N’envoyez pas un CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.
CMA CGM is seeking a Security Operations professional in Marseille to protect the group by monitoring and responding to cyber incidents. You will join a 24/7 SOC, rotating shifts and collaborating with a dynamic team using high-level security solutions.
You will analyze alerts from SIEM/SOAR platforms, investigate events, and escalate incidents per procedures. Python skills are appreciated, with experience in transport or logistics considered a plus.
Your main mission will be to protect the CMA CGM Group by detecting and responding to cyber incidents. In a context where threats are growing in number and complexity, you will have the opportunity to work within a dynamic, motivated team equipped with high-level security solutions. You will report to the SOC Manager.
24/7 operational monitoring: You will take part in a 24/7 operational SOC, working in rotation (Following the Sun).
Analysis and detection: You will analyze,contextualizeandmonitorsecurity alerts from advanced platforms.
Investigation and escalation: You will investigate security events, communicatefindingsand escalatete incidents according to procedures.
Stakeholder support: You will handle security service requests (responding to subsidiaries/stakeholders, analyzing malicious or suspicious files).
Incident response: You will support incident response (IR) whenever analysis confirms an actionable incident.
Threat hunting: You will take part in Threat Hunting exercises and sessions with the CTI (Cyber Threat Intelligence) team.
Continuous improvement: You willoptimizeSOC use cases (detection rule tuning) and contribute to designing and improving playbooks, standard operating procedures (SOPs)and guidelines.
Simulations and collaboration: You will take part in incident response simulations and work closely with the SOC RUN Manager, theLeadand the Manager on various tasks and projects.
Education: Master's degree in Computer Science, Cybersecurity, Networks or a related field.
SOC tools:Proficiencywith SIEM, SOAR, as well as network/host logs, firewalls, IPS/IDSand email security gateways.
Technical knowledge: Solid understanding of cybersecurity principles and best practices, attack methodologies (Cyber Kill Chain, MITRE ATT&CK), common attack vectors, and concepts such as perimeter defense, endpointmanagementand data loss prevention (DLP).
Programming: Python skills are appreciated.
Industry experience: Prior experience in transport,maritimeorlogisticswould be a plus.
Personal qualities: Motivated,autonomousand proactive, with strong analytical and synthesis skills, a solid understanding of security logs, real ease working with management, business teams and technical teams, and absolute discretion on sensitive matters.