Product Development Cyber Risk Specialist

Marlink

France

Hybride

EUR 70 000 - 110 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV personnalisé et une lettre de motivation qui correspondent directement à l’offre.

Passez les filtres ATS

Résumé du poste

Marlink in France seeks a senior cybersecurity professional to guide and support project managers in embedding secure-by-design practices across the lifecycle of digital products and services.

You will translate regulatory requirements (CRA/NIS2) into actionable controls, support ISO27001 ISMS, and coordinate threat modeling, vulnerability management, and audit-ready documentation with cross-functional teams.

Qualifications

  • 5–10 years of cybersecurity experience, ideally in regulated or product-focused environments.
  • Strong knowledge of ISO27001/27002, ISO27005, and OWASP standards.
  • Experience with risk assessment and threat modeling methods (EBIOS RM, STRIDE, TARA).
  • Hands-on with vulnerability management and security testing (SAST/SCA/DAST).
  • DevSecOps in CI/CD environments; secure-by-design mindset.
  • Ability to secure web, cloud, networked, and embedded/IoT architectures.
  • Additional experience in pentesting or security architecture is a plus.
  • Fluent English with good writing/presentation skills.

Responsabilités

  • Embed cybersecurity requirements from earliest project stages and ensure consistent application.
  • Perform threat modeling and cyber risk assessments (EBIOS RM).
  • Translate CRA/NIS2 into actionable security controls and deliverables.
  • Support ISO27001 ISMS implementation and AnnexA alignment.
  • Define and monitor vulnerability management in CI/CD pipelines (SAST, SCA, DAST).
  • Review architectures to ensure effective controls and risk mitigation.
  • Coordinate remediation actions with developers and stakeholders.
  • Produce audit-ready documentation and compliance evidence.

Connaissances

5-10 years
ISO27001/27002
OWASP Top10
EBIOS RM
STRIDE
TARA
SAST
SCA
DAST
DevSecOps
Web/Cloud/Embedded
Penetration Testing

Outils

SAST Tools
SCA Tools
DAST Tools
CI/CD Security Tools

Description du poste

Your Mission

Guide and support project managers in integrating cybersecurity throughout the lifecycle of digital products and services.

The mission focuses on ensuring compliance with key regulations such as CRA and NIS2, alignment with international standards including ISO27001, and application of recognized best practices like OWASP.

The role also includes managing cyber risks and vulnerabilities to ensure secure‑by‑design and secure‑by‑default products and services.

Main Tasks

Embed cybersecurity requirements from the earliest project stages and ensure their consistent application throughout the project lifecycle.

Perform and review threat modeling and cyber risk assessments using methods such as EBIOS RM.

Translate regulatory requirements (CRA, NIS2) into actionable security controls and project deliverables.

Support ISO27001 ISMS implementation and align project activities with AnnexA controls.

Define, implement, and monitor vulnerability management frameworks, including integration of SAST, SCA, and DAST tools in CI/CD pipelines

Review system, application, cloud, and embedded architectures to ensure effective security controls and risk mitigation.

Coordinate with developers, architects, and stakeholders to track remediation actions and ensure closure of critical vulnerabilities.

Produce audit‑ready documentation, security assessments, and compliance evidence.

Qualifications & Professional skills
  • 5 to 10 years of experience in cybersecurity, preferably in product‑oriented or regulated environments.
  • Strong knowledge of cybersecurity frameworks and standards: ISO27001/27002, ISO27005, OWASP (Top10, ASVS, SAMM).
  • Solid experience in risk assessment and threat modeling methodologies (EBIOSRM, STRIDE, TARA).
  • Practical understanding of vulnerability management processes and security testing tools (SAST, SCA, DAST).
  • Expertise in integrating DevSecOps practices within CI/CD environments.
  • Ability to assess and secure diverse architectures: web, cloud, networked systems, and embedded/IoT.
  • Additional experience in penetration testing, security auditing, or security architecture is an asset.
  • Fluent English with good writing and presentation skills
Attitude & Interpersonal skills
  • Strong communication skills, with the ability to engage and advise diverse stakeholders.
  • Analytical mindset and structured approach to problem solving and risk evaluation.
  • Proactive attitude with a focus on continuous improvement of security practices.
  • Ability to collaborate effectively across project management, R&D, IT, and security teams.
  • Strong technical writing skills to produce clear, actionable, and audit‑ready documentation.
  • Comfortable challenging designs and decisions constructively to enhance security posture.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Cybersecurity Engineer
Cybersecurity Engineer

Jobtailor • Castet-Arrouy

Sur place
EUR 42 000 - 65 000
Cybersecurity Solution Architect
Cybersecurity Solution Architect

IDEMIA Public Security • Osny

Sur place
EUR 90 000 - 130 000
Cybersecurity Engineer, Service Platforms
Cybersecurity Engineer, Service Platforms

Jobtailor • Saclay

Sur place
EUR 60 000 - 90 000
Cyber GRC Specialist
Cyber GRC Specialist

Sonepar Canada, Inc. • Paris

Sur place
EUR 65 000 - 90 000
Cybersecurity Solution Architect
Cybersecurity Solution Architect

IDEMIA • Osny

Sur place
EUR 90 000 - 140 000
Senior Product Manager (Hardware Security & Cybersecurity)
Senior Product Manager (Hardware Security & Cybersecurity)

Gramian Consulting Group • Aix-en-Provence

Sur place
EUR 90 000 - 140 000
OT (Industrial) Cyber Security Consultant
OT (Industrial) Cyber Security Consultant

Integrity360 • Paris

Hybride
EUR 60 000 - 90 000
Reference manager program
Internal training and progression
Annual external training
Senior Product Manager – Cybersécurité
Senior Product Manager – Cybersécurité

CYCLAD FRANCE • Toulouse

Sur place
EUR 70 000 - 110 000
Senior Product Manager – Cybersécurité
Senior Product Manager – Cybersécurité

CYCLAD FRANCE • Nice

Sur place
EUR 90 000 - 120 000
Senior Product Manager – Cybersécurité
Senior Product Manager – Cybersécurité

CYCLAD FRANCE • Nantes

Sur place
EUR 70 000 - 95 000