Job Search and Career Advice Platform

Activez les alertes d’offres d’emploi par e-mail !

PSIRT Core Developer R&D (M/F)

Atos SE

Échirolles

Sur place

EUR 40 000 - 60 000

Plein temps

Aujourd’hui
Soyez parmi les premiers à postuler

Générez un CV personnalisé en quelques minutes

Décrochez un entretien et gagnez plus. En savoir plus

Résumé du poste

A global leader in digital transformation is seeking a PSIRT Core Developer to monitor and triage security vulnerabilities for their products. The ideal candidate will have expertise in scripting (Python, Bash), vulnerability management, and security concepts. Fluent English is required. This position offers the opportunity to work closely with product teams and contribute to improving product security measures.

Qualifications

  • Experience in the Cybersecurity area: access control, encryption or analyzing events.
  • Nice to have knowledge on cybersecurity best practices and ISO 27001 processes.

Responsabilités

  • Monitor potential threats to the security of Atos BDS products.
  • Make a first triage on the potential vulnerabilities.
  • Prepare security advisories related to Atos BDS products.

Connaissances

Knowledge of scripting languages (Python, Bash)
Knowledge on vulnerability management
Knowledge on security concepts for administrators
Fluent written and spoken English

Outils

Cybersecurity tools
Description du poste
Overview

Eviden, part of the Atos Group, with an annual revenue of circa € 5 billion is a global leader in data-driven, trusted and sustainable digital transformation. As a next generation digital business with worldwide leading positions in digital, cloud, data, advanced computing and security, it brings deep expertise for all industries in more than 47 countries. By uniting unique high-end technologies across the full digital continuum with 47,000 world-class talents, Eviden expands the possibilities of data and technology, now and for generations to come.

Organizational context:

The Product Security Incident Response Team (PSIRT) is a dedicated team focused on the security of the product developed in Atos BDS. Its objective is to triage the vulnerabilities potentially affecting them and to ensure they are remediated in time. The PSIRT core team is not directly involved in the implementation of remediation, which remains to be done by development teams.

Role description

PSIRT Core Developer:

  • Contributes to the 7/7 main monitoring mission of PSIRT in triaging the discovered vulnerabilities.
  • Develops the features of the PSIRT automation tools to improve PSIRT efficiency.
  • Interacts with Engineering, Support, and Product Management to confirm vulnerabilities, assess their risk, and elaborate and validate workarounds and remediation.
  • Knowledge of scripting languages, especially Python and Bash.
  • Knowledge on vulnerability management and reporting procedures.
  • Knowledge on security concepts for administrators, especially those useful in a production environment.
Responsibilities
  • Monitor the potential threats to the security of Atos BDS products.
  • Make a first triage on the potential vulnerabilities.
  • Liaise with the product teams to further analyze the vulnerabilities and decide over remediation.
  • Prepare security advisories related to Atos BDS products.
  • Notify relevant authorities in compliance with regulations (notably the Cyber Resilience Act).
  • Track the remediation with the support of development teams.
Interacts with
  • Product R&D teams through Product Security Officers, to ensure in-depth analysis of potential vulnerabilities and remediation availability.
  • Support teams to help addressing Customer issues with respect to vulnerability remediation.
  • Product Managers to help prioritize remediation and assess security risks.
  • The Chief Product Security Officer (CPSO) who is responsible for the overall governance of Product Security in Eviden’s delivered products.
Qualifications
  • Knowledge of scripting languages, especially Python and Bash.
  • Knowledge on vulnerability management and reporting procedures.
  • Knowledge on security concepts for administrators, especially those useful in a production environment.
  • Fluent written and spoken English.
  • Nice to have: Knowledge on cybersecurity tools, best practices, CISO role and ISO 27001 processes.
  • Experience in Cybersecurity area: access control, encryption / collecting & analyzing events.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez un fichier PDF, DOC, DOCX, ODT ou PAGES jusqu’à 5 Mo.