CISO for France driving cybersecurity strategy at Once For All's SaaS platform in construction. Collaborate with teams to manage security and compliance across operations.
Responsibilities
As the CISO for France, you will own the security strategy for the French scope and lead the workstreams of the Group cybersecurity master plan that fall under France.
Cybersecurity point of contact for France: drive security for the French perimeter, coordinate the Group master plan workstreams assigned to France, and represent security to local teams.
Customer-facing security: handle security questionnaires from customers and prospects in French, take part in security calls with sales teams, and review contractual security clauses.
Governance, risk and compliance: maintain the governance model, policies and risk management processes (MAGERIT, NIST RMF, EBIOS); ensure compliance with ISO 27001, NIS2, GDPR, ANSSI recommendations and SOC 2, and support related audits.
Security architecture and operations: work with Tech and IT teams to integrate security into the SaaS architecture (cloud, network, application) and oversee detection, monitoring and incident response for the region.
Vendors, budget and reporting: manage relationships with security vendors, oversee the regional security budget, run awareness programs and produce regular reporting to the Executive Committee (Comex).
Requirements
University degree (Master's or Engineering degree) in Computer Science, Information Systems, Cybersecurity or an equivalent field.
Minimum 3 years in a cybersecurity leadership role, and 5 to 8 years of overall information security experience.
Strong knowledge of security governance: policies, frameworks and risk management processes.
Expertise in at least one risk management methodology: MAGERIT, NIST Risk Management Framework or EBIOS Risk Manager.
Solid knowledge of compliance frameworks: ISO 27001, NIS2, GDPR, ANSSI guidance and SOC 2, with experience in audits and remediation.
Good understanding of SaaS architecture and cloud security on AWS, Azure and GCP, across network, application and identity domains.
Hands-on experience in security operations: monitoring, detection, incident response and post-incident continuous improvement.
Knowledge of penetration testing methodologies and associated remediation workflows.
Experience managing security vendors and overseeing budgets.
At least one certification among CISSP, CISM, CEH or CompTIA Security+.
Native or fluent French and fluent English, both written and spoken.
Senior Network Security Engineer designing and implementing network security systems for clients in Greece and abroad. Leading a small team and providing technical support.
Senior Security Engineer at Flanks leading security initiatives in a fast - paced fintech startup. Evolving security practices and collaborating with teams to implement best practices across stacks.
Security Consultant at Kyndryl defining security policies and managing incident responses for clients. Collaborating on security measures and conducting audits to safeguard sensitive data.
Senior Staff Engineer at GEICO designing intelligent cybersecurity automation systems. Collaborating across teams to enhance security architecture and improve production readiness.
Senior Network Security Engineer managing and supporting Palo Alto firewalls across enterprise environments. Leading firewall migrations and ensuring operational effectiveness in network security.
Cybersecurity Expert leading the establishment of a FedRAMP - compliant SOC at Philips, a health technology company, while managing various cybersecurity initiatives.
Cybersecurity Engineer developing cloud - based security architectures for critical DoD systems. Responsible for securing cloud infrastructure and automating security processes in innovative technology environments.
Technical Program Manager leading strategic cloud security initiatives for global enterprises. Orchestrating diverse teams and delivering innovative products to protect critical data and infrastructure.
Mid - Level Information Security & Governance Specialist at Boeing ensuring NASA program compliance with cybersecurity expectations. Engage with Information System Owners and conduct assessments as needed.