- Company Name
- Sector Group
- Job Title
- Consultant cybersécurité Gouvernance, Risque et Conformité (H/F)
- Job Description
-
**Job title**
Cybersecurity Governance, Risk and Compliance Consultant (M/F)
**Role Summary**
Consultant responsible for delivering a comprehensive cybersecurity assessment for an industrial plant, focusing on inventory creation, backup governance, and compliance with IEC 62443 and related standards. Work across client sites, develop governance frameworks, validate backup systems, and support future expansion of cybersecurity services.
**Expactations**
- Deliver a complete plant inventory (physical assets, networks, applications).
- Design and implement secure backup and business‑continuity processes.
- Ensure all controls comply with IEC 62443, ISO/SAE 21434, TS 50701, ISO 27001, LPM, NIS, ISO 27000 series.
- Provide risk analysis, vulnerability assessment, incident‑response planning, and security logging.
- Conduct stakeholder training and awareness sessions on cybersecurity and standards.
- Support documentation for homologation dossiers (e.g., LPM).
- Engage in emerging cybersecurity topics (NIS2, IEC 63452).
**Key Responsibilities**
- Lead full‑scale inventory and mapping of industrial assets.
- Build and manage a governance framework for backup and recovery solutions.
- Develop and test backup procedures, verifying efficiency and reliability.
- Perform risk assessment, identify vulnerabilities, and recommend mitigations.
- Design incident‑response protocols and logging mechanisms.
- Draft compliance documentation and liaise with regulatory bodies.
- Deliver cybersecurity training and awareness programs.
- Mentor and coordinate cross‑functional teams on GRC projects.
**Required Skills**
- Proven experience in GRC within automotive, rail, or industrial sectors.
- Deep knowledge of IEC 62443, ISO/SAE 21434, TS 50701, ISO 27000/27001, LPM, NIS.
- Expertise in industrial systems architecture and security constraints.
- Proficiency in asset inventory, network/app mapping, and security control implementation.
- Strong backup systems knowledge (design, deployment, testing).
- Ability to conduct risk analysis, vulnerability management, incident response, and security logging.
- Excellent communication, training delivery, and stakeholder management.
- Leadership experience in complex, critical system projects.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Cybersecurity, Information Security, Electrical/Electrical Engineering, or related field.
- Professional certifications such as ISO/IEC 27001 Lead Implementer / Lead Auditor, CISM, CRISC, CISSP, or equivalent.
- Familiarity with IEC 62443 traceability matrix and NIS2/IEC 63452 standards highly desirable.