Friday, July 10, 2020

INFRASTRUCTURE ARCHITECT (IT)

AUTRES INTITULÉS
Architecte technique
Architecte système, stockage et réseaux
Architecte infrastructure globale

ACTIVITÉS PRINCIPALES
Veille et conseil aux équipes de conception
Conseiller l’urbaniste S.I. sur l’utilisation des outils informatiques et télécoms.
Pour toute nouvelle technologie, participer aux études d’impact sur l’architecture existante ou prévisionnelle project architect job description.
Préconiser des choix techniques afin de garantir la cohérence des évolutions.

Participation à la définition des infrastructures techniques
Dans le respect des règles d’urbanisme, définir et gérer les standards techniques.
Assurer la cohérence de l’ensemble des moyens informatiques et télécoms dans le cadre du schéma directeur.
Réaliser et maintenir la cartographie technique du S.I.
Définir et faire évoluer le schéma directeur technique.
Définir et gérer les standards techniques, définir les briques de base du middleware.
Garantir la cohérence de l’architecture technique avec l’architecture applicative du S.I.
Identifie les besoins de changements et les composants impliqués : matériels, logiciels, processus, plateforme, en garantissant l’interopérabilité, le dimensionnement, la disponibilité et la sécurité.

Évalue l’impact des solutions informatique en termes de responsabilités écologiques.

Conduite de projets d’infrastructures
Analyser les besoins en liaison avec les architectes S.I.
Analyser l’impact des solutions applicatives retenues en termes d’infrastructures.
Préconiser des solutions techniques permettant de s’engager sur une qualité et une continuité de service.
Participation au maquettage de la solution.
Définir les procédures d’intégration technique.
Assurer le respect des normes et processus définis dans le cadre du schéma directeur technique.
Elaborer des procédures de tests permettant d’évaluer la performance, la sécurité, la compatibilité et la fiabilité.
 
Suivi et amélioration des processus
Réalise l’audit des infrastructures informatiques de l’entreprise.
Mesure l’efficacité des processus informatiques en termes d’infrastructures.
Rédige des recommandations pour l’évolution des solutions informatiques.
ACTIVITÉS ÉVENTUELLES
L’architecte infrastructure peut être amené à encadrer des équipes d’ingénieurs systèmes, d’ingénieurs réseaux/télécoms et d’administrateurs de bases de données lors de projets de migration.

L’architecte infrastructure peut être en charge des projets de mise en place du plan de reprise d’activité (PRA), avec la définition de la stratégie retenue, le choix des infrastructures, la mise en place des procédures techniques, la réalisation de l’infrastructure de sauvegarde et la mise en place des procédures fonctionnelles (mesures palliatives, communication, …)

VARIABILITÉ DES ACTIVITÉS
Le rôle de l’architecte infrastructure peut varier en fonction de son positionnement en entreprise ou en société de services :

En entreprise utilisatrice, il peut inscrire son action dans la durée et jouer un rôle de conseil auprès du Directeur des systèmes d’information. Il peut encadrer dans le cadre de très grandes entreprises des équipes d’architectes et d’experts techniques.
En société de services, il exerce non seulement un rôle d’expertise technique et d’audit, en proposant de nouvelles solutions à ses clients. Il participe aux phases d’avant-vente et répond aux appels d’offres. Il peut participer à la définition de l’offre de services de son entreprise et coordonner l’intervention d’autres experts de son entreprise sur le projet sur lequel il intervient.
 
Quelques architectes travaillent en indépendant, ce qui leur impose une activité commerciale et de gestion en plus de leurs missions.

PROFIL
Diplômes requis
Formation de niveau Bac +5 (Master 2) spécialisée en informatique et/ou télécoms, sécurité des systèmes informatiques et des réseaux…
Écoles d’ingénieurs (informatique, télécoms, généralistes..)
 
Le certificat de qualification professionnelle d’architecte technique (CQP AT) peut être demandé aux personnes travaillant au sein d’entreprises adhérant au SYNTEC.

Durée d’expérience
Ce poste est accessible aux cadres confirmés possédant au minimum 5 ans d’expérience.

COMPÉTENCES REQUISES
Compétences techniques
Bonne connaissance du système d'information global et de l’architecture du SI et des applications
Excellente maîtrise des systèmes d’exploitation (notamment Windows, UNIX/LINUX), des réseaux et télécoms, des bases de données, stockage (NAS/SAN/DAS)
Connaissance des technologies et outils de virtualisation (VMware, XEN, RHEV…)
Compréhension de l’environnement (clients, secteur d’activité, données sensibles…) et du fonctionnement de l’entreprise
Maîtrise des risques liés à la sécurité des infrastructures et à dématérialisation
Connaissance des normes dans le domaine de l’archivage et du chiffrement
Connaissances des problématiques du green IT et du Big Data
La maîtrise de l’anglais technique est indispensable (documentation en anglais).

Thursday, July 9, 2020

Information security

GLOBAZ's expertise makes it possible to identify the critical elements of information systems and to apply the appropriate measures for their security.

Information capital
Nowadays, information represents an intangible capital which it is essential to preserve. Data lives, shares, transforms and gains value as it evolves. Therefore, they must be protected in order to guarantee companies their availability, integrity, confidentiality and traceability.

Our support proposals
In this context, information security is fundamental. We have all the skills to anticipate, prevent and detect risks, but also to react quickly if necessary.

Benefiting from several years of experience in the field of information security, we support you in the following areas: Information security architecture

information systems risk management and analysis,
audit and examination of vulnerabilities,
drafting and implementation of security policies, directives and procedures,
information systems security architecture,
surveillance, detection and penetration tests,
training and awareness,
security consulting,
implementation of an information security management system based on ISO27001.

Wednesday, July 8, 2020

security architecture consultant at Cyberswat do?

Asks and responsibilities:
Develop and revise security architectures for complex systems;
Identify security objectives in compliance with security policies and standards;
Conceptualize and implement security management solutions;
Act as a technical expert with clients;
Define technical security specifications in contracts;
Carry out security audits and check compliance with procedures;
Categorize the assets of the organization;
Evaluate the residual risk when there is a difference between the defined architecture and the one implemented architect job description

Requirements:
10 years of experience in the information technology field;
A minimum of 8 years in information security;
4 years of experience in security architecture (confidentiality, authentication, identity and access, standards, policies, intrusion detection, security perimeter, etc.);
Hold at least a DEC in computer science or information technology.
Strengths:
Hold a certification among the following: CCSK (Certificate of Cloud Security Knowledge), Certified Information Systems Security Professional (CISSP), Risk Manager ISO 27005, Lead auditor ISO 27001), Certified Information System Auditor (CISA), CCNA-Security.

Tuesday, July 7, 2020

IS security has its place in the enterprise architecture

Patrick Chambet, IT security architect and security expert at Bouygues Telecom
The concept of enterprise architecture, very fashionable these days, has a more general framework than traditional technical architecture. It models the business of the company and its processes. He is urbanizing his information system and helping to extend the process to the technical architecture. In summary, it brings a more global vision and builds on the functional areas of the business, in addition to the resources of the IT department. It takes into account in particular the organization, business processes, governance, global architecture, IT production and security enterprise security architect.

The safety architect alongside the chief architect
The security architecture is fully integrated into the overall architecture of the IS. At Bouygues Telecom, the RSSI also works within the ISD itself, in the governance, tools and architecture department, alongside the chief architect. This promotes close relationships between IS security and the central architecture. It also helps to design the target architecture of the IS by integrating the security elements contributing to the common objective of quality of service. Security is therefore an integral part of the overall architecture of the IS. It also provides traditional perimeter security services (network filtering architecture, firewalls, DMZ, VPN, etc.) and defense in depth (trusted spaces, access controls at the resource level, detection of intrusion, etc.), several building blocks of infrastructure in the form of shared services. For example, identity and authorization management, authentication directories (Active Directory, LDAP), enterprise PKI, IS access platforms for external partners, secure file transfer service with the outside, etc. More concretely, security spans the entire architecture of the IS. Security requirements are therefore an integral part of the design of the various systems and the applications constituting it. In this context, the technical architects who design the applications must respect the good practices formalized in the security standards of the company's IT developments.

Assess the risk on each IS brick
The relations between the technical architects and the security architect come up against differences in vocabulary, which must be clarified first, by offering them initial training in the concepts of security, in particular in application. Once the common language is assimilated and the first reflexes acquired, the dialogue is much more constructive, because the various stakeholders better understand the risks which weigh on the various systems composing the IS (and therefore on the business processes based on those -this). They also measure the security needs necessary to limit these risks to an acceptable level (without even having to address the ISO 27001 standard). The company's IS is increasingly extended to its partners, including publishers who very often request contractual access to external maintenance for their products installed at the heart of the IS, including in production. This constitutes a non-negligible risk that the adapted and particularly secure access architectures must cover: network filtering, encryption of flows, individual authentication, protocol breaks, enhanced traceability. For all these reasons, taking security into account in the design of the enterprise architecture is already completely essential. individual authentication, protocol breaks, enhanced traceability. For all these reasons, taking security into account in the design of the enterprise architecture is already completely essential. individual authentication, protocol breaks, enhanced traceability. For all these reasons, taking security into account in the design of the enterprise architecture is already completely essential.

Monday, July 6, 2020

Cyber ​​security in software development: the good rules to follow

Cyber ​​security must be the cornerstone of the software code development process . It is of fundamental importance, in fact, to guarantee the safety requirements in every phase of its life cycle. From the embryonic phase of the project, a path must be taken that has information security as its guiding thread .

According to this modus operandi, it is necessary to apply development rules and make use of professionals with specific skills. An information security risk assessment and an impact assessment is required to ensure the privacy of sensitive data processed by the project application.

Finally, a test repeated over time in all phases of the software life cycle is indispensable.

Topic index

Cyber ​​security in software development: the risks
Paying attention to cyber security in development is important to minimize vulnerabilities , related to possible programming errors, which can be exploited by increasingly effective and constantly increasing cyber attacks, but also affect the quality of the final product.

Protecting the code and data managed by the application being developed as well as guaranteeing the IT security protection parameters ( integrity , confidentiality and authentication ) must represent the main objectives of software security.

Cyber ​​security in software development: the stages
We will describe below the various phases of the software life cycle, according to a common denominator: to guarantee the security requirements of the data, functions and programming language.


The precise definition of these phases and their organization constitutes a development model: the so-called software life cycle model . The model to which we will refer is for simplicity a cascading model which, as the name suggests, is nothing more than a sequential succession in which, only after completing a phase, we move on to the next.

This does not mean that each phase can be revised to be eventually revised and corrected: in fact there are alternative and less rigid models than the one proposed, to make the entire production and management process of the software more reliable.

Each phase must be verified and approved in compliance with certain guidelines consistent with the main safety standards .

Feasibility study
It is the phase in which possible costs and benefits of the product to be developed are evaluated. A document is produced which must contain: Security architecture definition

the definition of the project;
possible solutions and their reasons;
for each of the proposed solutions, the estimate of the benefits, costs, resources required and delivery times.
Analysis and specification of requirements
This phase aims to determine the functionality required by the customer and the properties of the software in terms of performance, safety, ease of use, portability and maintenance .

The collection of requirements must take into account the technological and regulatory context. These properties are also recorded in a document, which will allow the customer to verify the specified characteristics and allow the designer to proceed with the development of the software architecture. In this phase it can be foreseen to draw up a user manual and a definition of the system test methods .

PA FORUM 6 - 11 JULY
Building digital trust: cybersecurity and privacy
Network Security
Privacy
Sign up for the event
The analysis and specification of the safety requirements represents an important and conditioning element for the solution that will be decided upon.

Particular attention will have to be paid with regard to the choice of the operational safety modalities of the application, infrastructure and development environment.


System architecture design
The purpose of this phase is the production of a document containing a description of the software architecture both globally and at the level of the individual integrated and interacting modules.

The functions and solutions proposed in the feasibility phase will be analyzed , times and resources planned for the implementation of the requirements and the conduct of the tests, and establish the safety rules defining with the developers the programming language to be used and the characteristics of the application.

This is the moment in which to carry out preliminary investigations for the drafting of a risk assessment document to which the application is exposed, and of impact assessment on data processing , to safeguard information security respectively ( ISO 27034, ISO 29151 ) and the protection of personal data ( GDPR - General Data Protection Regulation, EU regulation 679/2016 ).

Realization of individual components and their verification
It is the phase in which the programs are actually implemented by applying rules of good practice for the safe drafting of the code and by performing functionality tests and searching for any vulnerabilities.

For each component we provide:

encoding
documentation
specification of the tests carried out
For security purposes, the development environments must be equipped with audit, backup, access control systems and kept up to date and protected by specific software security modules on the basis of guidelines shared and imparted by subjects providing support, training services and information.


System integration and verification
This phase has the purpose of assembling the product code, checking its effective compatibility, solving any interaction and security errors, and may not be considered conceptually distinct from the previous phase.

It is advisable to prepare a test plan with test cases and related acceptability criteria, simulating intrusions with various attack scenarios, keeping the test environment separate from the development environment.

The objectives of the tests must allow to highlight the degree of exposure of the software to known vulnerabilities and to review the source code in search of anomalies in the correct functioning of the security controls and operational specifications.


Delivery
In this phase, the system is distributed to users who verify its operation, identifying any anomalies or dissimilarities with respect to the project specifications. For the release of the software in production it is necessary to have passed an acceptance test to verify compliance with the functional and safety requirements , to have created a system documentation and planned training for users and users.

Delivery takes place in two stages:

Beta test : the system is distributed to a selected set of users for the purpose of testing in real cases. The errors found should be corrected before the actual distribution of the product.
Distribution : the software is permanently released to users. The errors that are found after this release are usually corrected in subsequent versions or through the use of appropriate corrective software.
Maintenance
This phase encompasses all the evolution of the system from delivery onwards. It therefore includes modifications and evolutions of various types . Furthermore, the maintenance phase, encompassing each activity that follows the delivery of the product, can affect well over half of the overall costs of the entire life cycle.

Conclusions
The cost of correcting a vulnerability or error is higher the later it is detected in the life cycle. For this reason, the safety requirements should be acquired and verified before development and production.

A planned test, verifying the completeness and consistency of the functions, the quality, safety and functionality of the software, can in fact help to identify any anomalies when the cost for the correction does not significantly affect.

Periodic tests can also be useful in the post delivery (maintenance) phase . In fact, they can prevent the outcomes of any new vulnerabilities and / or attack techniques and monitor the application functionality following significant changes in the product delivered.

The key to obtaining a good result is to structure a project team by clearly defining roles and responsibilities such as the project manager, the safety manager, programmers, system engineers, testers, customers, suppliers and end users.

In some cases, it may be necessary to provide preventive training for all development personnel by specifying 5 macro areas:

policies and guidelines for software lifecycle security;
best practices for safe code compilation;
security issues according to the technologies used;
code vulnerabilities that could be exploited by cyber attacks;
reference standards on software security.

Friday, July 3, 2020

ROBBERIES WITH STRENGTH IN RESIDENCES GROW 5.3% IN THE FIRST HALF OF 2013

In order to interpret statistics objectively and draw conclusions that are not biased, an exhaustive analysis is required, which is not what I intend to carry out in this paper. It is true that, on the one hand, robberies in private homes seem to decrease, on the other hand, on the other hand, robberies with violence in homes, preferably isolated ones, increase significantly.
Robbing banks, robbing ATMs, jewelry stores, is embarrassing and technically complicated. Assaulting more or less protected solitary homes imposes some difficulties, due to the fact that their protection has been significantly increased by security systems with more or less protection capacity.
Consequently, the offender is more profitable to attack solitary houses, with the inhabitants inside, intimidation, aggression, the pressure generated allows unique possibilities to carry out crime.

There has been talk of intimidation by drug traffickers while they slept, now there is a lot of talk about burundanga, (Scopolamine). But the most striking thing is direct aggression, violent intimidation. In our country we are not used to this type of violent actions.
As occurs on many occasions, in the end it is civil society itself that manages to solve its problems, providing means, (See nightly rounds of surveillance between neighbors, somatén), actions and habit changes to minimize these circumstances that in one way or another are repeated over time.
In this sense, we are in a much more favorable situation than a few years ago. We have technological means that, properly applied, provide effective solutions to avoid or at least divert the criminal will towards other objectives. (This is what happened with the security of ATMs or gas stations).
Companies dedicated to security can play a significant role in this field. It would seem wrong to me that my reflection could be interpreted as a manifesto of business opportunity, despite the fact that the business flows from the opportune coincidence of the hand of whoever does it. But my reflection is directed to the opportunity to exercise our profession by providing solutions with creative, effective and value-adjusted applications to offer to those who may need them. I insist, with common sense, responsible work and creativity, above economic objectives subject to opportunism.
It is also worth remembering to those who may need it that the <reed boats> sink more easily than the wooden ones. Hard to four pesetas do not exist.
My represented AUX-VYD VSS, provides a unique peripheral security solution for this type of risk that solves an important part of the incident factors. Through the conjunction of different technologies, with their own intelligence, they allow them to effectively resolve situations that usually precede claims of this type. This creativity is worth appreciating, leaving behind mediocrities that apparently leave users alone but are indifferent to criminals, due to lack of rigor in the application and insufficient resistance to being violated.

Wednesday, July 1, 2020

Cloud security architect

Being a Cloud Security Architect at CGI means having the opportunity to participate concretely in various projects in world-class organizations. Each mandate, whether governmental or private, development or migration, will give you a distinct advantage in the market.

Becoming a consultant at CGI will not only allow you to broaden your field of expertise in several technos, but will also give you this opportunity to advise our clients on appropriate technologies and methodologies that will meet their needs.

Our team is dynamic and encourages collaboration, exchange and initiative. Respect and pleasure are the basis of our working environment. Our experienced team will guide you on your arrival and support you in the development of your career systems architect job description.
Give your career a boost.

The information technology (IT) sector is going through an extraordinary period. The digital transformation of organizations continues to accelerate, and CGI is at the forefront of this change. We support our clients in their digital approach and offer our professionals stimulating career opportunities.

CGI's success depends on the talent and commitment of our professionals. Together, we meet the challenges and share the benefits from the growth of our business. This approach strengthens our shareholder-owner culture, so all of our professionals benefit from the value that we collectively create.

Join us to participate in the growth of one of the largest independent information technology (IT) and business process management companies in the world.

To learn more about CGI: www.cgi.com.

Unsolicited applications from recruiting firms will not be considered.

CGI promotes employment equity. In addition, CGI is committed to providing accommodations to people with disabilities, in accordance with provincial legislation. Please let us know if you live with a disability requiring reasonable accommodation as part of our recruitment process, we will work with you to meet your needs.
Functions and responsibilities
In the context of IT projects in a private or public cloud environment, advise and support development or technology teams in particular:
Identify project security challenges in a cloud environment and develop adjacent strategies to respond to them;
Support clients in the design phases of secure cloud architectures
Categorize information (availability, integrity, confidentiality);
Write security advisories about sometimes complex situations in a cloud environment;
Perform various comprehensive analyzes on aspects of digital information security;
Collaborate in the development of positioning and orientations with the various stakeholders in IT services in a cloud computing environment;
Participate in the definition of cloud security framework requirements;
Perform the required risk analyzes and ensure constant monitoring.
Qualities required to succeed in this role
Hold an undergraduate university degree in computer science or a related discipline or equivalent experience;
Have between five (5) and ten (10) years and experience in the field of information technology, including three (3) years in IT security architecture;
Have completed security architecture mandates in a cloud environment;
In the last three (3) years, having participated in a project using methodologies based mainly on Scrum, Kanban and Disciplined Agile 2.0 (DAD), and (2) adaptation of Center DMR Productivity version 3.5 (Green Guide);
Have written analysis reports;