The position
1 June 2026
Senior Cybersecurity Consultant
Job Description
Against the backdrop of rapidly growing challenges in cybersecurity, compliance, and data protection (GDPR, PCI-DSS, NIS2, AI Act), our digital agency—which specializes in e-commerce, data repositories, and AI —is strengthening its security expertise.
We are looking for an experienced Cybersecurity Consultant who can provide hands-on support to our clients and gradually take on an internal or cross-functional CISO role.
Main tasks:
1. Operational Missions
As a consultant, you will work with large enterprise and mid-sized company clients, primarily in e-commerce, web, and cloud environments:
- Conducting security audits:
- Application Audits (OWASP, APIs, CMS, e-commerce platforms)
- Architecture Audits (Cloud, Hybrid Infrastructures)
- Risk Analysis (EBIOS RM or equivalent)
- Compliance Support:
- GDPR (in connection with the DPO)
- PCI-DSS (online payments)
- ISO 27001 / Information Security Best Practices
- Recommendations and Remediation Plans
- Safety Awareness Training for Technical and Line-of-Business Teams
- Contribution to bids for cybersecurity-related contracts
2. Developing the RSSI role (medium term):
Over time, you will be expected to:
- Contribute to the continuous improvement of the information systems security policy (ISSP)
- Challenging and advancing security governance tailored to a digital agency:
- Process
- Indicators
- Documentation
- Serve as the internal cybersecurity lead:
- Advice for Project, Sales, and Tech Teams
- Balancing Safety and Business Interests
- Oversee matters related to:
- Security Incident Management
- Business Continuity Planning (BCP / PRA)
- Relationships with partners and customers regarding SSI matters
- Preparing for the Transition to a Full-Fledged CISO Role
Typical technical environments:
- E-commerce: Magento / Adobe Commerce, PrestaShop, Sylius, ORO Commerce, Intershop
- Cloud: AWS, Azure, VMware, Kubernetes
- API Architectures / AI Gateway
- CI/CD, DevSecOps
- CMS: WordPress, Drupal, Pimcore, Headless CMS
Profil recherché :
Experience:
- 4 to 7 years of experience in cybersecurity
- Significant experience in auditing, consulting, or application security
- Web, e-commerce, and cloud environments are highly valued
Technical skills:
- Application Security (OWASP Top 10)
- Cloud Architecture Security
- SSI Risk Management
- Standards and Frameworks: ISO 27001, GDPR, PCI-DSS
- A solid understanding of Dev/Ops issues
Transferable Skills:
- Ability to communicate effectively with both technical and non-technical staff
- Commitment to service and advice
- A business-oriented and pragmatic approach to security
- Ability to organize, formalize, and prioritize
Trends & Outlook:
- A natural progression toward a position as CISO or Cross-Functional Security Manager
- Significant exposure to clients and management
- Opportunity to develop a cybersecurity offering within the agency
Why Join Us?
- A Leading Digital Agency in E-commerce
- PSSI in place, ISO 27001-certified company
- Interest in new technologies, AI
- A stimulating technical environment
- ISO 27001 Lead Implementer Certification Offered
- Position of High Strategic Importance
- Long-term vision and tangible progress toward the role of CISO
Our advantages:
- Swile Card (face value of €10, with 60% covered by the company)
- Udemy Business Access
- Executive status 38,5h / RTT
- Participation
- Referral Bonus(es)
- SideCare Health Insurance (for employees and their dependent children; 60% covered by the company)
- Opportunities to transfer between our offices throughout France (Paris, Lyon, Lille, Chambéry, Nantes, Bordeaux, Montpellier, Toulouse, Poitiers)