Job Overview
Job description
- Location:
- Courbevoie, IDF, France
- Work arrangement:
- On-site
Role Summary
Your future working environment
Within the Cybersecurity Division, you integrate the Prevent Value Center and the Governance product on our Paris site.
You act as Operational Security and Information System Manager within the framework of the Integration of Security in Projects (ISP) and the maintenance of compliance with the security measures of our clients and our outsourcing contracts.
Responsibilities
Your roles and missions
As an Operational Security & Information System Manager, you work on missions to assist customer CISOs in the management of all or part of their information system. You define the technical and organizational measures to meet their security requirements, formalize them through various deliverables including Security Assurance Plans and any procedure dealing with the operational security of IS. You monitor it on a daily basis through security indicators. You also play a strategic role in providing information, advice and alerting on risks related to the security of the information system.
You will ensure governance of the security of customer contracts under delegation from the CISO of Sopra Steria I2S, ensuring compliance with security rules, supporting operational teams in improving associated measures, and advising on the integration and implementation of security in projects, as well as for the implementation of solutions/services offered by the Cybercenter.
You will also be responsible for ensuring the production and animation of the safety committee, guaranteeing the quality of information and monitoring of actions.
You will manage the contractualized security deliverables, in particular the Security Assurance Plan, the PSSI, the additional Policies, the Control Plan for monitoring deliverables, the RBAC Matrix, the PCA/PRA, the management of security incidents, the management of security patching, and the management of access to the IS.
You will carry out security checks in connection with the IT DICT of our contracts, by defining and producing relevant KPIs.
You will monitor security and vulnerabilities from various sources of information, including our CERT bulletins, and perform first-level analysis on the criticality and impact on our clients' IS. In addition, you will propose the available OS/Middleware/Application security patches to the customer CISO and supervise their proper deployment.
You will monitor the security coverage of IS via various security products, by collecting elements relating to the MCS of the security solutions managed by the teams concerned (e.g. EPP, EDR, etc.) and producing recommendations and an action plan based on the analyzes (e.g. coverage of the fleet by these solutions, updating).
You will manage security incidents by monitoring alerts from security tools and suspicious information reported. You will contribute to the management of security incidents and possible crises, by helping to define the action plan, monitoring the actions put in place and ensuring communication with the client.
- You will provide support for external audits, supporting auditors mandated by the client or company in collecting evidence and understanding the security system in place.
- You will participate in the implementation or improvement of the ISMS of the identified areas.
Requirements
Graduate of an engineering school or university equivalent, you have at least 5 years of experience as a RSO/CISO, and 9 years of experience in Information Systems Security and cybersecurity. You combine the posture as well as the knowledge required for this role.
Soft skills
- Good interpersonal skills and excellent communication and writing skills
- A sense of rigor, a spirit of synthesis and a capacity for popularization
- Good control and management of stress and pressure
- Great adaptability and a good sense of ethics
- An ability to take a step back and anticipate needs
- You have natural leadership and enjoy team spirit
- You are pugnacious in managing your security actions and projects
Know-how
- You know how to manage priorities and risks
- You master strategic security planning
- You are aware of safety standards and regulations
- You master IS security technologies
- You know how to process raw data or through monitoring dashboards (Excel, PowerBI)
- You know how to lead meetings and prescribe your recommendations with convictions
You are certified ISO27001 Lead Implementer, ISO27005 Risk Manager.
You have strong expertise in IT security
- Certifications such as: CSPM, CISM, ISO27002, etc. are a plus.
- Your level of English is fluent, both written and spoken.
- Sopra Steria engages in national and international communities to influence the development of cyber norms and standards. Our group is the first member of the Miter Affiliate Program in Europe, and actively participates in OASIS and InterCERT.
Benefits
What we offer you
- A teleworking agreement to telework up to 2 days per week depending on your missions.
- An interesting benefits package: mutual insurance, a CSE, restaurant vouchers, a profit-sharing agreement, vacation bonuses and co-optation.
- Multiple career opportunities: more than 30 job families, so many pathways to imagine together.
- Hundreds of training courses to develop your skills and evolve within the Group.
- Independent training platforms to prepare for your certifications and support your personal development.
- The possibility of getting involved with our foundation or our partner “Friday”.
- The opportunity to join the Tech'Me UP collective (training, conferences, monitoring, and much more...).
- An inclusive and committed employer, our company works every day to fight against all forms of discrimination and promote a respectful working environment. This is why, committed to diversity and diversity, we encourage all applications and all profiles.
- https: //www.soprasteria.fr/nous-connaitre/nos-engagements
About the Company
About Sopra Steria
Sopra Steria, a major player in Tech in Europe, with 51,000 employees in nearly 30 countries, is recognized for its consulting, services and digital solutions activities. It helps its clients carry out their digital transformation and obtain concrete and lasting benefits. The Group provides a global response to the competitiveness challenges of large companies and organizations, by combining in-depth knowledge of sectors of activity and technologies with a collaborative approach. Sopra Steria places people at the heart of its action and is committed to its clients to make the most of digital technology to build a positive future. In 2025, the Group achieved a turnover of 5.6 billion euros.
The world is how we shape it *
Sopra Steria's Cybersecurity Business Line is present in Europe with more than 2,500 experts - more than half of whom are in France - our mission is to provide trusted solutions and services to the most exposed public and private actors to ensure the resilience of their critical systems and protect their sensitive digital assets.
Beyond the strong European presence, the cybersecurity division is positioning itself and developing in North America (Toronto), as well as in Asia Pacific (Singapore).
We offer 3 areas of offering: Prevention, Protection & detection and response. These 3 areas work together to provide our customers with consistent information and decision-making capabilities informed by operational reality. This approach is based on our transversal methodology centered on Miter Att&ck.
Sopra Steria relies on proven and recognized sovereign capabilities to strengthen your resilience to cyberattacks and accelerate your digital transformation.
An end-to-end trusted solution
A “security by design” approach focused on business risks and transversal to the organization.
A commitment to the development of innovative sovereign solutions.
Each individual can have an impact on responding to these new cyber risk challenges. Everyone contributes both individually and collectively to securing our clients and society while maintaining personal and professional growth.
- Role:
- Operational security & information system manager - Cybersecurity - Ile-de-France
- Industry Type:
- Information Technology And Services
- Job Type:
- Full-Time
Company profile
Sopra Steria
soprasteria.comSopra Steria is a European technology company recognised for its consulting, digital services and software development. It helps large companies and organizations carry out their digital transformation by combining knowledge of their sectors and technologies with a collaborative approach. The group has 51,000 employees in nearly 30 countries and achieved a turnover of 5.6 billion euros in 2025. Its subsidiaries include CS Group, which develops and certifies safety-critical systems for the aerospace, electric and autonomous driving industries.
- Company Size
- 50,000 - 100,000 employees
- Headquarters
- Annecy-le-Vieux, France
- Founded
- 2015
- Funding Stage
- Public