur un programme stratégique de transformation digitale. La mission consiste à concevoir et développer des applications web sur mesure, data-intensive et AI-native, principalement sur l'écosystème Google Cloud Platform. Le consultant interviendra de bout en bout sur la chaîne applicative, depuis l'exploitation des données dans BigQuery jusqu'à l'intégration d'agents IA et à la création d'interfaces utilisateurs avancées. Le rôle est fortement orienté développement et nécessite une excellente maîtrise de React.js, TypeScript et Python. Le consultant sera responsable de la qualité et de la maintenabilité des solutions produites, avec un véritable ownership sur l'ensemble du cycle de développement. Les principales responsabilités seront les suivantes : Concevoir et développer des applications web responsives et data-intensive en React.js et TypeScript Créer des interfaces utilisateurs avancées, ergonomiques et conformes aux maquettes Figma Développer des composants réutilisables, des filtres complexes et des visualisations interactives Intégrer des agents IA et des modèles LLM directement dans les applications web Mettre en œuvre des fonctionnalités conversationnelles, du streaming de réponses et du tool-calling Développer des API et des services backend en Python Concevoir les connecteurs et les flux entre BigQuery, les agents IA et les interfaces utilisateurs Intégrer des fonctionnalités d'embedded analytics avec Looker Embed SDK et les API Looker Participer à la transition progressive de certains usages Power BI vers Looker Déployer et exploiter les applications sur Google Cloud Platform Utiliser notamment Cloud Run, App Engine, Vertex AI, BigQuery et IAM Mettre en place les mécanismes de sécurité de bout en bout : SSO, OAuth, IAM et Row Level Security Appliquer les bonnes pratiques de développement : Git, CI/CD, clean code, DRY et atomic design Garantir la performance, la robustesse et la maintenabilité du code livré Utiliser de manière responsable les outils de développement assistés par IA tels que Cursor, GitHub Copilot ou Gemini Conserver une maîtrise complète et une compréhension précise de l'ensemble du code produit
Voir cette offre
Freelance
CDI

Offre d'emploiAdministrateur/Ingénieur Systèmes Windows / Virtualisation (VMware / Citrix) chez AESIO Mutuelle

Deodis
Publiée le
Active Directory
Citrix
OS Windows

6 mois
44k-55k €
360-410 €
Lyon, Auvergne-Rhône-Alpes
Administrateur/Ingénieur Systèmes Windows / Virtualisation (VMware / Citrix) – H/F en pré-embauche chez Aesio Mutuelle. Contexte Au sein du Domaine Infrastructures & Production, vous assurez le RUN et contribuez activement au BUILD des plateformes Windows Server, VMware vSphere, Citrix Virtual Apps & Desktops ainsi que des services Active Directory supportant les applications métiers d'AÉSIO. Vous intervenez sur des environnements à forte disponibilité, avec des enjeux de sécurité, industrialisation et amélioration continue. Vos missions 1) Administration & exploitation Windows Server (v. 2016–2022) · Administrer les services système : GPO, DNS, DFS, ADCS/PKI, services de fichiers, etc. o Déploiement et maintien de GPO de durcissement (baselines) + gestion des exceptions documentées o Mise en place/optimisation DFS (namespace, réplication, diagnostic de latence) o Gestion des rôles Windows (RDS composants, services applicatifs, etc.) 2) Identités & annuaires (AD / ADFS / Entra ID) · Administrer et faire évoluer l'écosystème d'identités : Active Directory, ADFS, Entra ID o Optimisation Sites & Services (topologie, coûts, subnets, RBAC) o Contribution à des chantiers d'hybridation (synchronisation, SSO, MFA, conditional access ) o Création et MCO de trusts SAML / OPENID 3) Virtualisation VMware (vSphere / vCenter) · Exploiter et faire évoluer la plateforme : HA/DRS, clusters, datastores, templates, backup/restore, capacity planning. o Création/maintien de templates standardisés & patching images o Analyse de performance (CPU Ready, contention stockage) + recommandations o Mise en œuvre de bonnes pratiques HA/anti-affinité + préparation aux opérations de PRA 4) Virtualisation applicative & postes – Citrix (CVAD) · Administrer les environnements Citrix Virtual Apps & Desktops et composants associés (XenApp/CVAD, StoreFront, Delivery Controllers, Netscaler). o Création et Mise à jour de catalogues de machines, gestion des images (MCS) o Diagnostic d'incidents niveau 2 perf/session (ICA RTT, logon duration, profils) o Pilotage d'évolutions : montée de version, durcissement TLS, optimisation d'accès externe 5) Sécurisation des accès & bastion (Wallix) · Exploiter et administrer Wallix (Bastion), comptes techniques, coffres, sessions, traçabilité. o Industrialisation des onboardings (comptes, ressources, approbations) o Revue des accès, traçabilité, et alignement avec exigences conformité o Gestion des incidents (problèmes d'accès à la plateforme) 6) Automatisation & industrialisation · Développer et maintenir des automatisations : PowerShell, Ansible (selon usage interne). o Scripting PowerShell robuste (logs, erreurs, idempotence) pour routines de MCO et contrôles d'intégrité IT (checks AD, inventaires, taches complexes répétitives et mailing.) o Playbooks Ansible pour standardisation configuration, déploiements récurrents, post-install 7) Cycle de vie certificats / PKI · Administrer ADCS/PKI et la gestion des certificats (génération, déploiement, renouvellement). o Création et renouvellement et déploiement de certificats services (Citrix, IIS, LDAPS, etc…) sans rupture o Mise en place d'alerting sur expirations et procédures de rollback 8) Supervision & observabilité · Intégrer/maintenir la supervision (Centreon/Nagios ou équivalent), améliorer les indicateurs et la visibilité. o Création de sondes ou checks spécifiques o Mise en place de dashboards & seuils pertinents + réduction du bruit d'alerting 9) Sécurité & conformité · Appliquer les exigences sécurité : durcissement OS, patching, gestion vulnérabilités, conformité. o Pilotage patching mensuel (WSUS/ANSIBLE) & gestion des exceptions o Traitement des vulnérabilités (priorisation, correctifs, compensations) o Contribution aux audits (preuves, logs, configurations), et application des recommandations SSI 10) Support N2/N3 & gestion des problèmes · Intervenir en escalade sur incidents complexes, contribution à la résolution durable. o Analyse RCA (Root Cause Analysis), mise en œuvre actions correctives o Participation aux revues post-incident et à l'amélioration continue 11) Documentation & partage · Produire et maintenir la documentation d'exploitation et d'architecture. o Procédures (MOP), checklists de déploiement, schémas de flux, runbooks o Capitalisation sur incidents récurrents et automatisation des résolutions Environnement technique : · Windows Server 2016–2022 · Active Directory / ADCS / GPO / DNS / DFS · VMware vSphere / vCenter – Backup IBM TSM · Citrix Virtual Apps & Desktops (CVAD), NetScaler/ADC · PowerShell, Ansible · WSUS / Cyberwatch · Centreon / Nagios · Wallix Bastion Profil recherché · 5–7 ans minimum sur des environnements Windows/AD, VMware et Citrix à l'échelle entreprise. · Très bonne maîtrise AD : design, Sites & Services, Tiering AD, RBAC, DNS & Réplication. · Véritables compétences virtualisation serveur (VMWare de préférence). · Bonne maîtrise Citrix (architecture + exploitation + diagnostic). · PowerShell : scripts propres, robustes, standardisés. · Notions réseau solides : TCP/IP, VLAN, flux, LB, certificats/TLS. · Qualités : curiosité, autonomie, rigueur, sens du service, esprit d'équipe, capacité à documenter. Atouts (bonus, mais pas bloquants) · Expérience PRA/PCA, sauvegarde/restauration, plan de reprise. · Connaissance ITIL (incident/change/problem), outils de ticketing, astreintes/rotations. · Sécurité : baselines CIS/Microsoft, LAPS, etc.
Voir cette offre
Freelance

Mission freelanceBeyond Trust SME

LA International Computer Consultants Ltd
Publiée le

30 mois
M6 7WQ, Salford, England, United Kingdom
BeyondTrust SME (Privileged Access Management) 6 months Location: Manchester and Inverness | 5 days onsite £550 inside IR35 We are seeking two experienced BeyondTrust SMEs to support the transition and ongoing operation of a Privileged Access Management (PAM) service. The successful candidates will provide hands-on administration, support, troubleshooting, and knowledge transfer activities across the BeyondTrust platform, working closely with customer SMEs and operational teams. They will play a key role in ensuring secure management of privileged access, supporting integrations with Active Directory and Microsoft Entra ID, and assisting with the transfer of service knowledge into the run organisation. Key Responsibilities 🔷 Provide hands-on administration and support for the BeyondTrust platform, including Privileged Access Management (PAM) capabilities. 🔷 Support knowledge transfer sessions and documentation review during transition activities. 🔷 Manage and maintain privileged access policies, user access controls, and security configurations. 🔷 Work with Active Directory and Microsoft Entra ID to support authentication, authorisation, group management, and role-based access controls. 🔷 Configure and maintain integrations between BeyondTrust and identity services including SAML, MFA, and directory services. 🔷 Support troubleshooting and resolution of operational incidents, service requests, and platform issues. 🔷 Assist with onboarding and offboarding privileged users and privileged accounts. 🔷 Support policy management and Group Policy-related configurations that interact with BeyondTrust services. 🔷 Participate in hypercare activities and provide operational support during service stabilisation. 🔷 Produce and maintain technical documentation, operational procedures, and support knowledge articles. 🔷 Collaborate with infrastructure, security, and service management teams to ensure service continuity and compliance. Essential Skills & Experience 2-3+ years hands-on experience supporting and administering BeyondTrust. Good understanding of Privileged Access Management (PAM) concepts and best practices. Experience with: BeyondTrust Password Safe BeyondTrust Privileged Remote Access (PRA) BeyondTrust Endpoint Privilege Management (EPM) Strong Active Directory administration experience. Experience with Microsoft Entra ID (Azure AD). Active Directory Group Policy administration and troubleshooting. Knowledge of: SAML authentication Single Sign-On (SSO) Multi-Factor Authentication (MFA) Role-Based Access Control (RBAC) Experience supporting production services in a secure enterprise environment. Strong troubleshooting and documentation skills. Desirable Skills Experience working in financial services or highly regulated environments. Exposure to service transition, KT, and hypercare activities. Understanding of ITIL processes and operational support models. Experience working within secure or restricted-access environments. Candidate Profile The ideal candidate will be a practical, hands-on engineer who can quickly become productive within an existing BeyondTrust environment, absorb knowledge from incumbent teams, support transition activities, and provide ongoing operational expertise as the service moves into BAU. Please share your latest Cv LA International is an award-winning partner of choice for many of the world's most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance. A multiple award-winning organisation, having secured the prestigious Queens Award for Enterprise: International Trade over consecutive years. We are committed to fostering an inclusive, equitable and accessible workplace where everyone feels valued and supported. We welcome applications from all individuals, regardless of background or identity, and we encourage candidates who may not meet every listed requirement to still apply. If you require any adjustments or support during the recruitment process, please let us know and we will work with you to ensure a fair and accessible experience. Please Note: If a high volume of applications is received, only candidates shortlisted will be contacted.
Voir cette offre
Freelance
CDI

Offre d'emploiIngénieur Sécurité - Expert Sécurité Applicative / DevSecOps

R&S TELECOM
Publiée le
Microsoft Access

12 mois
40k-48k ¤
400-480 ¤
Île-de-France, France
Contexte de la mission Dans le cadre du développement de ses systèmes de gestion, un acteur majeur du secteur financier doit recourir à une prestation externe afin de fournir une assistance aux études et développements, et de poursuivre l'intégration des bonnes pratiques en sécurité dans les développements informatiques. La prestation devra disposer de la double expertise sécurité et développement afin de promouvoir la sécurité dans les équipes Études et Développement du Client. Les principaux objectifs de la prestation sont : Conseil : choix d'architecture, sécurisation des choix technologiques, évaluation des risques Formation : sensibilisation et montée en compétences des équipes études et développement Réalisation : implémentation de mécanismes de sécurité, implémentation de mécanismes de contrôles automatisés, proposition de correction de vulnérabilités Audit : audit de code, tests d'intrusion applicatifs, revue de configuration, contrôles automatisés Ils se découperont de la façon suivante : La prestation sera également amenée à réaliser des pentests ciblés afin de valider la remédiation d'une vulnérabilité remontée par un pentest, de produire des PoC pour prouver l'exploitabilité d'une vulnérabilité détectée par des outils de scan automatisés, ou encore valider la sécurité d'une nouvelle fonctionnalité sensible. Objectifs et livrablesObjectifs et livrables Amélioration et maintien des standards de sécurité dans les développements La prestation contribuera à l'évolution des standards et bonnes pratiques de développement sécurisé, en intégrant les nouvelles technologies et les risques associés aux nouvelles menaces : Evolution et maintien de la documentation existante Intégration des nouvelles menaces liées aux IA (ML/LLM), et définition de mesures de sécurité applicatives Participation à la rédaction des exigences de sécurité IA pour les nouveaux projets intégrant des LLM Identification et implémentation de nouvelles mesures de sécurité applicatives appliquées au pipeline de développement (CI/CD) Accompagnement sur les projets stratégiques La prestation s'assurera de l'application du référentiel sécurité dans les développements sur les projets majeurs et pourra fournir des conseils sur les choix d'architectures applicatives. Conseils sécurité applicative Analyse sécurité de l'architecture applicative Contrôles sécurité (audit de code, pentest en phase de développement, …) Aide à la sécurisation durant les phases de développement Accompagnement des équipes études et développements dans le choix de technologie ou framework Compréhension des besoins des équipes ETU/DEV et de la stratégie IT Participation aux réflexions et aux choix de nouvelles technologies applicatives (framework, API gateway, SSO, etc.) Participation à la définition des configurations des différents frameworks ou outils Contrôle de leurs bonnes mises en œuvre Maintien et évolution des outils d'analyse de code (SAST) et des librairies (SCA), et d'analyse dynamique (DAST) La prestation aura la charge du pilotage des outils d'analyse de code (Coverity), d'audit des librairies (Black Duck) et du DAST (Insight App Sec). Définition et amélioration des processus d'intégration de l'outil aux processus de développement Configuration fonctionnelle des outils Promotion de l'outil et accompagnement des équipes études dans l'appropriation de l'outil Définition et amélioration des politiques d'analyse de code Accompagnement des équipes études dans l'analyse des résultats Conseil des équipes études sur les mesures correctives à mettre en œuvre Suivi des recommandations d'audits sur le périmètre des équipes études et développement Analyse/challenge des nouvelles recommandations issues de tests d'intrusion Construction des plans d'action afférents avec les équipes IT Pilotage du traitement des recommandations sécurité Reporting Construction, animation et suivi du plan de sensibilisation « Sécurité dans les développements » Plan de sensibilisation sécurité sur le périmètre étude et développement Participation au choix des méthodes de sensibilisation (workshop, CTF…) et réalisation de ce plan une fois validé par le Responsable Sécurité Informatique Développement des frameworks internes du Client ainsi qu'à la réalisation des audits de type boîte blanche ou encore proposer des corrections de vulnérabilité directement dans le code La prestation devra disposer des expertises suivantes : Concepts et implémentation d'OpenID et OAuth Analyse et compréhension du code CONDITIONS TECHNIQUES DE LA PRESTATION La prestation se déroulera au sein du service en charge de la sécurité informatique, en étroite collaboration avec les équipes études et développement. RÉSULTATS ATTENDUS / LIVRABLES De façon non exhaustive, la prestation pourra être amenée à produire du code dans les langages suivants : PHP JAVA SQL/LDAP (pour des éventuels ajustements) Python Elle sera également amenée à fournir : Maintien en condition opérationnelle des outils sécurité utilisés par les développeurs (audit de code, SCA, etc.) Amélioration du niveau de sécurité applicative des applications développées par le Client Rapports d'audit détaillant les vulnérabilités trouvées incluant des captures d'écran, des extraits de code, etc. PRÉREQUIS L'expertise sécurité applicative est impérative. Référentiels sécurité OWASP Web Top 10 OWASP API Security Top 10 (2023) OWASP LLM Top 10 (2025) Secure SDLC et pratiques DevSecOps (Shift-Left Security) Audit technique : boîte blanche (code), boîte grise, boîte noire Expertise développement Langages : Java, PHP, AngularJS, Python Technologies : Frameworks Spring, Quarkus, API REST, NodeJS, SOAP, Java RMI Authentification et IAM Expertise sécurité dans les technologies modernes d'authentification : OpenID, OAuth Outil Keycloak Container / Cloud-Native Docker Security Kubernetes RBAC Network Policies Helm Chart Security Connaissances transverses Domaines informatiques : réseau, infrastructure, développement, etc. Architectures standards techniques d'une entreprise (reverse proxy, firewall, DMZ) Langues Contexte international : francophone et anglophone
Voir cette offre

Au service des talents IT

Free-Work est une plateforme qui s'adresse à tous les professionnels des métiers de l'informatique.

Ses contenus et son jobboard IT sont mis à disposition 100% gratuitement pour les indépendants et les salariés du secteur.

Free-workers
Ressources
A propos
Espace recruteurs
2026 © Free-Work / AGSI SAS
Suivez-nous