Careers
Principal Technical Auditor – Cybersecurity and Control Validation
About Quantum Beyond
Quantum Beyond advises companies and organizations on their strategic decisions related to technology, artificial intelligence, cybersecurity, digital sovereignty, and organizational transformation. Our experts work independently alongside leadership teams and strengthen internal teams as well as their partners.
Your mission
You will independently assess the design, implementation, and actual effectiveness of cybersecurity controls. Your work will allow organizations to verify whether the measures announced, documented, or provided by their partners adequately protect their systems, their data, and their operations.
You will carry out in-depth technical reviews, coordinate the offensive expertise required, and present findings in language suited to technical teams and executives alike.
Key responsibilities
- Plan and carry out technical cybersecurity audits.
- Define the scope, methods, and evaluation criteria.
- Examine security architectures and configurations.
- Verify access controls, privileges, and authentication mechanisms.
- Assess the segmentation of networks and environments.
- Verify data protection and secrets management.
- Examine logging, monitoring, and detection mechanisms.
- Assess the security of cloud services, applications, and APIs.
- Perform or oversee vulnerability assessments.
- Coordinate penetration tests and specialized expertise.
- Validate the quality and coverage of tests performed by third parties.
- Assess the operational effectiveness of controls.
- Verify the remediation of vulnerabilities and nonconformities.
- Gather and document supporting evidence.
- Qualify risks and prioritize corrective measures.
- Produce technical and executive reports.
- Present findings to teams, executives, and governance committees.
- Contribute to improving Quantum Beyond’s audit methods.
Profile sought
- Minimum of 8 years of experience in technical audit, offensive cybersecurity, security architecture, or control assessment.
- Hands-on experience assessing complex environments.
- Solid knowledge of networks, systems, cloud services, applications, and identities.
- Command of vulnerability assessment methods.
- Ability to interpret tool results and confirm their real significance.
- Understanding of technical risks and their operational consequences.
- Independence, rigor, and professional integrity.
- Excellent ability to document and defend one’s conclusions.
- Ability to explain findings clearly to decision-makers.
- Professional French and English.
Assets
- CISA, CISSP, OSCP, GIAC, or an equivalent certification.
- Experience in penetration testing or red teaming.
- Experience in cloud audit, DevSecOps, or application security.
- Knowledge of NIST, CIS Controls, ISO 27001, and SOC 2.
- Experience in critical infrastructure or regulated sectors.
- Knowledge of industrial environments and embedded systems.
- Experience coordinating external laboratories or specialists.
Conditions
Location (on site and remote), compensation based on experience, benefits and working arrangements: to be discussed or determined...
Submit your application
Send us your résumé along with a short introductory note.
