- Company Name
- SELFING
- Job Title
- Responsable Sécurité des Systèmes d'information - RSSI F/H
- Job Description
-
Job Title: Information Security Manager (RSSI) – Male/Female
Role Summary:
Lead and manage the information security program for a multinational energy group and its subsidiaries, ensuring alignment with corporate strategy, regulatory requirements (NIST CSF v2, RGPD, NIS2, ISO 27001), and industry best practices.
Expectations:
- Develop, implement, and evolve the Group’s Information Security Policy (PSSI).
- Oversee cybersecurity architecture, identity & access management, vulnerability management, threat intelligence, and incident response.
- Manage SOC/CERT operations and coordinate crisis response.
- Define and maintain business continuity and disaster recovery plans (PCA/PRA).
- Deliver cybersecurity awareness and training across the Group.
- Communicate security posture internally and externally, representing the Group to authorities and partners.
- Lead cross‑functional cyber teams (SecOps, GRC, architects) and coordinate efforts across subsidiaries.
- Control the cybersecurity budget.
Key Responsibilities:
- Design and maintain security architecture for network, systems, applications, and cloud environments.
- Implement and manage security controls (EDR, SIEM, firewall, WAF, DLP, IAM).
- Conduct risk assessments (EBIOS) and ensure compliance with ISO 27001, NIST, RGPD, NIS2.
- Lead incident detection, containment, eradication, and post‑incident analysis.
- Plan and test business continuity and disaster recovery procedures.
- Develop and deliver security training and awareness programs.
- Report on security metrics, incidents, and risk posture to executive management.
- Coordinate with legal, compliance, and external auditors.
- Manage vendor relationships and technology procurement.
Required Skills:
- Deep expertise in cybersecurity and information security governance.
- Strong knowledge of ISO 27001, NIST CSF, EBIOS, RGPD, NIS2, and related frameworks.
- Hands‑on experience with EDR, SIEM, firewalls, WAF, DLP, IAM solutions.
- Proven ability to lead and coordinate cross‑functional security teams.
- Crisis management and incident response experience.
- Strategic planning, risk assessment, and continuous improvement skills.
- Excellent communication, influence, and stakeholder management.
- Professional English (written and spoken).
Required Education & Certifications:
- Master’s degree (Bac+5) in Information Security Governance, Cybersecurity, or related field.
- Professional certifications preferred: CISSP, CISM, ISO 27001 Lead Implementer/Lead Auditor, NIST CSF Practitioner.
Saint-rémy-lès-chevreuse, France
On site
25-12-2025