Cyber Security Expert_ DevSecOps

Sanofi
Bridgewater, NJ
Full-time
We are sorry. The job offer you are looking for is no longer available.

In Digital Cyber Security Dept., we are looking for a Digital Cyber Security Expert into the Vulnerability Operations Center, one pilar of the Vulnerability Operations Center & Legal Ops Team.

Position is focus on Internet Risk Exposure . The activity is global, relates to different categories of assets (Web sites, APIs, Routers, IPs, ) and the team is responsible for detection, analysis and remediation to any possible cyber-threats and / or non-compliances.

Digital Cyber Security Expert needs to be an expert in cyber security. He / She must have expertise in principles of ethical hacking, secure development, and system hardening (Top 10 OWASP, Top 25 CWE, Patch management, ).

Main missions :

Develop end-to-end Vulnerability Management process in order to decrease our risk exposure on Internet

Develop automation of scope update in order to ensure assets exposed on Internet are monitored

Promote the different Vulnerability Detection Services around the company (Vulnerability scanners, Pentest, Bug Bounty, Compliance scanner, )

Contribute to maintaining up-to-date inventory of assets exposed on Internet (usage, type, ownership, components installed, )

Chase Shadow-IT on Internet in order to keep back the control of any system handling Sanofi’ data

Define the roadmap, moving forward step by step with concrete results and promote the value for Cyber Security team.

Contribute to the VOC activity extension to better protect the company

Key Responsibilities :

Strategic Vision

Own and drive Cyber solutions with our vendors

Contribute to define the roadmap and priorities.

Envision proactive detection capability to build automatic response capability based on business context.

Define and Implement the relevant use cases working with the business and Cyber Security Network.

Manage end-to-end the vulnerability remediation and steer the lessons learned.

Promote the vision and the Cyber value added for the company.

Project management

Build and develop the activity according to your roadmap, delivering step by step with visible results.

Work across Digital organization and business entities to enable the most valuable use cases.

Integrate your activity in the existing Cyber ecosystem leveraging the current Cyber components.

Report on regular basis about achievements and metrics.

Communicate via multiple channels to make people more cautious using experience feedback.

Ensure that on-site support teams are trained and ready to answer in case of end user request or alert.

Based on your technical experience and Cyber expertise on some key components like Web site, APIs, Infrastructure components, Database, PowerBI, build a consistent management of vulnerabilities from end-to-end, and contribute to identifying any deviation to best practices.

Leverage as much as possible existing security features already purchased and identify the best combination.

Profile :

Formal Education and Experience Required

University / Master’s Degree in Computer Science, preferably in Information Security.

Real world Vulnerability Management experience.

10 years of professional experience in IS / IT, of which 5 years is in IS / IT Security.

Security Certifications like CISSP or CEH.

Expertise and Competencies

Significant expertise in secure development of Digital components (Web site, Web services, APIs, )

Experience feedback on Vulnerability detection scanners would be preferred

Basic understanding of network infrastructure components, WAF, proxy, and firewalls is necessary.

Experience in Vulnerability management would be preferred.

Basic skills in building SQL request and PowerBi dashboards would be preferred.

Leadership and strong communication skills.

Ability to translate complex technical stories into non-technical language is necessary.

Mastery of English is required.

Experience feedback on O365 and Zscaler cloud services would be preferred.

Basic understanding of computer networks, firewalls, intrusion prevention technologies, and Antivirus technologies is necessary.

Real world experience working with these technologies is expected.

Expertise as a red team penetration tester or a blue team system defender would be preferred.

Experience with Security Information Event Management (SIEM) systems and Event Detection and Response (EDR) technology.

Basic scripting skills in Python, Powershell and Visual Basic would be expected. More advanced programming skills are not required but would add strongly to the profile.

GD-SA

LI-SA

Pursue , discover

Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people people from different backgrounds, in different locations, doing different roles, all united by one thing : a desire to make miracles happen.

So, let’s be those people.

At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, ability or gender identity.

Watch our and check out our Diversity Equity and Inclusion actions at !

3 hours ago
Related jobs
Sanofi
Bridgewater Township, New Jersey

Digital Cyber Security Expert needs to be an expert in cyber security. Digital Cyber Security Expert. In Digital Cyber Security Dept. Define the roadmap, moving forward step by step with concrete results and promote the value for Cyber Security team. ...

Promoted
CACI
Florham Park, New Jersey

Understand Cybersecurity: Work with a team of passionate, intelligent, and innovative software and cyber engineers to understand and identify current and future Cybersecurity needs and challenges. Knowledge of cybersecurity and current and emerging network technologies (IP and Wireless networking, a...

Promoted
TekWissen ®
Morristown, New Jersey

SAP Master Data Analyst / ERP Data Analyst III. We are seeking a detail-oriented [analyst or specialist] who will help with a screening project. Ensure data integrity and accuracy. Hands-on experience with SAP Master Data structures is required. ...

Promoted
AbbVie
Branchburg, New Jersey

Regulatory Compliance Analyst will support all aspects of the Regulatory Compliance processes which include but are not limited to the activities listed below. Under the supervision of the Manager of Regulatory Compliance, the Sr. Identifies and communicates compliance risks to management to ensure ...

Promoted
Insight Global
Morristown, New Jersey

The primary responsibility for the IT Compliance Analyst position will be support of the internal Sarbanes-Oxley (SOX) testing and compliance. The IT Compliance Analyst will be responsible for reviewing, developing, and/or maintaining IT Compliance standards and procedure documentation for business ...

Promoted
Precision Technologies
South Brunswick Township, New Jersey

Perform penetration testing against products and systems, including web applications, web services, and mobile devices.Assist with coordination of vendor pen testing services with internal development teams.Collaborate with stakeholders to develop remediation strategies.Demonstrating practical/worki...

Promoted
Pyramid Consulting, Inc
New Brunswick, New Jersey

Corporate Services Sourcing Data Analyst. Skills; Data Extraction; Reporting, Data Analysis, Supply Chain, Procurement. Complete data analysis of compliance and training program effectiveness. ...

Promoted
Daiichi Sankyo, Inc.
Bernards, New Jersey

Serve as the primary point of contact for customer master data, data warehouse, data security, data integration, database, Manage File Transfer, and enterprise scheduler operational issues. Support Daiichi Sankyo internal business departments, data steward, and sourcing partners with the following a...

Promoted
Source One Technical Solutions
Raritan, New Jersey

Associate, Aggregate Report Compliance will generate compliance metrics and reports in support of MSQ Compliance and Risk Management key partners, including:. Associate, Aggregate Report Compliance will support the oversight of the aggregate report tracking process and compliance monitoring of aggre...

Promoted
Aequor Inc
Summit, New Jersey

Job Title: The Data Stewardship and Compliance Business Analyst. The Data Stewardship and Compliance Business Analyst, Cell Therapy Manufacturing Technology work with a cross-functional team responsible for supporting the production of personalized cell therapy products for global commercial supply....