20 hours, 30 minutes ago

Security Expert

1. Mission Context

As part of its ongoing efforts to strengthen its cybersecurity posture, In BW wishes to engage the services of a Senior Expert Consultant in Cybersecurity to provide independent expertise in assessing the security of its information system and to support IT teams in sustainably improving their level of protection.

The consultant will mainly be involved in technical audits, penetration testing, technical risk analyses, architecture reviews, and securing Microsoft, Linux, and Cloud infrastructures.

Beyond assessment activities, the consultant will act as the company’s technical point of reference for all matters related to cybersecurity. They will provide independent expertise on architectural choices, transformation projects, and security measures, while ensuring a balance between security requirements, operational constraints, and business continuity.

The mission is planned for a duration of 12 months, at approximately 2.5 days per week.

Remote work is allowed up to approximately 50% of the time, subject to business needs.

2. Mission Objectives

The consultant will have the following objectives, among others:

  • Assess the actual security level of the information system.
  • Identify technical and organizational vulnerabilities that could be exploited.
  • Conduct internal and external penetration tests.
  • Assess the security of Microsoft, Microsoft Entra ID, Azure, Linux, and network infrastructures.
  • Analyze attack paths leading to compromise of the information system.
  • Verify the effectiveness of existing security measures.
  • Evaluate the compliance of infrastructures with the security standards adopted by the company and industry best practices.
  • Support technical teams in defining and prioritizing corrective measures.
  • Provide independent expertise within infrastructure evolution projects.
  • Contribute to the continuous improvement of the company's cybersecurity posture.

3. Main Responsibilities

A. Security Assessment

  • Conduct internal and external penetration tests.
  • Perform Active Directory audits.
  • Assess the security of Microsoft Windows, Linux, Microsoft Entra ID, and Azure environments.
  • Analyze the security of networks, authentication mechanisms, exposed services, and privileged access.
  • Review security configurations and identify deviations from best practices.
  • Validate the effectiveness of existing protective measures.
  • Identify exploitable technical vulnerabilities and assess their impact.

B. Offensive Analysis

  • Simulate attack scenarios representative of current threats.
  • Analyze compromise chains and attack paths.
  • Identify possibilities for privilege escalation and lateral movement.
  • Assess network segmentation and security mechanisms.
  • Analyze the security of identities, privileges, delegations, and authentication mechanisms.
  • Identify technical risks that could affect the confidentiality, integrity, or availability of the information system.

C. Consulting, Architecture, and Support

  • Serve as the technical point of reference for all matters related to cybersecurity.
  • Advise IT teams on technical choices impacting security.
  • Participate in architecture reviews from a cybersecurity perspective.
  • Assess the impacts of new projects on the company's security posture.
  • Make technical recommendations to reduce risks while taking operational constraints into account.
  • Participate in technical risk analyses.
  • Support teams in the implementation of remediation measures and in the continuous improvement of security.

D. Documentation and Knowledge Transfer

  • Produce detailed technical reports as well as executive summaries intended for management.
  • Prioritize recommendations based on their criticality, exploitability, and feasibility.
  • Document findings, analyses, security architectures, and remediation measures.
  • Develop best practice guides and contribute to the standardization of security practices.
  • Ensure knowledge transfer and contribute to the upskilling of internal teams.
  • Present mission results to both technical audiences and management, adapting the level of discourse and formulating clear, well-argued, and pragmatic recommendations.

4. Sought Technical Skills

Cybersecurity

  • Internal and external penetration testing.
  • Active Directory audits.
  • Securing Microsoft environments.
  • Securing Microsoft Entra ID and Azure.
  • Securing Linux environments.
  • Identity and Access Management (IAM).
  • Analysis of privileges and authentication mechanisms.
  • Analysis of attack paths.
  • Evaluation of security architectures.
  • Configuration review and system hardening.
  • Vulnerability analysis and remediation recommendations.

Infrastructures

  • Microsoft Windows Server.
  • Active Directory.
  • Microsoft Entra ID.
  • Microsoft Azure.
  • Microsoft 365.
  • Linux (Debian, Ubuntu, or equivalent distributions).
  • TCP/IP networks.
  • Switching, routing, and VLAN.
  • Enterprise Wi-Fi infrastructures.
  • Firewalls and VPN.
  • Knowledge of virtualized environments (VMware, Hyper-V or equivalents) allowing assessment of their security level.

Methodologies

  • OWASP Testing Guide.
  • OWASP Top 10.
  • MITRE ATT&CK.
  • NIST Cybersecurity Framework.
  • CIS Benchmarks.

Documentation

  • Excellent writing skills.
  • Production of technical and executive reports.
  • Documentation of architectures, findings, and recommendations.
  • Ability to communicate technical topics to non-specialized audiences.

5. Desired Profile

The consultant must demonstrate significant experience in cybersecurity acquired in complex environments.

They should notably demonstrate:

  • At least 7 years of professional experience in the field of cybersecurity.
  • Complete autonomy in carrying out complex missions.
  • Excellent command of Microsoft environments, Microsoft Entra ID, Azure, and Linux.
  • Solid experience in conducting penetration tests and technical audits.
  • Strong analytical and synthesis skills.
  • A methodical, rigorous, structured, and results-oriented approach.
  • Excellent organizational and prioritization skills.
  • Ability to interact with both technical teams and management.
  • A critical mindset enabling them to make pragmatic, proportionate, and context-appropriate recommendations.
  • The ability to act as a cybersecurity reference point for internal teams.
  • Excellent documentation, communication, and knowledge-sharing skills.

The consultant must demonstrate professional maturity and favor a pragmatic approach to cybersecurity, based on objective risk assessment, the pursuit of realistic solutions, and supporting teams in their implementation.

6. Desired Certifications

Minimum certification

The consultant must hold at least one recognized offensive cybersecurity certification, such as:

  • Offensive Security Certified Professional (OSCP) or an equivalent certification.

Certifications considered an asset

  • Burp Suite Certified Practitioner (BSCP).
  • Practical Network Penetration Tester (PNPT).
  • Certified Red Team Operator (CRTO).
  • Certified Red Team Professional (CRTP).
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN).
  • Certified Information Systems Security Professional (CISSP).
  • Microsoft Certified: Azure Security Engineer Associate.
  • Any Microsoft certification related to security or Microsoft Entra ID.

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration