Within the EQUANS IT department, you will be part of the Cyber Customer Trust team, that helps the EQUANS business units delivering cyber secure solutions to their customers.
This team is led by the Cyber Customer Trust director and is reporting to the Global CISO.
As the Cloud Security Consultant in the Shared Line of Service (SLS) Cyber Customer Trust (CCT), you report to the Head of Cyber Design Office and will mainly be tasked with assessing the cybersecurity of cloud architectures of products created by the Equans Business Units. Also providing global support to local cyber teams responsible for securing the service offerings of their businesses, as well as working closely with the Cyber Technical Office (CTO) team. This can also include in globalizing a local product for EQUANS world wide usage. For example, assessing an existing cloud architecture on cybersecurity aspects and advising the Business Unit on improvements. Develop and continuously improve cloud security standards and frameworks as input for the CTO CCT architect as well as the business units. Together with the OT Architect in the Cyber Design Office you form the security team in charge of security architecture frameworks and assessments in Cloud and on-prem solutions.
In this context, your main missions and activities will include:
- Provide independent security assessment reports and recommendations to Business Units and Product Owners. Track remediation actions and report status through the Cyber Customer Trust governance process and take part in the Security Architecture Review Board and support Business Units through the validation process.
- Assess architectures hosted on Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP) and hybrid/on-premises environments.
- Define cloud cyber guidelines and policies related to service offerings delivered to our clients.
- Be responsible for designing and maintaining our standardized security solutions that will enable our operational staff to conduct their activities with a good cyber posture and be compliant to EQUANS policies.
- Maintain a catalog of cyber solutions, products, and partners that can be integrated into the commercial offers.
- Review cloud-native development practices, CI/CD pipelines, infrastructure-as-code configurations and deployment patterns from a cybersecurity perspective.
- When needed, participate in the writing of cyber offers and supporting local cyber teams, in case local skills and knowledge are absent. This includes participating in the Bid, Design and Acceptance phases of projects. These activities also demonstrate the added value of cyber activities from the launch of the SLS.
- Participate in Technology Watch to spot solutions, trends and innovations, that can be used by the EQUANS business to deliver secure solutions to EQUANS customers.
- Participate in Regulatory Watch to monitor regulations in different countries where EQUANS operates for any impact on the CCT activities or impact the EQUANS solutions used for EQUANS customers, for example NIS2 and the Cyber Resilience Act (CRA).
Your profile:
- You have a higher education degree (an Engineering degree in cybersecurity or a master's degree in computer science and networks) and 5+ years of experience in cloud security, security architecture within complex enterprise environments;
- You are recognized for your expertise in reviewing systems, with ideally some related certifications (CISSP, CCSP, TOGAF Practitioner, Microsoft Azure Security, AWS Security Specialty) or certifications from main security solutions related to Cloud Architecture;
- Have of:
- Identity & Access Management (IAM)
- Zero Trust
- Entra ID / Azure AD
- Key Management and PKI
- Cloud Security Posture Management (CSPM)
- Container Security
- Kubernetes
- Infrastructure as Code
- Security Monitoring principles
- API Security
- Cloud Security fundamentals in Azure / AWS / GCP
- Threat modeling (e.g. STRIDE) and trust boundary analysis
- You have a good understanding of our clients' business challenges;
- Knowledge of security information frameworks and risk management is useful (NIST CSF, ISO 27001/2, CSA CCM, CIS Controls, ISO 27005, EBIOS RM). Familiarity with OT/ICS security concepts (IEC 62443) is considered a plus;
- You are comfortable working in a decentralized and multicultural organization, with heterogenous maturity levels in terms of cybersecurity and architecture practices;
- You can act as a consultant for the internal EQUANS business.
- You are autonomous, energetic and show initiative.
- You are a good communicator, develop and maintain good relationships.
- You have strong ethics, and can exercise discretion.
- You are fluent in English / french will be a plus but not mandatory.