Fime

Consultant, Cybersecurity

Fime Paris, Ile-de-France, France

IT Services and IT Consulting · 501-1,000 employees

6 h ago
security Mid (2-5 yrs) Full-time France
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will support clients in meeting cybersecurity obligations, specifically focusing on the EU Cyber Resilience Act through gap assessments and risk analysis. Additionally, you will produce technical documentation and provide guidance throughout the engagement lifecycle to ensure client compliance.

What they look for

Cybersecurity EU Cyber Resilience Act Risk assessment Threat modelling Regulatory compliance Technical documentation Gap analysis Secure development lifecycle Applied cryptography Vulnerability handling Audit readiness Stakeholder management Project management Communication skills Consulting

Requirements

Candidates must have 2 to 6 years of experience in cybersecurity consulting or product security and a Master's degree in a relevant engineering field. Proficiency in the EU Cyber Resilience Act and experience with threat modelling and risk management methodologies are required.

Full description

Fime is a globally recognised international player providing deep expertise across digital payments, mobility services, and digital identity. We work with leading organisations worldwide to solve complex challenges, identify emerging opportunities, and future-proof their strategies.

Our team of 900+ experts operates in over 20 locations around the globe, delivering solutions that support millions of transactions every day, across global markets. What sets us apart is our values: we are curious, creative, and highly collaborative, with a strong commitment to integrity - we do the right thing for our clients, our people, and our shareholders.

At Fime, the work is varied and intellectually stimulating. No two days are the same, and you will be surrounded by smart, engaged colleagues who value learning and continuous improvement.

MISSION As a Consultant, Cybersecurity, you will support clients in understanding and meeting their security obligations, with an immediate focus on the landmark EU Cyber Resilience Act (CRA). You will own defined workstreams end‑to‑end, from gap assessments and conformity roadmaps to risk assessments and technical documentation, and progressively expand your autonomy and expertise across the wider connected‑product cybersecurity and compliance landscape.

ACTIVITIES

  • Conduct regulatory gap assessments. Assess client products with digital elements against applicable cybersecurity regulations and standards, with a strong focus on the EU Cyber Resilience Act (CRA), and build clear, actionable conformity roadmaps.
  • Perform product risk and threat analysis. Carry out product risk assessments, threat modelling and vulnerability‑handling reviews, providing structured recommendations to reduce security exposure.
  • Produce high‑quality technical documentation. Create clear, evidence‑driven technical reports and conformity documentation, translating complex technical findings into concise business impacts and remediation actions.
  • Apply quality processes and support audit readiness. Diligently follow internal quality procedures, maintain accurate project artefacts, and contribute to overall audit readiness and continuous improvement initiatives.
  • Guide clients throughout engagements. Provide technical guidance to clients across the engagement lifecycle, clarify requirements and findings, and support scoping discussions with pre‑sales teams.
  • Develop internal knowledge and mentor peers. Contribute to the internal security and regulatory knowledge base, share best practices, and informally support the onboarding and professional growth of junior colleagues.
  • Manage personal delivery performance. Plan and track your own billable activities, log hours accurately, and meet individual engagement milestones and utilisation targets.
  • Support business development. Provide technical input for scoping and proposal development, and periodically represent Fime at industry forums, conferences, webinars, or client‑facing events.

JOB EXPERIENCE

  • 2 to 6 years of experience in cybersecurity consulting, product security, certification/evaluation, or secure development.
  • Working knowledge of the EU Cyber Resilience Act (CRA) and adjacent frameworks (e.g. EUCC, RED‑DA, ETSI EN 303 645, IEC 62443).
  • Experience with regulatory and certification readiness for connected products.
  • Hands‑on experience with threat modelling for connected environments and risk assessment / risk management methodologies.

Nice to have:

  • Exposure to secure development lifecycle (SDL) practices within product or embedded engineering teams.
  • Experience contributing to conformity assessments, audits, or formal certification processes.

KNOWLEDGE & SKILLS

  • Master’s degree (Bac+5 or equivalent) in Cybersecurity, Computer Science, Electrical/Electronic Engineering, Embedded Systems, or a related engineering field.
  • Understanding of secure development lifecycle (SDL), including defining security goals, objectives and controls with appropriate traceability.
  • Knowledge of application security fundamentals (e.g. OWASP), basics of applied cryptography (e.g. key‑management concepts), and awareness of firmware/hardware security analysis.
  • Strong ability to manage complexity and ambiguity, with a customer‑focused and collaborative mindset.
  • Effective communication skills, able to explain technical topics clearly to different audiences.
  • Ability to plan and align work with project priorities and deadlines, driving results with high ownership.
  • Situational adaptability and openness to learning new standards and technologies quickly.
  • Fluency in French and English (oral and written)

Contract: Permanent, full‑time Starting date: Asap Location: Paris, France

Similar roles