Activez les alertes d’offres d’emploi par e-mail !

Incident Response Lead

American President Lines

Marseille

Sur place

EUR 40 000 - 60 000

Plein temps

Il y a 30+ jours

Mulipliez les invitations à des entretiens

Créez un CV sur mesure et personnalisé en fonction du poste pour multiplier vos chances.

Résumé du poste

Une entreprise innovante dans le secteur maritime recherche un Responsable de la Réponse aux Incidents. Ce rôle clé implique de diriger une équipe d'experts en cybersécurité pour détecter et atténuer les menaces. Vous serez le point de contact pour les incidents critiques, en prenant des décisions sous pression. Avec un engagement envers l'excellence opérationnelle, vous développerez des stratégies et des cadres de réponse aux incidents, tout en formant votre équipe pour faire face aux défis émergents. Si vous êtes passionné par la cybersécurité et que vous souhaitez faire la différence dans un environnement dynamique, cette opportunité est faite pour vous.

Qualifications

  • 10+ ans d'expérience en cybersécurité, dont 5+ ans en gestion d'incidents.
  • Expérience dans la gestion de crise et la communication efficace avec les dirigeants.

Responsabilités

  • Diriger une équipe d'intervenants en cas d'incidents de cybersécurité.
  • Développer des stratégies de gestion des crises et des cadres de réponse aux incidents.

Connaissances

Gestion de crise
Analyse forensique
Analyse des malwares
Intelligence des menaces
Communication
Gestion des incidents

Formation

Certifications reconnues dans l'industrie (GIAC/GCIH, CISSP, CISM)

Outils

SIEM
EDR
Splunk
CrowdStrike

Description du poste

Location:

Marseille, FR

Incident Response Lead

Led by Rodolphe Saadé, the CMA CGM Group, a global leader in shipping and logistics, serves more than 420 ports around the world on five continents. With its subsidiary CEVA Logistics, a world leader in logistics, and its air freight division CMA CGM AIR CARGO, the CMA CGM Group is continually innovating to offer its customers a complete and increasingly efficient range of new shipping, land, air and logistics solutions.

Committed to the energy transition in shipping, and a pioneer in the use of alternative fuels, the CMA CGM Group has set a target to become Net Zero Carbon by 2050. Through the CMA CGM Foundation, the Group acts in humanitarian crises that require an emergency response by mobilizing the Group’s shipping and logistics expertise to bring humanitarian supplies around the world.

Present in 160 countries through its network of more than 400 offices and 750 warehouses, the Group employs more than 155,000 people worldwide, including 4,000 in Marseilles where its head office is located.

THE ROLE

As the Incident Response Commander Lead, you will be the driving force behind our cybersecurity incident response operations, leading a team of elite Incident Response Commanders in detecting, analyzing, containing, and mitigating cyber threats. This role demands exceptional leadership, crisis management, and deep investigative expertise to guide high-stakes incident response efforts effectively.

You will report directly to the Cyber Defense Center (CDC) Director, ensuring that your team is always prepared, proactive, and decisive in managing security incidents and minimizing business impact. Beyond just responding to incidents, you will develop strategy, enforce operational excellence, and enhance team capabilities to stay ahead of evolving cyber threats.

WHAT ARE YOU GOING TO DO?

  1. Lead and inspire a team of Incident Response Commanders, fostering a culture of excellence, urgency, and accountability.
  2. Command and oversee all major cybersecurity incidents, ensuring rapid detection, containment, investigation, and remediation.
  3. Act as the escalation point for critical incidents, making high-pressure decisions with precision.
  4. Enhance crisis management strategies to ensure swift coordination across technical and business stakeholders.
  5. Develop and enforce incident response frameworks aligned with industry best practices (MITRE ATT&CK, NIST, Cyber Kill Chain).
  6. Collaborate closely with threat intelligence, SOC, forensic, and red team functions to anticipate and mitigate threats proactively.
  7. Lead tabletop exercises and crisis simulations to test and refine response capabilities.
  8. Mentor and upskill the incident response team, ensuring they stay ahead of emerging threats and technologies.
  9. Define and implement continuous improvement processes to enhance detection, response, and remediation efficiency.
  10. Represent the incident response function in executive-level discussions, providing clear, concise, and actionable insights.

WHO ARE WE LOOKING FOR?

ESSENTIAL EXPERTISE & EXPERIENCE

  1. Proven leadership experience in cybersecurity incident response, crisis management, or SOC operations.
  2. 10+ years of experience in cybersecurity, including 5+ years in a leadership role within Incident Response, CERT, or SOC.
  3. Industry-recognized certifications (e.g., GIAC/GCIH, GCFA, GCIA, CISSP, CISM, OSCP).
  4. Expert-level knowledge of attack techniques, threat actors, and exploit methodologies.
  5. Hands-on experience with forensic analysis, malware analysis, and threat intelligence.
  6. Deep familiarity with MITRE ATT&CK, Cyber Kill Chain, NIST, and other security frameworks.
  7. Strong crisis management skills, with the ability to make critical decisions under pressure.
  8. Excellent communication skills, able to articulate technical risks to executive leadership.
  9. Experience conducting tabletop simulations and training security teams for real-world incidents.
  10. Proficiency in SIEM, EDR, and forensic tools (Splunk, Sentinel, CrowdStrike, etc.).
  11. Fluent in French & English (spoken and written) in a professional context.

ADDITIONAL STRENGTHS THAT SET YOU APART:

  1. Experience in transport, shipping, or logistics industries.
  2. Experience in attack surface management and exposure reduction.
  3. Strong ability to analyze and synthesize large amounts of security data.
  4. Proven ability to drive change and innovation in security operations.
  5. Experience working in international and offshore environments.
  6. Background in cyber risk assessment and reporting.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez un fichier PDF, DOC, DOCX, ODT ou PAGES jusqu’à 5 Mo.