- Company Name
- Huxley
- Job Title
- expert securité
- Job Description
-
Job title: Security Expert
Role Summary: Provide strategic security oversight across proposal, product, and architecture teams, ensuring SaaS offerings meet cloud, API, and regulatory requirements. Evaluate vendor and cloud security postures, manage risk, and embed secure design principles into product development cycles.
Expactations: Deliver rigorous security analyses, influence architectural decisions, and maintain up-to‑to-date governance documentation. Ensure compliance with ISO 27001/27701, SOC2, GDPR, and internal security standards. Demonstrate strong communication and stakeholder engagement skills while driving continuous improvement of security controls.
Key Responsibilities:
· Act as security liaison for PMO, product squads, and architecture teams.
· Draft security and compliance requirements for SaaS RFPs (cloud, APIs, GDPR).
· Analyze vendor responses: SOC2, ISO27001, penetration test reports, red‑team findings.
· Develop scoring matrices and provide recommendations for supplier security.
· Review documentation for SaaS/cloud solutions (SOC1/2, ISO27701, pentests, red‑team, PAS reports).
· Assess IAM, logging, encryption, resilience, and shared‑responsibility models.
· Conduct risk assessments of integrated SaaS components, classify data, and identify threats.
· Track mitigation plans and residual risks.
· Facilitate workshops on threat modeling, API security, IAM, data protection, GDPR.
· Review architecture designs for security compliance.
· Monitor adherence to internal security standards.
· Evaluate third‑party risk, track non‑compliance issues, and support subcontractor security audits.
Required Skills:
· Deep knowledge of ISO 27001/27701, SOC2, GDPR, OWASP, cloud security frameworks.
· Extensive experience with SaaS and multi‑cloud environments.
· Expertise in risk management, cloud architecture, data protection.
· Strong analytical, autonomous, and rigorous approach.
· Excellent communication and influencing skills.
· Pedagogical approach to Secure‑by‑Design principles.
Required Education & Certifications:
· Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
· Relevant certifications: ISO 27001 Lead Implementer/Lead Auditor, SOC2 Practitioner, CISSP, CISM, Cloud Security Practitioner (e.g., CCSCP).