Now hiring

Security Analyst & Auditor @ Orange

MUOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Publication date : Sep 11, 2026, 12:00AM Orange Business is here! About usJoin us at Orange Business! We are a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business. Every day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate. With over 30,000 employees across Asia, the Americas, Africa, and Europe, we offer a dynamic environment to develop and perfect your skills in a field filled with exciting challenges and opportunities. About the roleSecurity is a strategic priority for Orange Business. Protecting our information assets, digital services and technology landscape is essential to maintaining customer trust, safeguarding the business and ensuring compliance with regulatory and internal security requirements.

The Global Policy Controls team is responsible for defining, coordinating and monitoring key cybersecurity governance processes across Orange Business. The team works closely with security stakeholders across the organisation to strengthen its security posture, enhance vulnerability management and drive continuous risk reduction.

As a Security Analyst and Auditor, you will conduct technical security assessments and audits, manage vulnerability and security posture activities, and support the continuous improvement of the organisation's cybersecurity controls. Working closely with infrastructure, application and security teams, you will identify and assess technical security risks, coordinate remediation activities, monitor external security exposure, and provide reporting that supports informed risk management and compliance with organisational security standards.

About youKey Responsibilities Technical Security Assessments and Audits

• Plan, coordinate and perform technical security assessments across infrastructure, applications, cloud environments and internet-facing services. • Conduct technical security audits, including configuration reviews, vulnerability assessments, architecture reviews and secure configuration validation. • Coordinate penetration testing, application security assessments and code reviews with internal teams and external providers where appropriate. • Validate assessment findings to eliminate false positives and ensure the accuracy of reported vulnerabilities. • Produce clear technical assessment reports detailing findings, risk levels and remediation recommendations. • Present findings to technical and business stakeholders and support the implementation of remediation plans. • Track remediation activities to ensure audit findings are resolved within agreed timelines. • Contribute to the continuous improvement of technical assessment methodologies and security standards.

Vulnerability Management

• Assess newly disclosed vulnerabilities and determine their impact on the Orange Business’s technology landscape. • Coordinate remediation activities with infrastructure, application and security teams to ensure vulnerabilities are addressed within agreed service levels. • Validate vulnerabilities, assess exploitability and support risk-based prioritisation. • Monitor remediation progress and escalate critical or overdue vulnerabilities where necessary. • Produce vulnerability dashboards, compliance metrics and management reports. • Maintain vulnerability management procedures, documentation and operational standards. • Identify opportunities to improve vulnerability management processes through automation and continuous improvement initiatives.

External Attack Surface Management

• Maintain an accurate inventory of internet-facing assets, domains, subdomains and public IP addresses. • Identify newly exposed assets and ensure they are incorporated into the organisation's security monitoring processes. • Perform regular external vulnerability assessments using approved security tools. • Validate discovered vulnerabilities and coordinate remediation with asset owners. • Ensure internet-facing assets comply with organisational security policies and remediation timelines. • Maintain documentation and procedures related to external asset discovery and monitoring.

Security Alerts and Risk Coordination

• Monitor critical security advisories, vulnerability notifications and security alerts received from internal and external security sources. • Perform an initial assessment of security alerts to determine their potential impact on the organisation's technology landscape. • Coordinate impact assessments with infrastructure, application and security teams to identify affected assets and services. • Work closely with asset owners and technical teams to ensure appropriate remediation actions are implemented within agreed timelines. • Track remediation progress for critical vulnerabilities and provide regular status updates to management and security stakeholders. • Support the investigation of significant security issues by providing technical analysis, vulnerability expertise and risk assessment. • Maintain records of security alerts, impact assessments and remediation activities to support reporting and governance. • Contribute to the continuous improvement of security alert handling, vulnerability response and risk coordination processes.

Reporting and Continuous Improvement

• Produce operational dashboards and management reports covering technical assessments, vulnerability management, security posture and remediation activities. • Develop and maintain technical procedures, standards and operational documentation. • Identify opportunities to automate repetitive activities through scripting and workflow improvements. • Analyse security metrics and trends to support informed decision-making and continuous improvement. • Contribute to the enhancement of cybersecurity governance processes, technical controls and operational practices. • Share knowledge and support the onboarding and development of team members.

Key Requirements Technical Skills

• Strong understanding of vulnerability management and remediation processes. • Experience performing technical security assessments and security audits. • Knowledge of operating systems, networking, web technologies and cloud environments. • Familiarity with vulnerability scanning, attack surface management and security posture management platforms. • Understanding of penetration testing methodologies and secure configuration practices. • Knowledge of cybersecurity frameworks and standards such as ISO 27001, NIST and CIS Controls. • Ability to analyse technical findings and translate them into practical remediation recommendations. • Experience with scripting or automation (Python, PowerShell or similar) is desirable. • Experience producing dashboards, metrics and management reports.

Behavioural Competencies

• Strong analytical and problem-solving skills. • Excellent written and verbal communication skills. • Ability to communicate technical concepts to both technical and non-technical audiences. • Strong organisational and stakeholder management skills. • Ability to manage multiple priorities and work independently. • Collaborative team player with a continuous improvement mindset. • High level of integrity and attention to detail.

Required Qualifications

• Bachelor's degree in Cybersecurity, Computer Science, Information Technology or a related discipline. • Experience in cybersecurity, vulnerability management, technical security assessments or infrastructure security. • Experience working across multiple technical teams within a large enterprise environment is desirable.

Desired Certifications One or more of the following:

• CompTIA Security+ • GIAC Security Essentials (GSEC) • Certified Ethical Hacker (CEH) • ISO/IEC 27001 Lead Implementer or Lead Auditor (desirable) • Microsoft Azure Security Engineer, AWS Security Specialty, or equivalent cloud security certification

Experience At least 5 years of experience in cybersecurity, IT compliance, or related fields.

Languages

• Fluent in English (written and spoken). • Proficiency in French is an advantage.

You bring a can-do attitude, tackle challenges head-on and challenge the status quo with new and innovative ideas.

What we offer• Global Opportunities: Work in multi-national teams with opportunity to collaborate with colleagues and customers from all over the world. • Flexible Work Environment: Flexible working hours and possibility to combine work from office and home (hybrid ways of working). • Professional Development: training programs and upskilling/re-skilling opportunities. • Career Growth: Internal growth and mobility opportunities within Orange. • Caring and Daring Culture: Health and well-being programs and benefits, diversity & inclusion initiatives, CSR and employee connect events. • Reward Programs: Employee Referral Program, Change Maker Awards.

Only your skills matterRegardless of your age, gender identity, race, ethnic origin, religion/belief, sexual orientation, marital status, neuroatypia, disability, veteran status or appearance, we encourage diversity within our teams because it is a strength for the collective and a vector of innovation. Orange Group is a disabled-friendly company and equal opportunity employer: don't hesitate to tell us about your specific needs. At Orange, only your skills matter.

Regardless of your age, gender, background, origin, religion, sexual orientation, disability, neurodiversity, or appearance, we actively encourage diversity within our teams, as it is a collective strength and a driver of innovation.Orange is a disability-inclusive employer: please feel free to let us know about any specific needs you may have.

Skills

technical security assessmentvulnerability managementsecurity auditingpenetration testingsecure configurationcloud securitysecurity compliancerisk assessmentsecurity monitoringsecurity reportingsecurity documentationsecurity metrics analysissecurity automationpythonpowershell

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores