LE NOIRMONT
Cybersecurity Manager
- 07 September 2026
- 100%
- Permanent position
About the job
GLOBAZ SA develops and hosts critical IT solutions for demanding environments in Switzerland: pension, health, industry and administrations. Our activities involve a high level of reliability , security , execution quality and responsibility . The company is engaged in a major transformation of its organisation and execution level.
In this context, we are strengthening our cybersecurity, and we are looking for a:
Cybersecurity Manager
A key role at the heart of the Cybersecurity strategy
As a leader in the governance of sensitive personal data, Globaz places security, compliance and sovereignty issues at the heart of its transformation.
We are creating this key role to strengthen our cybersecurity and are therefore looking for a person capable of combining strategic vision and operational execution, with a real capacity to influence, who enjoys having a real impact and moving things forward with pragmatism.
Your role
You are responsible for operationalising Globaz's cybersecurity strategy and thus ensure that our services are designed, operated and continuously improved in a secure manner and in line with ISO 27001 requirements.
As the unique cybersecurity technical referent for the BUILD (Technology & Engineering) and RUN (Delivery & Operations) teams, you translate the cybersecurity strategy into architecture, standards and operational execution.
Your responsibilities
Architecture & Security by Design
- Define and maintain technical security guidelines and standards: hardening, network segmentation, IAM, encryption, cloud, workstations, AI security
- Conduct security architecture reviews on all significant BUILD projects
- Promote Zero Trust principles, segmentation, least privilege, application lifecycle security (DevSecOps, in collaboration with Software & DevOps architects)
- Specify security requirements in technology choices and supplier contracts
- Keep the technical risk mapping and critical asset inventory up to date
- Support teams in integrating security requirements from the design and prioritisation phases
Operational security management
- Manage the cybersecurity action plan: remediation tracking, prioritisation, monthly reporting
- Orchestrate vulnerability management campaigns: scans, prioritisation, patch tracking with teams
- Lead the security incident management process (in connection with RUN for detection and with a SOC partner) — role of Cybersecurity Incident Commander
- Coordinate penetration tests, technical audits and crisis exercises (Red / Purple Team) with external partners
- Prepare and execute ISO 27001 controls on the technical scope, provide evidence for internal and external audits
- Manage the lifecycle of security tools - not the technical management which is the responsibility of the teams (e.g. EDR / XDR, SIEM / SOC, firewall, IAM / PAM, vulnerability management, MFA, secure backups)
Facilitation & cross-functional responsibilities
- Facilitate operational Cybersecurity committees and promote team alignment around security priorities
- Raise awareness and train IT teams on cybersecurity issues: policy, phishing campaigns, hygiene, secure development
- Act as the operational contact for external audits and clients on technical security matters
- Assess and prioritise cybersecurity risks according to their business and operational impact
- Support management and the Technology & Cybersecurity Governance Office in defining the cybersecurity strategy, producing key deliverables and updating the ISMS
Your profile
- More than 7 years in cybersecurity, including 3–4 years combining architecture and operations, in a technology company
- Hands-on oriented profile
- Mastery of at least one framework (ISO 27001/27002, NIST CSF 2.0, CIS Controls) and key tools (EDR/XDR, vulnerability management, IAM/PAM, hardening, network security)
- DevSecOps and CI/CD security experience
- Security certification (CISSP, CISM, GIAC or technical equivalent)
- Pragmatism, capacity to influence and unite
- Ability to simplify and ease of communication, up to the Executive Committee
- Knowledge of the LPD, a plus
- Fluent French, professional English
Join us now and grow your ambitions
This profile is not a pure governance consultant! It requires the ability to intelligently challenge the status quo and prioritise, including in a context of limited resources, but it offers the possibility to have a concrete impact on the evolution of cybersecurity.
We are looking for profiles who enjoy advancing practices and directly contributing to raising the level.
GLOBAZ SA, your ideal employer, discover our CV!
Show us your passion, we look forward to receiving your application via JobUp.
On our side, we will apply to our future talents and share our GLOBAZ CV with you to convince you that we are your ideal employer.