Within the Information Systems Department, the CISO (Chief Information Security Officer) is responsible for defining and implementing the company's security policy.
They work in concert with the security team in charge of operational cybersecurity, as well as the DPO (Data Protection Officer) of the leboncoin group and the Adevinta CISO. The goal is to ensure security, confidentiality, traceability, regulatory compliance, and integrity of the information system and data.
The CISO is responsible for implementing processes related to the availability, integrity, and confidentiality of information about customers, business partners, employees, and companies in accordance with the organization's information security policies.
Their mission includes:
- Defining, disseminating, and monitoring the implementation of the Information Systems Security Policy.
- Analyzing information systems security risks.
- Selecting security measures and defining and monitoring implementation plans.
- Raising awareness, training, and advising on information systems security issues.
- Developing data backup strategy.
- Implementing a business continuity plan.
- Strategizing physical security of premises in relation to general services.
The scope of intervention is the leboncoin group, namely leboncoin and all its subsidiaries.
Qualifications:
We are looking for a profile with soft skills, namely:
- Ability to convince and convey ideas
- Teaching skills
- Ability to onboard and work across departments without hierarchical links
- Rigorous
- Ability to work in an Agile environment where teams constantly adapt
- Results-oriented
Technical skills would also be a significant plus:
- Basics of the OSI model (flow security, http concepts, layer 2 security, IDS/IPS/WAF)
- Basics of encryption (asymmetric vs. symmetric)
- Notions of secure development (sanitizing variable values)
- Able to describe, technically and in broad terms, how a company compromise unfolds
- Must know and be able to explain the limitations of defensive security
- In-depth knowledge of information security technologies, regulatory compliance, information governance, and privacy best practices
Additional Information:
- Position based in Paris
- Compensation based on education level / experience level
- Partial remote work possible