- Company Name
- Stormshield
- Job Title
- Expert en cybersécurité des produits
- Job Description
-
**Job title**
Product Security Officer (Product Security Delegate)
**Role Summary**
Lead security strategy and operations for a cloud‑native SaaS security platform. Drive product compliance with national and industry best‑practice standards, conduct risk analyses, and champion secure development across multidisciplinary agile teams. Act as the primary security liaison within engineering, testing, and product management, ensuring that security is embedded from design through deployment.
**Expectations**
- Demonstrated depth of cybersecurity expertise, independent of a specific technology stack or cloud provider.
- Ability to rapidly assimilate new environments, articulate security requirements, and influence product direction.
- Strong communicative and collaborative mindset; comfortable influencing senior technical, product, and operational stakeholders.
- Proficiency in risk, threat, and resilience engineering for SaaS products, including DevSecOps integration.
**Key Responsibilities**
- Verify product compliance with leading security frameworks (e.g., ANSSI, NIST, ISO 27001).
- Perform comprehensive risk assessments for all product components.
- Define and maintain a Product Security Assurance Plan and Disaster Recovery/Tail of Operations Plan (PRA).
- Draft, communicate, and drive execution of the product security roadmap.
- Evaluate and validate security recommendations from audits and penetration tests.
- Coordinate with the Product Security Officer (PSO) and security audit teams to reinforce operational controls.
- Detect, analyze, and report vulnerability points in product and infrastructure, ensuring timely remediation.
- Act as the day‑to‑day security reference for cross‑functional teams in an Agile/Scrum environment.
- Continuously improve security standards, tooling, and processes.
- Contribute to security community initiatives within the organization.
**Required Skills**
- Thorough understanding of SaaS delivery models, from low‑level networking to application layers.
- Expertise in secure software development lifecycle (Secure Coding, Threat Modeling, Secure Design).
- Proficiency in DevSecOps concepts and tooling (CI/CD pipelines, container security, IaC hardening).
- Strong knowledge of network security fundamentals (firewalls, VPN, SD‑WAN, Zero‑Trust).
- Experience with automated testing frameworks (e.g., Vitest, Cucumber, Gherkin) and vulnerability scanning tools.
- Familiarity with Kubernetes, Docker, GitLab CI, Prometheus, Grafana.
- Hands‑on knowledge of identity and access management (Keycloak, OpenFGA).
- Excellent communication, documentation, and stakeholder‑management skills.
- Ability to bridge technical and business perspectives to drive security value.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- Recognized cybersecurity certifications preferred (e.g., CISSP, CISM, CEH, OSCP, ISO 27001 Lead Implementer).
- Relevant experience in SaaS product security, preferably with experience in regulated environments like ANSSI or equivalent.