About us
Wherever our customers are in the world, we help them digitalise and optimise their remote business processes using advanced hybrid network solutions and digital technologies.
Our teams work together across the globe, using constant innovation, expertise and applied technology to bring systems and people together with a future focus. We push boundaries. We combine unrivalled resources and expertise in field engineering with advanced digital technologies such as cyber security, IT, and cloud enablement.
Today, we employ 1700 people in over 30 countries, with customers in the maritime, energy, and humanitarian sectors. We believe in creating a culture where you can develop and thrive. Our commitment to excellence drives our success.
Apply nowFrance, Aussaguel
Job
Product Development Cyber Risk Specialist
France, Aussaguel – Full time – Apply before 06.11.26Your Mission
Guide and support project managers in integrating cybersecurity throughout the lifecycle of digital products and services.
The mission focuses on ensuring compliance with key regulations such as CRA and NIS2, alignment with international standards including ISO 27001, and application of recognized best practices like OWASP.
The role also includes managing cyber risks and vulnerabilities to ensure secure‑by‑design and secure‑by‑default products and services.
Main Tasks
Embed cybersecurity requirements from the earliest project stages and ensure their consistent application throughout the project lifecycle.
Perform and review threat modeling and cyber risk assessments using methods such as EBIOS RM.
Translate regulatory requirements (CRA, NIS2) into actionable security controls and project deliverables.
Support ISO 27001 ISMS implementation and align project activities with Annex A controls.
Define, implement, and monitor vulnerability management frameworks, including integration of SAST, SCA, and DAST tools in CI/CD pipelines
Review system, application, cloud, and embedded architectures to ensure effective security controls and risk mitigation.
Coordinate with developers, architects, and stakeholders to track remediation actions and ensure closure of critical vulnerabilities.
Produce audit‑ready documentation, security assessments, and compliance evidence.
Qualifications & Professional skills
- 5 to 10 years of experience in cybersecurity, preferably in product‑oriented or regulated environments.
- Strong knowledge of cybersecurity frameworks and standards: ISO 27001/27002, ISO 27005, OWASP (Top 10, ASVS, SAMM).
- Solid experience in risk assessment and threat modeling methodologies (EBIOS RM, STRIDE, TARA).
- Practical understanding of vulnerability management processes and security testing tools (SAST, SCA, DAST).
- Expertise in integrating DevSecOps practices within CI/CD environments.
- Ability to assess and secure diverse architectures: web, cloud, networked systems, and embedded/IoT.
- Additional experience in penetration testing, security auditing, or security architecture is an asset.
- Fluent English with good writing and presentation skills
Attitude & Interpersonal skills
- Strong communication skills, with the ability to engage and advise diverse stakeholders.
- Analytical mindset and structured approach to problem solving and risk evaluation.
- Proactive attitude with a focus on continuous improvement of security practices.
- Ability to collaborate effectively across project management, R&D, IT, and security teams.
- Strong technical writing skills to produce clear, actionable, and audit‑ready documentation.
- Comfortable challenging designs and decisions constructively to enhance security posture.