About the job Operational Security Engineer (M/F)
CONTEXT AND CHALLENGES
The mission of BGL ProdSec is to ensure a secure, resilient, and compliant production environment, in line with security requirements and best practices, by protecting BGL's critical systems, data, and operations against internal and external cyber threats.
To achieve this, it provides the following security services:
- Identity Management: responsible for managing employee and partner identities and access rights to the bank's systems and data;
- Supervision & Control: responsible for the monitoring, deployment, and maintenance of Active Directory environments and the Anti-Malware Protection framework (EDR and Antivirus). It also ensures the alignment of log collection environments with the Group, in close cooperation with relevant teams, as part of the deployment of new intrusion detection use cases (signals);
- Vulnerability Management & Follow-up: responsible for detecting vulnerabilities and technical non-compliances, as well as organizing and monitoring their remediation;
- Network Filtering: responsible for implementing traffic filtering policies through security devices such as WAF, Firewall, Proxy, and DDoS protection solutions for BGL's critical systems;
- Data Protection & Encryption: responsible for maintaining an inventory of encryption keys and certificates, ensuring the protection of BGL data, and detecting security events across the network.
As an Operational Security Engineer, you will be a member of the Vulnerability Management & Follow-up Squad.
WHAT WILL YOUR ROLE AND DAILY RESPONSIBILITIES BE?
The Operational Security Engineer is a recognized IT expert in their field. They are responsible for a community of practice around a specific discipline and ensure the relevance and performance of their area of expertise in support of the Production Security Center of Expertise (CoE).
The Operational Security Engineer plays a central role and is responsible for monitoring the vulnerability and non-compliance management process, from scan preparation through execution and analysis, to the presentation of findings and the production of security performance indicators.
THE MISSIONS MATTER, BUT SO DO THE TEAM AND THE WORKING ENVIRONMENT!
Your Working Environment
As a member of the Vulnerability Management & Follow-up Squad, your objectives will include:
- Monitoring compliance with security standards through the preparation, execution, and analysis of vulnerability scans;
- Presenting detected vulnerabilities (new findings and those approaching their remediation deadlines) and monitoring remediation activities with stakeholders across the various Tribes;
- Checking the security configurations and patches implemented by technical domains and infrastructure teams (APS and non-APS);
- Producing and publishing security indicators;
- Identifying security vulnerabilities and weaknesses;
- Supporting and collaborating with the Security & Governance function;
- Designing and developing new security solutions.
Technology Watch and Monitoring of Changes to the Regulatory and Standards Framework
- Keep up to date with changes to the regulatory and standards framework through evolving security requirements published by CDF Group and/or requested by the BGL CISO. Highlight identified gaps and propose a convergence plan, including changes to operational security indicators;
- Identify and plan the necessary technological upgrades (Lifecycle Management / Security Patching) for the tools supporting BGL's vulnerability and non-compliance scanning framework;
- Identify and plan the necessary functional enhancements to ensure scan coverage across all assets and technologies;
- Monitor security compliance (PingCastle, etc.).
Operational Maintenance / Maintaining Operational Readiness
- Ensure the operational maintenance of the tools supporting the scanning framework through the management of production incidents, including the corresponding lifecycle management activities and security patching of tools managed by the team;
- Formalize and maintain the documentation supporting the activity, including procedures, operational procedures, guides, and IC Plans;
- Address identified gaps in scan coverage by implementing the necessary remediation measures to ensure comprehensive coverage of On-Premises, DMZ, and/or IT Cloud environments;
- Address gaps resulting from technological changes to scanned assets by implementing the necessary enhancements to ensure comprehensive coverage of On-Premises, DMZ, and/or IT Cloud environments;
- Conduct technical studies and develop Proofs of Concept (PoCs) to validate implemented changes and enhancements.
Remediation Support and Monitoring
- Organize activities by acting as the central point of contact and driving force behind remediation tracking;
- Ensure coordination with the Security functions of business entities, monitor and support the training of these teams, and communicate/implement best practices;
- Organize remediation tracking in compliance with established procedures;
- For each detected vulnerability, identify the remediation owner, present the recommended remediation actions, and communicate the expected SLAs;
- Monitor progress through a formalized Action Plan providing visibility on the owner, required action, execution date, progress, and other relevant information;
- Identify risks of non-completion and escalate deviations as early as possible in the process;
- Act as the link with the IT Risk Management (ITRM) teams for exception requests;
- Perform the security analysis and validate the security impacts associated with activating such exceptions.
Reporting
- Produce and monitor operational security indicators, taking into account both local and Group-level KPIs.
WHAT DOES THIS POSITION OFFER?
By joining our team, you will have the opportunity to:
Take on a new challenge and broaden and strengthen your Cybersecurity skills and knowledge
Discover the work of Cybersecurity experts and engineers
Work at the heart of a complex Cybersecurity environment and collaborate with all areas of the Bank (IT, Business, and other Group entities)
Join a fascinating and constantly evolving field that adapts to current events and emerging threats
ARE YOU OUR FUTURE OPERATIONAL SECURITY ENGINEER?
Behavioral Skills
- Ability to collaborate and work as part of a team;
- Organizational skills;
- Rigor and attention to detail;
- Proactivity;
- Strong oral and written communication skills;
- Adaptability;
- Curiosity and willingness to learn.
Cross-functional Skills
- Ability to understand, explain, and drive change;
- Project management skills;
- Ability to develop and adapt processes;
- Ability to work using Agile methodologies.
Technical Skills
Vulnerability / Non-Compliance Management
- Qualys and Tanium (Vulnerability/Compliance modules, Self-Assessment, APIs, Comply, etc.);
- ELK Stack, Power BI, and Power Query.
Frameworks and Standards
- NIST / CIS Benchmarks;
- OWASP (Open Worldwide Application Security Project);
- PTES (Penetration Testing Execution Standard);
- ISSAF (Information Systems Security Assessment Framework);
- OSSTMM (Open Source Security Testing Methodology Manual);
- ISO 27001.
Environments
- Linux and Windows;
- Cloud environments.
Scripting Languages
- Python;
- PowerShell;
- Regular Expressions (Regex).
Networking
- Detailed understanding and analysis of standard network protocols.
Language Skills
- Fluent French;
- Good written and spoken English.