Security Expert
Job Summary
Mission Objectives
The consultants objectives will include in particular:
- Assess the actual level of security of the information system.
- Identify technical and organizational vulnerabilities that could be exploited.
- Perform internal and external penetration tests.
- Assess the security of Microsoft Microsoft Entra ID Azure Linux and network infrastructures.
- Analyze the attack paths that allow for a compromise of the information system.
- Verify the effectiveness of existing security measures.
- Evaluate the conformity of the infrastructure with the security standards adopted by the company and the best practices of the sector.
- Supporting technical teams in defining and prioritizing corrective measures.
- Providing independent expertise in the context of infrastructure development projects.
- Contribute to the continuous improvement of the companys cybersecurity posture
3. Main Responsibilities
A. Safety Assessment
- Performing internal and external penetration tests.
- Performing Active Directory audits.
- Security assessment of Microsoft Windows Linux Microsoft Entra ID and Azure environments.
- Analysis of network security authentication mechanisms exposed services and privileged access.
- Review of security configurations and identification of deviations from best practices.
- Validation of the effectiveness of existing protection measures.
- Identification of exploitable technical vulnerabilities and assessment of their impact.
B. Analyse offensive
- Simulation of attack scenarios representative of current threats.
- Analysis of chains of compromise and attack paths.
- Identification of opportunities for privilege escalation and lateral movement.
- Evaluation of network segmentation and security mechanisms.
- Analysis of the security of identities privileges delegations and authentication mechanisms.
- Identification of technical risks that may affect the confidentiality integrity or availability of the information system.
C. Consulting architecture and support
- To act as the technical expert for all cybersecurity-related matters.
- Advise IT teams on technical choices that have an impact on security.
- Participate in architecture reviews from a cybersecurity perspective.
- Evaluate the impacts of new projects on the companys security posture.
- Formulate technical recommendations to reduce risks while taking operational constraints into account.
- Participate in technical risk analyses.
- Supporting teams in implementing remediation measures and in continuously improving safety.
D. Documentation and skills transfer
- Produce detailed technical reports as well as executive summaries for management.
- Prioritize recommendations based on their criticality usability and feasibility.
- Document the findings analyses security architectures and remediation measures.
- Develop best practice guides and contribute to the standardization of security practices.
- To ensure the transfer of knowledge and contribute to the skills development of internal teams.
- Presenting the results of missions to both technical stakeholders and management adapting the level of discourse and formulating clear reasoned and pragmatic recommendations.
4. Required technical skills
Cybersecurity
- Internal and external penetration testing.
- Audits Active Directory.
- Securing Microsoft environments.
- Securing Microsoft Entra ID and Azure.
- Securing Linux environments.
- Identity and Access Management (IAM).
- Analysis of privileges and authentication mechanisms.
- Analysis of attack paths.
- Evaluation of security architectures.
- System configuration review and hardening.
- Vulnerability analysis and remediation recommendations.
Infrastructures
- Microsoft Windows Server.
- Active Directory.
- Microsoft Sign In ID.
- Microsoft Azure.
- Microsoft 365.
- Linux (Debian Ubuntu or equivalent distributions).
- TCP/IP networks.
- Switching routing et VLAN.
- Enterprise Wi-Fi infrastructure.
- Firewall and VPN.
- Knowledge of virtualized environments (VMware Hyper-V or equivalents) enabling the assessment of their security level.
Methodologies
- OWASP Testing Guide.
- OWASP Top 10.
- MITRE ATT&CK.
- NIST Cybersecurity Framework.
- CIS Benchmarks.
Documentation
- Excellent writing skills.
- Production of technical and executive reports.
- Documentation of architectures findings and recommendations.
- Ability to simplify technical subjects for non-specialist audiences.
5. Desired Profile
The consultant must demonstrate significant experience in cybersecurity acquired in complex environments.
He will notably have to demonstrate:
- A professional experience of at least 7 years in the field of cybersecurity.
- Complete autonomy in carrying out complex missions.
- Excellent command of Microsoft environments Microsoft Entra ID Azure and Linux.
- Extensive experience in conducting penetration tests and technical audits.
- Strong analytical and synthesis skills.
- A methodical rigorous structured and results-oriented approach.
- Excellent organizational and prioritization skills.
- An ability to communicate effectively with both technical teams and management.
- A critical mind enabling him to formulate pragmatic proportionate recommendations adapted to the companys context.
- The ability to act as a cybersecurity expert for internal teams.
- Excellent documentation communication and knowledge transfer skills.
The consultant will need to demonstrate professional maturity and prioritize a pragmatic approach to cybersecurity based on objective risk assessment the search for realistic solutions and support for teams in their implementation.
6. Desired certifications
Certification minimale
The consultant must hold at least one recognized certification in offensive cybersecurity such as:
- Offensive Security Certified Professional (OSCP) or equivalent certification.
Certifications are an asset
- Burp Suite Certified Practitioner (BSCP).
- Practical Network Penetration Tester (PNPT).
- Certified Red Team Operator (CRTO).
- Certified Red Team Professional (CRTP).
- GIAC Exploit Researcher and Advanced Penetration Tester (GXPN).
- Certified Information Systems Security Professional (CISSP).
- Microsoft Certified: Azure Security Engineer Associate.
- Any Microsoft certification related to security or Microsoft Entra ID.
Required Skills:
HYPER-VAZUREVMWAREDOCUMENTATIONMICROSOFTVLANLINUX
About Company
30 employees
Welcome to Sansaone, a dynamic force in the realm of ICT talent acquisition. Born out of a passion for excellence and a vision for connecting outstanding professionals with forward-thinking organizations, we stand as a beacon for strategic recruitment solutions in the Information and ... View more