{"id":1804845,"url":"https://alion.io/job/orange-security-analyst-auditor","title":"Security Analyst & Auditor","company":{"id":52882,"name":"Orange","domain":"orange.com","url":"https://alion.io/company/orange-com","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Phenom","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Ebène, Mauritius"],"countries":["MU"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":72000,"max_usd":166000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1567},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true}],"status":"live","first_seen_at":"2026-10-03T18:27:11Z","employer_posted_date":"2026-10-08","last_verified_at":"2026-10-09T23:06:21Z","board_verified":true,"closed_at":null,"days_open":6,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":6},"description":"Publication date : Sep 11, 2026, 12:00AM\nAbout usJoin us at Orange Business!\nWe are a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business.\nEvery day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate. With over 30,000 employees across Asia, the Americas, Africa, and Europe, we offer a dynamic environment to develop and perfect your skills in a field filled with exciting challenges and opportunities.\nAbout the roleAbout the Role\nSecurity is a strategic priority for Orange Business. Protecting our information assets, digital services and technology landscape is essential to maintaining customer trust, safeguarding the business and ensuring compliance with regulatory and internal security requirements.\nThe Global Policy Controls team is responsible for defining, coordinating and monitoring key cybersecurity governance processes across Orange Business. The team works closely with security stakeholders across the organisation to strengthen its security posture, enhance vulnerability management and drive continuous risk reduction.\nAs a Security Analyst and Auditor, you will conduct technical security assessments and audits, manage vulnerability and security posture activities, and support the continuous improvement of the organisation's cybersecurity controls. Working closely with infrastructure, application and security teams, you will identify and assess technical security risks, coordinate remediation activities, monitor external security exposure, and provide reporting that supports informed risk management and compliance with organisational security standards.\nKey Responsibilities\nTechnical Security Assessments and Audits\nPlan, coordinate and perform technical security assessments across infrastructure, applications, cloud environments and internet-facing services.\nConduct technical security audits, including configuration reviews, vulnerability assessments, architecture reviews and secure configuration validation.\nCoordinate penetration testing, application security assessments and code reviews with internal teams and external providers where appropriate.\nValidate assessment findings to eliminate false positives and ensure the accuracy of reported vulnerabilities.\nProduce clear technical assessment reports detailing findings, risk levels and remediation recommendations.\nPresent findings to technical and business stakeholders and support the implementation of remediation plans.\nTrack remediation activities to ensure audit findings are resolved within agreed timelines.\nContribute to the continuous improvement of technical assessment methodologies and security standards.\nVulnerability Management\nAssess newly disclosed vulnerabilities and determine their impact on the Orange Business’s technology landscape.\nCoordinate remediation activities with infrastructure, application and security teams to ensure vulnerabilities are addressed within agreed service levels.\nValidate vulnerabilities, assess exploitability and support risk-based prioritisation.\nMonitor remediation progress and escalate critical or overdue vulnerabilities where necessary.\nProduce vulnerability dashboards, compliance metrics and management reports.\nMaintain vulnerability management procedures, documentation and operational standards.\nIdentify opportunities to improve vulnerability management processes through automation and continuous improvement initiatives.\nExternal Attack Surface Management\nMaintain an accurate inventory of internet-facing assets, domains, subdomains and public IP addresses.\nIdentify newly exposed assets and ensure they are incorporated into the organisation's security monitoring processes.\nPerform regular external vulnerability assessments using approved security tools.\nValidate discovered vulnerabilities and coordinate remediation with asset owners.\nEnsure internet-facing assets comply with organisational security policies and remediation timelines.\nMaintain documentation and procedures related to external asset discovery and monitoring.\nSecurity Alerts and Risk Coordination\nMonitor critical security advisories, vulnerability notifications and security alerts received from internal and external security sources.\nPerform an initial assessment of security alerts to determine their potential impact on the organisation's technology landscape.\nCoordinate impact assessments with infrastructure, application and security teams to identify affected assets and services.\nWork closely with asset owners and technical teams to ensure appropriate remediation actions are implemented within agreed timelines.\nTrack remediation progress for critical vulnerabilities and provide regular status updates to management and security stakeholders.\nSupport the investigation of significant security issues by providing technical analysis, vulnerability expertise and risk assessment.\nMaintain records of security alerts, impact assessments and remediation activities to support reporting and governance.\nContribute to the continuous improvement of security alert handling, vulnerability response and risk coordination processes.\nReporting and Continuous Improvement\nProduce operational dashboards and management reports covering technical assessments, vulnerability management, security posture and remediation activities.\nDevelop and maintain technical procedures, standards and operational documentation.\nIdentify opportunities to automate repetitive activities through scripting and workflow improvements.\nAnalyse security metrics and trends to support informed decision-making and continuous improvement.\nContribute to the enhancement of cybersecurity governance processes, technical controls and operational practices.\nShare knowledge and support the onboarding and development of team members.\nAbout youKey Requirements\nTechnical Skills\nStrong understanding of vulnerability management and remediation processes.\nExperience performing technical security assessments and security audits.\nKnowledge of operating systems, networking, web technologies and cloud environments.\nFamiliarity with vulnerability scanning, attack surface management and security posture management platforms.\nUnderstanding of penetration testing methodologies and secure configuration practices.\nKnowledge of cybersecurity frameworks and standards such as ISO 27001, NIST and CIS Controls.\nAbility to analyse technical findings and translate them into practical remediation recommendations.\nExperience with scripting or automation (Python, PowerShell or similar) is desirable.\nExperience producing dashboards, metrics and management reports.\nBehavioural Competencies\nStrong analytical and problem-solving skills.\nExcellent written and verbal communication skills.\nAbility to communicate technical concepts to both technical and non-technical audiences.\nStrong organisational and stakeholder management skills.\nAbility to manage multiple priorities and work independently.\nCollaborative team player with a continuous improvement mindset.\nHigh level of integrity and attention to detail.\nRequired Qualifications\nBachelor's degree in Cybersecurity, Computer Science, Information Technology or a related discipline.\nExperience in cybersecurity, vulnerability management, technical security assessments or infrastructure security.\nExperience working across multiple technical teams within a large enterprise environment is desirable.\nDesired Certifications\nOne or more of the following:\nCompTIA Security+\nGIAC Security Essentials (GSEC)\nCertified Ethical Hacker (CEH)\nISO/IEC 27001 Lead Implementer or Lead Auditor (desirable)\nMicrosoft Azure Security Engineer, AWS Security Specialty, or equivalent cloud security certification\nExperience\nAt least 5 years of experience in cybersecurity, IT compliance, or related fields.\n\nLanguages\nFluent in English (written and spoken).\nProficiency in French is an advantage.\nYou bring rigor, passion for challenges, and determination. You seek the opportunity to expand your expertise, achieve your goals, and thrive.\nWhat we offer\nGlobal Opportunities: Work in multi-national teams with opportunity to collaborate with colleagues and customers from all over the world.\n\nFlexible Work Environment: Flexible working hours and possibility to combine work from office and home (hybrid ways of working).\n\nProfessional Development: training programs and upskilling/re-skilling opportunities.\n\nCareer Growth: Internal growth and mobility opportunities within Orange.\n\nCaring and Daring Culture: Health and well-being programs and benefits, diversity & inclusion initiatives, CSR and employee connect events.\n\nReward Programs: Employee Referral Program, Change Maker Awards.\nOnly your skills matterRegardless of your age, gender identity, race, ethnic origin, religion/belief, sexual orientation, marital status, neurotype, disability, veteran status or appearance, we encourage diversity within our teams because it is a strength for the collective and a vector of innovation. Orange Group is a disabled-friendly company and equal opportunity employer: don't hesitate to tell us about your specific needs.At Orange, only your skills matter.\nRegardless of your age, gender, background, origin, religion, sexual orientation, disability, neurodiversity, or appearance, we actively encourage diversity within our teams, as it is a collective strength and a driver of innovation.Orange is a disability-inclusive employer: please feel free to let us know about any specific needs you may have.","description_format":"text","description_chars":9649,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"French","level":"Advanced (C1)","optional":true},{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":["Flexible schedule","Professional development"],"hiring_locations":[{"name":"Mauritius","iso":"MU","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Telecommunications","Telecom Infrastructure","Information Security","Managed Security"],"lifecycle":[{"event":"open","at":"2026-10-03T19:01:25Z"},{"event":"close","at":"2026-10-03T19:16:26Z"},{"event":"reopen","at":"2026-10-03T23:46:36Z"},{"event":"close","at":"2026-10-04T04:40:38Z"},{"event":"reopen","at":"2026-10-04T09:20:11Z"},{"event":"close","at":"2026-10-05T03:33:17Z"},{"event":"reopen","at":"2026-10-05T05:49:55Z"},{"event":"close","at":"2026-10-05T11:23:42Z"},{"event":"reopen","at":"2026-10-05T16:47:41Z"},{"event":"close","at":"2026-10-07T03:21:19Z"},{"event":"reopen","at":"2026-10-07T05:51:40Z"},{"event":"close","at":"2026-10-08T09:20:41Z"},{"event":"reopen","at":"2026-10-08T11:49:25Z"},{"event":"close","at":"2026-10-08T14:25:23Z"},{"event":"reopen","at":"2026-10-08T17:23:38Z"}],"visa":[],"liveness":{"score":18,"band":"cold","label":"Long shot","p_open":1,"p_active":0.51,"p_room":0.35,"age_days":5,"expected_fill_days":2,"reasons":["conf:2","velocity","win:tail","comp:brand"],"computed_at":"2026-10-09T06:01:00Z"},"pay":null,"html_url":"https://alion.io/job/orange-security-analyst-auditor","json_url":"https://alion.io/job/orange-security-analyst-auditor.json","meta":{"generated_at":"2026-10-09T23:07:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"search","counted_by":"address","units_charged":0,"used_today":0,"day_limit":null,"remaining_today":null,"minute_limit":null,"resets_at":"2026-10-10T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":52882},"rest":"https://alion.io/mcp/rest/get_company?id=52882"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Forange-security-analyst-auditor"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Forange-security-analyst-auditor"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Forange-security-analyst-auditor"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/orange-security-analyst-auditor\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Forange-security-analyst-auditor"}]}