About this role
<p><span style="font-family:tahoma, arial, helvetica, sans-serif"><strong>Bull</strong> is a story. One with a century of European innovation and a working environment where experts design powerful, sustainable, and sovereign digital solutions, enabling states and industries to retain full control over their data and their AI.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif"><strong>Bull</strong> is also thousands of engineers, researchers and passionate tech people shaping the future of high-performance computing, AI, and quantum technologies.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">Every day, our teams push the boundaries of what is technologically possible – from next-generation HPC architectures to exascale supercomputers – supported by world-class R&D, more than 1,600 patents, and unique end-to-end capabilities spanning <strong>hardware design, software engineering, data science and quantum research. </strong></span><span style="font-family:tahoma, arial, helvetica, sans-serif">We are a people-centric, innovation-driven company, where collaboration spans Europe, the Americas and India. We share a common vision of a responsible and sustainable innovation that delivers concrete impact for our customers.</span></p><p> </p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif"><strong>Organizational context:</strong></span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif"> The<strong> Product Security Incident Response Team (PSIRT) </strong>is a dedicated team focused on the security of the product developed in Atos BDS. Its objective is to triage the vulnerabilities potentially affecting them and to ensure they are remediated in time. The PSIRT core team is not directly involved in the implementation of remediation, which remains to be done by development teams.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">Its role is to: </span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Monitor the potential threats to the security of Atos BDS products.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Make a first triage on the potential vulnerabilities.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Liaise with the product teams to further analyze the vulnerabilities and decide over remediation.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Prepare security advisories related to Atos BDS products.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Notify relevant authorities in compliance with regulations (notably the Cyber Resilience Act)</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Track the remediation with the support of development teams.</span></p> <p> </p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">The PSIRT interacts with:</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Product R&D teams through Product Security Officers, to ensure in-depth analysis of potential vulnerabilities and remediation availability.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Support teams to help addressing Customer issues with respect to vulnerability remediation.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Product Managers to help prioritize remediation and assess security risks.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• The Chief Product Security Officer (CPSO) who is responsible for the overall governance of Product Security in Eviden’s delivered products.</span></p> <p> </p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif"><strong>Role description: </strong>The PSIRT Core Developer:</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Contributes to the 7/7 main monitoring mission of PSIRT in triaging the discovered vulnerabilities.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Develops the features of the PSIRT automation tools to improve PSIRT efficiency.</span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Interacts with Engineering, Support, and Product Management to confirm vulnerabilities, assess their risk, and elaborate and validate workarounds and remediation.</span></p> <p> </p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif"><strong> Key competencies:</strong></span></p> <p><span style="font-family:tahoma, arial, helvetica, sans-serif">• Knowledge of scripting languages, especially python and bash.</span><br><span style="font-family:tahoma, arial, helvetica, sans-serif">• Knowledge on vulnerability management and reporting procedures</span><br><span style="font-family:tahoma, arial, helvetica, sans-serif">• Knowledge on security concepts for administrators especially those useful in a production environment</span><br><span style="font-family:tahoma, arial, helvetica, sans-serif">• Fluent written and spoken English Fluent written and spoken English.</span><br><span style="font-family:tahoma, arial, helvetica, sans-serif">Nice to have:</span><br><span style="font-family:tahoma, arial, helvetica, sans-serif">• Knowledge on cybersecurity tools, best practices, CISO role and ISO 27001 processes</span><br><span style="font-family:tahoma, arial, helvetica, sans-serif">• Experience in Cybersecurity area: access control, encryption / collecting & analyzing events.</span></p>