jobsswitzerland.ch
← All jobs

Cybersecurity Manager

GLOBAZ SA

Employment type
Full-time
Location
Le Noirmont
Company
GLOBAZ SA, Sous-la-Velle 6, 2340 Le Noirmont
First posted
Apply now

GLOBAZ SA develops and hosts critical IT solutions
Cybersecurity Manager
GLOBAZ SA develops and hosts critical IT solutions for demanding environments in Switzerland: pension funds, health, industry, and administrations. Our activities involve a high level of reliability, security, execution quality, and responsibility. The company is engaged in a significant transformation of its organization and its level of execution.
In this context, we are strengthening our cybersecurity, and we are looking for a:
Cybersecurity Manager
A key function at the heart of the Cybersecurity strategy
As a leader in the governance of sensitive personal data, Globaz puts security, compliance, and sovereignty issues at the heart of its transformation.
We are creating this key function to strengthen our cybersecurity and are thus looking for a person capable of combining strategic vision and operational execution, with a real capacity for influence, who likes to have a real impact and move things forward with pragmatism.
Your role
You are responsible for operationalizing Globaz's cybersecurity strategy and thus guarantee that our services are designed, operated, and continuously improved in a secure manner and in consistency with ISO 27001 requirements.
As the sole cybersecurity technical referent for the BUILD (Technology & Engineering) and RUN (Delivery & Operations) teams, you translate the cybersecurity strategy into architecture, standards, and operational execution.
Your responsibilities
Architecture & Security by Design
Define and maintain technical security guidelines and standards: hardening, network segmentation, IAM, encryption, cloud, workstations, AI security
Perform security architecture reviews on all significant BUILD projects
Uphold Zero Trust principles, segmentation, least privilege, application lifecycle security (DevSecOps, in collaboration with Software & DevOps architects)
Specify security requirements in technological choices and supplier contracts
Keep the technical risk mapping and critical asset inventory up to date
Support teams in the integration of security requirements, from the design and prioritization phases
Operational management of security
Drive the cybersecurity action plan: monitoring remediations, prioritization, monthly reporting
Orchestrate vulnerability management campaigns: scans, prioritization, monitoring of patches with the teams
Lead the security incident management process (in connection with RUN for detection and with a SOC partner) — role of Incident Commander Cybersecurity
Coordinate penetration tests, technical audits, and crisis exercises (Red / Purple Team) with external partners
Prepare and execute ISO 27001 controls on the technical perimeter, provide evidence for internal and external audits
Manage the lifecycle of security tools - not the technical management which is the responsibility of the teams (e.g., EDR / XDR, SIEM / SOC, firewall, IAM / PAM, vulnerability management, MFA, secure backups)
Animation & transversal responsibilities
Lead operational Cybersecurity committees and promote the alignment of teams around security priorities
Raise awareness and train IT teams on cybersecurity issues: directives, phishing campaigns, hygiene, secure development
Act as the operational interlocutor for external audits and clients on technical security issues
Evaluate and prioritize cybersecurity risks according to their business and operational impact
Support management and the Technology & Cybersecurity Governance Office in defining the cybersecurity strategy, producing key deliverables, and updating the ISMS
Your profile
More than 7 years in cybersecurity, including 3–4 years combining architecture and operations, in a technology company
Hands-on oriented profile
Mastery of at least one framework (ISO, NIST CSF, CIS Controls) and key tools (EDR/XDR, vulnerability management, IAM/PAM, hardening, network security)
DevSecOps and CI/CD security experience
Security certification (CISSP, CISM, GIAC or technical equivalent)
Pragmatism, capacity for influence and federation
Ability to popularize and ease of communication, up to the Executive Committee (CoDir)
Knowledge of the LPD, a plus
Fluent French, professional English
Join us now and grow your ambitions
This profile is not a pure governance consultant! It requires the ability to intelligently challenge the existing and to prioritize, including in a context of limited resources, but it offers the possibility of having a concrete impact on the evolution of cybersecurity.
We are looking for profiles that like to advance practices and contribute directly to raising the level.
GLOBAZ SA, your ideal employer, discover our CV!
Show us your passion, we look forward to receiving your application via JobUp.
On our side, we will apply to our future talents and share our GLOBAZ CV with you to convince you that we are your ideal employer. jpid0da6b2djm jpit0937jm jpiy26jm

Automatically translated from the original.

Posted 2 weeks ago

Location

View on Google Maps