- Company Name
- BASSETTI
- Job Title
- Responsable Sécurité Systèmes d'Information F/H
- Job Description
-
**Job Title**
Information Security Systems Manager
**Role Summary**
Strategic and operational security leader responsible for safeguarding the organization’s Information Systems. Oversees security policy, regulatory compliance, risk management, incident response, and business continuity while guiding secure deployment across multi‑cloud and on‑prem environments.
**Expectations**
- Uphold and evolve the company’s Information Security Policy (PSSI).
- Ensure continuous compliance with GDPR, NIS2, ISO27001, and other relevant regulations.
- Manage risk assessments, audits, and corrective actions across all IT assets.
- Lead incident‑management processes and maintain SIEM and CERT operations.
- Champion secure architecture design and multi‑cloud deployments.
- Drive a company‑wide security culture through training and awareness initiatives.
**Key Responsibilities**
- Maintain, review, and improve the PSSI, addressing emerging threats and regulatory changes.
- Monitor regulatory landscape (GDPR, NIS2, etc.) and sustain ISO27001 certification.
- Oversee the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP).
- Conduct risk assessments, internal audits, and recommend mitigation controls.
- Manage SIEM tools, analyse alerts, and coordinate incident‑response workflows.
- Guide IT and production teams in implementing secure solutions, especially in AWS and OVH multi‑cloud contexts.
- Secure network architectures spanning multiple sites and jurisdictions.
- Administer Windows Active Directory and Google Workspace security.
- Develop and deliver security awareness and training programs to all staff.
**Required Skills**
- Deep technical expertise in AWS, OVH Cloud, Windows Server, Active Directory, networking, and Google Workspace.
- Proficiency with security standards: ISO27001/27000 series, NIS2, GDPR, ANSSI.
- Strong knowledge of SIEM platforms and CERT incident‑management practices.
- Experience in risk assessment, audit, and remediation.
- Ability to architect secure multi‑site/international networks.
- Leadership, communication, and teaching skills to translate technical concepts for non‑experts.
- Proven initiative, analytical rigor, and autonomous project management.
- Professional working proficiency in English.
**Required Education & Certifications**
- Minimum Bac+5 (Engineering school, Master’s in Cybersecurity or Information Security).
- Relevant certifications preferred: ISO27001 Lead Implementer, CISSP, CISM, or equivalent.