Bull

PSIRT Core Developer R&D (M/F)

Bull

Échirolles, FR

Posted 1 month 1 week ago

Bull is a story. One with a century of European innovation and a working environment where experts design powerful, sustainable, and sovereign digital solutions, enabling states and industries to retain full control over their data and their AI.

Bull is also thousands of engineers, researchers and passionate tech people shaping the future of high-performance computing, AI, and quantum technologies. Every day, our teams push the boundaries of what is technologically possible, supported by world-class R&D, more than 1,600 patents, and unique end-to-end capabilities spanning hardware design, software engineering, data science and quantum research.

Organizational context

The Product Security Incident Response Team (PSIRT) is focused on the security of products developed in Atos BDS. Its objective is to triage vulnerabilities potentially affecting them and ensure they are remediated in time.

The PSIRT core team is not directly involved in implementing remediation, which remains the responsibility of development teams. Its role is to:

  • Monitor potential threats to the security of Atos BDS products.
  • Perform initial triage of potential vulnerabilities.
  • Liaise with product teams to analyze vulnerabilities and decide on remediation.
  • Prepare security advisories related to Atos BDS products.
  • Notify relevant authorities in compliance with regulations, notably the Cyber Resilience Act.
  • Track remediation with support from development teams.

The PSIRT interacts with Product R&D teams, support teams, product managers, and the Chief Product Security Officer.

Role description

The PSIRT Core Developer:

  • Contributes to the 7/7 PSIRT monitoring mission by triaging discovered vulnerabilities.
  • Develops features for PSIRT automation tools to improve efficiency.
  • Interacts with Engineering, Support, and Product Management to confirm vulnerabilities, assess risk, and develop and validate workarounds and remediation.

Key competencies

  • Knowledge of scripting languages, especially Python and Bash.
  • Knowledge of vulnerability management and reporting procedures.
  • Knowledge of security concepts for administrators, especially those useful in a production environment.
  • Fluent written and spoken English.

Nice to have

  • Knowledge of cybersecurity tools, best practices, the CISO role, and ISO 27001 processes.
  • Experience in cybersecurity, including access control, encryption, and collecting and analyzing events.

Similar Job Openings