Within the Cybersecurity Department of a major Luxury Group, the Security Integration in Projects (ISP) team ensures that security requirements are proactively and effectively embedded across all IT projects within the Group.
The ISP acts as a key player in the cybersecurity framework in order to:
- Reduce exposure to cyber risks
- Ensure regulatory compliance
- Enforce internal security standards
- Promote a strong Security by Design culture
The objective of this mission is to act as a Risk Assessor within the ISP team, contributing to all activities within the scope, in close collaboration with project teams, business stakeholders, cybersecurity teams, and design functions (architecture, privacy).
Main Activities:
- Security integration from project initiation: participation in Kick-Off Meetings, project criticality assessment, identification of security stakes, and triggering of required analyses.
- Risk analysis and treatment: execution of Business Impact Analysis (BIA) and CATIS, identification of threat scenarios, risk evaluation (custom methodology aligned with ISO 27005 & EBIOS RM), definition and follow-up of mitigation measures.
- Pentest coordination and follow-up: planning and coordination with external providers, analysis of test reports, and monitoring of vulnerability remediation.
- Validation of new applications/tools: risk assessment, compliance verification against internal standards, definition of compensating controls where needed, and issuance of formal security opinions.
- Technical architecture challenge: security review of proposed architectures (network segmentation, IAM, encryption, APIs, logging, interconnections) and formulation of recommendations prior to production go‑live.
Your Profile :
Confirmed to Senior Profile (minimum 4 years of experience) with strong expertise in cybersecurity and risk assessment activities.
Technical skills:
- Strong knowledge of Information Security principles
- Risk analysis expertise (ISO 27005 / EBIOS RM aligned)
- Blueteam and security control expertise
- Architecture security (on‑premise and cloud environments)
- Application security
- Network and Infrastructure security
- Vulnerability management
- Understanding of modern IT environments
- Expertise in AI, Cloud security, payment systems security would be highly appreciated
- Project environments include: AS400, Headless architectures, SAP, data platforms, new retail points of sale, Cloud AWS, Azure, GCP, Alibaba, Salesforce
- Certifications could be an advantage : CCSP, ISO27001, CISA, CRISC, CEH, CISSP, CCNA Cisco,…
- Facultative : Redteam culture or experiences
Soft Skills
- Ability to challenge stakeholders diplomatically
- Strong analytical and structured mindset
- Leadership capabilities
- Strong synthesis and reporting skills
- High level of autonomy
- Proactive and solution‑oriented mindset
Languages
We value diversity and inclusion. Every voice matters, and we encourage applications from all backgrounds.
🌍All our offers are open to people with disabilities.