Job Search and Career Advice Platform

Activez les alertes d’offres d’emploi par e-mail !

Operation Security Officer

Wooclap

Paris

Sur place

EUR 60 000 - 80 000

Plein temps

Il y a 2 jours
Soyez parmi les premiers à postuler

Générez un CV personnalisé en quelques minutes

Décrochez un entretien et gagnez plus. En savoir plus

Résumé du poste

A tech-driven company based in Paris is seeking an Operation Security Officer to strengthen its security posture. This role involves leading various strategic security projects, ensuring compliance with international standards, and managing the security strategy across teams. Candidates should possess a strong background in information security, including governance, risk management, and incident handling. This position offers a unique opportunity to shape the security framework of a leading company during its international growth.

Prestations

Health insurance
Flexible working hours
Training and development opportunities

Qualifications

  • Experience in security governance and risk compliance.
  • Knowledge of international security standards (GDPR, ISO 27001).
  • Proven ability to lead security projects and initiatives.

Responsabilités

  • Contribute to security vision and strategy.
  • Ensure compliance with key regulations and standards.
  • Lead security audits and enhance compliance frameworks.
  • Oversee vulnerability lifecycle management.
  • Manage security support for clients and partners.

Connaissances

Security Strategy Development
Risk Management
Compliance with ISO 27001
Incident Management
Security Tools Proficiency

Formation

Bachelor's degree in Information Security or related field
Certifications (CISSP, CISM, etc.)

Outils

SIEM tools
Vulnerability Scanners
Description du poste

As the security team our ambition is to:

  • Security Leader: Have the best security among our competitors

  • Guardian of Trust: Not only meet but exceed the highest security standards required by our customers and partners.

  • Total Resilience: Build defences that makes us indestructible and guarantees our operational resilience.

  • Support of our Growth: Support Wooclap in its global expansion.

As an Operation Security Officer you will be the second member of the Wooclap Security team. This position is inherently cross‑functional: you will work in close collaboration with the Technical team while being the key contact for all internal stakeholders (Business, Legal, Operations, Marketing teams, etc.).

This role is essential in the context of Wooclap’s international growth.

We rely on your autonomy and initiative to build the future of our security. You will lead strategic projects from A to Z, support our clients and partners, and evolve our security posture to anticipate the risks associated with our rapid expansion.

Your missions:
1. Governance Risk & Compliance
  • Contribute to the Security Vision: Contribute to the security strategy and roadmap in close collaboration with Security Management, the technical teams and all stakeholders.

  • Contribute to Compliance: Ensure continuous alignment with international standards (e.g. ISO 27001) and key regulations (GDPR, etc.). Ensure follow‑up on legal and regulatory obligations (CNIL, cloud hosting, etc.).

  • Improve Security Policies: Define and maintain security policies (access control, encryption, device management, data protection) and oversee their deployment and implementation by the relevant teams (HR, suppliers, etc.).

  • Committees and Monitoring: Create security committees, KPIs and dashboards to track the security posture and report to the Management team or the Board if necessary.

  • Governance and Reporting (KPIs): Create and lead security committees, define KPIs and dashboards to track the security posture and clearly communicate the level of risk to the Management team.

  • Audit and Certification: Lead security audits (both internal and external), monitor and enhance compliance with ISO/IEC 27001 and contribute to future certifications.

2. Security Project Management
  • Access Management (IAM): Lead the project to create a new rights and access management (IAM) strategy.

  • Tooling: Participate in the selection and deployment of the next SIEM and launch large‑scale projects (e.g. Bug Bounty, EDR).

  • Endpoint Security: Evolve the security aspects of the device fleet and related subcontractors.

  • Establish the new security incident management strategy and business continuity plans.

  • Simulation and Post‑Mortem: Organize crisis simulation exercises to test process resilience and lead post‑mortem analyses.

  • Internal Program: Co‑build the future Information Security Officers (ISOs) program within the teams.

3. App & Infrastructure Security
  • Security by Design: Define and promote secure development best practices within the TECH team.

  • Architecture Review: Lead architecture and implementation reviews for critical functionalities (authentication, payments, APIs, AI usage, etc.).

  • SDLC Integration: Collaborate with Engineering Managers and the DevX team to integrate security throughout the Software Development Life Cycle (SDLC).

  • Vulnerability Lifecycle Management: Establish and oversee the process for detecting, classifying and remediating vulnerabilities.

  • Security Tooling: Maintain and evolve security tools (SAST, DAST, vulnerability scanners) for proactive fault detection.

4. Security Support & Communication
  • External Support: Manage security support for clients and partners and be the key contact for our clients and partners on security and confidentiality topics.

  • Security Forms: Respond to security questionnaires and contribute to process improvement (communication, AI, etc.).

  • Internal Advice: Act as a privileged advisor to the Product Engineering and Business teams on all security matters.

  • Awareness and Training: Actively promote a culture of security and shared responsibility. Organize regular awareness initiatives (phishing simulations, training sessions).

First Year Projects

To ensure the rapid scaling of our security strategy the role will begin with high‑impact projects. Your initial objectives will include but not be limited to the following:

  • Posture Analysis and Roadmap: Upon arrival conduct a risk analysis (like a discovery report) of our security level and current policies in order to challenge and refine the existing strategic roadmap.

  • Redesigning our Identity and Access Management (IAM) strategy.

  • Governance and Measurement: Create and define the associated KPIs and dashboards to ensure better monitoring of our security level and posture.

  • Internal Program: Co‑build and launch the future Information Security Officers (ISOs) program within the teams to expand the security culture.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez un fichier PDF, DOC, DOCX, ODT ou PAGES jusqu’à 5 Mo.