Lead Security Engineer - Governance & Risks
Role details
Job location
Tech stack
Job description
Our platform enables businesses to enhance their client experience with solutions in:
- Electronic Signature: digitization and automation of signing processes
- KYC & ID Verification: online identity and document verification with AI and machine learning
What you will do at Signaturit
You are actively participate in defining, implementing, and maintaining Signaturit's information systems security (ISS) policy.
Your role is central to guaranteeing operational security on a daily basis, responding to the needs of internal teams, and contributing to strategic projects related to compliance, audits, and certification.
Compliance, Certification & Client Relations:
- Contribute to maintaining existing certifications and qualifications for trust services (eIDAS).
- Actively prepare for future ISO 27001 certification (drafting procedures, implementing processes). - Process and respond to client security questionnaires, ensuring the accuracy of information. Risk & Vulnerability Management:
- Assist the CISO in updating the ISS risk repository and analyzing vulnerabilities.
- Participate in risk impact analysis and propose mitigation action plans.
- Awareness & Communication: - Conduct security awareness campaigns for all staff.
- Disseminate best practices and act as an advisor and trainer for teams.
- Perform active monitoring (watch) on security threats and share relevant information.
- Maintain and update technical and security policy documentation.
Operational Support & Incident Response:
- Respond autonomously or provide support to security requests and incidents reported by various teams.
- Participate in Datacenter management and maintenance operations and achieve autonomy on defined procedures.
- Contribute to post-incident analysis and remediation efforts.
- Represent the ISS department to clients and auditors on topics within your scope.
What we believe should contribute to your success in this context, * 1st interview with our business (direct report)
- Business case
- 2nd interview with our business & business case feedback
- Reference check
Why Join Us
- Flexible hybrid work set up
- Flexible working hours and A framework status with RTT
- Health Insurance 100% covered
- ️ Meal Vouchers (Ticket restaurants)
- ️ Tailor-made onboarding and skills development program
- Access to specialized technical training platforms
- Regular events to maintain a good atmosphere
Requirements
Do you have experience in TCP/IP?, Do you have a Master's degree?, You have a Engineer or Master's degree in Security/ Network and 5-7 years experience in Security, with a first experience as a team leader.
Hard skills:
- Security Tools: Familiarity with SIEM platforms, vulnerability scanners and endpoint protection solutions.
- Networking Security: understanding of TCP/IP, firewalls, VPNs, and network segmentation.
- Cryptography and HSM /Hardware Security Module knowledge is a plus.
- Already manage Internal & External Audits.
- French and English are mandatory.
- EIDAS and ISO 27001 knowledges are a plus.
Soft Skills:
- Good communication and use to face clients.
- Deep understanding of our client's business and solution seeker.
- Flexibility & adaptability.