Context
The mission of the Production Security team is to ensure a secure, resilient, and compliant production environment by protecting critical systems, data, and operations against internal and external cyber threats.
The team provides the following security services:
- Identity Management: Management of user identities and access rights for employees and external partners.
- Supervision & Control: Administration and maintenance of Active Directory environments and endpoint protection solutions (EDR and Antivirus). Support for log collection and intrusion detection capabilities.
- Vulnerability Management & Follow-up: Identification of vulnerabilities and technical non-compliance issues, coordination of remediation activities, and monitoring of corrective actions.
- Network Filtering: Management of security filtering policies through WAF, Firewalls, Proxies, and DDoS protection solutions.
- Data Protection & Encryption: Management of encryption keys and certificates, protection of sensitive data, and monitoring of security events across the network.
As an Operational Security Engineer, you will be part of the Vulnerability Management & Follow-up team.
Role Purpose
The Operational Security Engineer is a security expert responsible for ensuring the effectiveness and continuous improvement of vulnerability management and security compliance processes.
The role covers the full lifecycle of vulnerability management, from scan preparation and execution to remediation tracking and security reporting.
Key Responsibilities
Vulnerability Management & Compliance
- Prepare, execute, and analyze vulnerability scans.
- Monitor compliance with corporate security standards.
- Present identified vulnerabilities and track remediation activities.
- Coordinate remediation efforts with technical and business stakeholders.
- Review security configurations and patch management activities.
- Identify security weaknesses and improvement opportunities.
- Support Security and Governance teams.
- Contribute to the design and implementation of new security solutions.
Technology Watch & Security Governance
- Monitor changes in security standards and regulatory requirements.
- Identify security gaps and propose remediation plans.
- Define improvements to operational security metrics.
- Manage lifecycle and security patching activities for vulnerability management tools.
- Ensure complete vulnerability scanning coverage across all technologies and assets.
- Monitor compliance using dedicated security assessment tools.
Operational Maintenance
- Maintain the operational availability of vulnerability scanning platforms.
- Manage incidents affecting security tools and services.
- Perform upgrades, lifecycle management, and security patching.
- Create and maintain operational procedures, documentation, and recovery plans.
- Address scanning coverage gaps across On-Premises, DMZ, and Cloud environments.
- Conduct technical studies and Proofs of Concept (PoCs) for new security solutions.
Remediation Coordination
- Act as the central coordinator for vulnerability remediation activities.
- Work closely with business security representatives and technical teams.
- Identify remediation owners and define corrective action plans.
- Establish remediation recommendations and expected SLAs.
- Maintain action plans with clear ownership, deadlines, and progress tracking.
- Escalate remediation risks and delays when necessary.
- Collaborate with IT Risk Management teams for exception requests and security risk assessments.
Reporting
- Produce operational security dashboards and KPIs.
- Monitor and report security performance against local and Group standards.
What You Will Gain
- Exposure to advanced cybersecurity practices and technologies.
- Opportunity to work alongside experienced cybersecurity engineers and experts.
- Collaboration with IT, business teams, and international stakeholders.
- Experience in a dynamic and constantly evolving cybersecurity environment.