CDIIle-de-france (Hybride)
Vulnerability manager : qualys, cyber security
Hybride
Mission: Support the central security team in leading the vulnerability management
The consultant will be supporting and working in close cooperation with the security operation service lead in the Team and with Manager on the following activities (not exhaustive):
Vulnerability Management
- Challenge Regional CISOs and local IT teams
- Drive continuous improvement of the vulnerability management program, including potential automation
- Define and prioritize processes
- Maintain transparent communication with headquarter office on vulnerability management matters
- Follow up on patch management activities
- Organize meetings and engage key stakeholders as required within the defined services
- Identify business areas where risks may emerge
- Establish and document processes
- Manage exceptions effectively
- Develop KPIs and reporting mechanisms
- Provide reporting
- Lead entities
Qualys Activities
- Ensure comprehensive coverage of the external perimeter in Qualys, leveraging all available data sources
- Manage operational continuity (MCO)
- Perform quarterly assessments of Qualys assets against CMDB or other asset sources
- Include third-party servers in assessments
- Deploy additional agents as needed
- Conduct monthly asset assessments using Qualys against ServiceNow or CMDB to verify agent installation on servers
- Challenge and monitor IT provider KPIs and remediation efforts
Penetration Test Follow-Up
- Ensure Regional CISOs oversee the penetration test process (initiation, monitoring, reporting) in alignment with policy timelines
DELIVERABLES :
- Documentation
- Process & process documentation
- KPI
- Run of the vulnerability management solution
- Minutes & follow-up
SKILL STUDIES EXPERTISE :
Minimum 5-10 years experience in working in a complex/enterprise IT environment
- 2-4 years on Qualys
- Experience with cybersecurity, specifically vulnerability management and architecture, penetration testing,
System security and compliance administration a plus
- Relevant security/network Certifications (CISSP, CCNA, CCIE) preferred
- Familiarity with governing security principals (ITIL, PCI, ISO 27000 series, FFIEC, NYSDFS, NIST)
- Team player with excellent written and oral communication skills
Work independently and in a team environment (same team and cross-functional teams)
- Ability to handle multiple tasks in a fast paced environment
Complete projects and perform daily tasks w/minimal supervision
- Excellent documentation skills
- Excellent troubleshooting skills
High attention to detail
Informations de la mission :
The consultant will be supporting and working in close cooperation with the security operation service lead in the Team and with Manager on the following activities (not exhaustive):
Vulnerability Management
- Challenge Regional CISOs and local IT teams
- Drive continuous improvement of the vulnerability management program, including potential automation
- Define and prioritize processes
- Maintain transparent communication with headquarter office on vulnerability management matters
- Follow up on patch management activities
- Organize meetings and engage key stakeholders as required within the defined services
- Identify business areas where risks may emerge
- Establish and document processes
- Manage exceptions effectively
- Develop KPIs and reporting mechanisms
- Provide reporting
- Lead entities
Qualys Activities
- Ensure comprehensive coverage of the external perimeter in Qualys, leveraging all available data sources
- Manage operational continuity (MCO)
- Perform quarterly assessments of Qualys assets against CMDB or other asset sources
- Include third-party servers in assessments
- Deploy additional agents as needed
- Conduct monthly asset assessments using Qualys against ServiceNow or CMDB to verify agent installation on servers
- Challenge and monitor IT provider KPIs and remediation efforts
Penetration Test Follow-Up
- Ensure Regional CISOs oversee the penetration test process (initiation, monitoring, reporting) in alignment with policy timelines
DELIVERABLES :
- Documentation
- Process & process documentation
- KPI
- Run of the vulnerability management solution
- Minutes & follow-up
SKILL STUDIES EXPERTISE :
Minimum 5-10 years experience in working in a complex/enterprise IT environment
- 2-4 years on Qualys
- Experience with cybersecurity, specifically vulnerability management and architecture, penetration testing,
System security and compliance administration a plus
- Relevant security/network Certifications (CISSP, CCNA, CCIE) preferred
- Familiarity with governing security principals (ITIL, PCI, ISO 27000 series, FFIEC, NYSDFS, NIST)
- Team player with excellent written and oral communication skills
Work independently and in a team environment (same team and cross-functional teams)
- Ability to handle multiple tasks in a fast paced environment
Complete projects and perform daily tasks w/minimal supervision
- Excellent documentation skills
- Excellent troubleshooting skills
High attention to detail
Informations de la mission :
- Début de mission : ASAP
- Durée : 12 mois
- Date de publication : 04/09/2026 18:17:54
Compétences recherchées
Qualys (Indispensable)ServiceNow (Indispensable)CMDB (Indispensable)Vulnerability Management (Indispensable)Penetration Test (Indispensable)Patch Management (Indispensable)KPI (Indispensable)CISSP (Indispensable)CCNA (Indispensable)CCIE (Indispensable)ITIL (Indispensable)PCI (Indispensable)ISO 27000 (Indispensable)FFIEC (Indispensable)NYSDFS (Indispensable)NIST (Indispensable)Cyber Security (Indispensable)Architecture (Indispensable)
Intéressé(e) ?
Rejoignez l'équipe et participez à nos projets ambitieux.