Patch Velocity

Il y a 4 jours

Gentilly, Île-de-France Sanofi Temps plein 90 000 € - 120 000 € Contrat

Le contenu du poste est libellé en anglais car il nécessite de nombreuses interactions avec nos filiales à l’international, l'anglais étant la langue de travail.

This job offer is accessible to all, regardless of gender.

Patch Velocity & Software Lifecycle Lead

Lyon or Gentilly, France

Type: Permanent, Full-time, Hybrid

About The Job

At Sanofi, we are strengthening our cybersecurity posture by accelerating the remediation of vulnerabilities and enforcing robust software lifecycle governance.

Le contenu du poste est libellé en anglais car il nécessite de nombreuses interactions avec nos filiales à l’international, l'anglais étant la langue de travail.

This job offer is accessible to all, regardless of gender.

Job title: Patch Velocity & Software Lifecycle Lead

Location: Lyon or Gentilly, France

Type: Permanent, Full-time, Hybrid

At Sanofi, we are strengthening our cybersecurity posture by accelerating the remediation of vulnerabilities and enforcing robust software lifecycle governance.

One-line Mission: Accelerate vulnerability remediation and enforce software lifecycle governance to sustainably reduce Sanofi’s exposure to cybersecurity risks.

Ready to get started?

About Sanofi

We’re an R&D-driven, AI-powered biopharma company committed to improving people’s lives and delivering compelling growth. Our deep understanding of the immune system – and innovative pipeline – enables us to invent medicines and vaccines that treat and protect millions of people around the world. Together, we chase the miracles of science to improve people’s lives.

Main responsibilities

Drive Patch Velocity & Remediation Performance

  • Accelerate patch deployment across servers, middleware, endpoints, and application layers
  • Reduce Mean Time To Patch (MTTP) and vulnerability backlog
  • Ensure adherence to remediation SLAs, especially for critical and high-risk vulnerabilities
  • Identify and remove bottlenecks impacting remediation speed

Enforce Software Lifecycle & Obsolescence Management

  • Define and drive software lifecycle standards (EOL/EOS management)
  • Ensure continuous upgrade and modernization of software components
  • Reduce risks related to obsolete and unsupported technologies

Strengthen Software Governance & Catalog Control

  • Enforce compliance with the Digital-approved software catalog
  • Implement mechanisms to detect and remove unauthorized software
  • Reduce exposure linked to shadow IT and unmanaged software components

Ensure Security Compliance by Design

  • Guarantee that systems are secure and compliant at delivery (golden images, baselines)
  • Maintain compliance throughout the asset lifecycle
  • Embed patching and lifecycle requirements into operational processes

Define Policies, Standards & Operating Model

  • Formalize patch management and software lifecycle policies
  • Define clear roles, responsibilities, and governance frameworks
  • Ensure alignment between Security, IT, and Business stakeholders

Drive Transversal Execution

  • Engage and align cross-functional teams:
    • Infrastructure & Cloud
    • Digital Workplace
    • Application Owners
    • CyberSecurity & Risk and Compliance
  • Activate the right organizational and technical levers to meet objectives

Measure Performance & Drive Continuous Improvement

  • Define and monitor key KPIs:
    • Mean Time To Patch (MTTP)
    • SLA compliance for vulnerability remediation
    • Patch and lifecycle compliance rates
    • Unauthorized software rate
  • Track Progress and ensure sustainable improvement (non-regression)
  • Provide clear reporting and executive visibility

Experience

About you

  • Proven experience in cybersecurity, vulnerability management, or infrastructure security
  • Track record in driving cross-functional transformation or remediation programsli>
  • Strong understanding of:
    • Patch management processes and tools
    • Software lifecycle and obsolescence risks
    • Enterprise IT environments (endpoints, servers, applications)

Technical Skills

  • Experience with Windows and Linux environments, and patch management tools (Intune, SCCM, Microsoft Azure Arc, Red Hat Satellite, etc.)
  • Experience with cloud environments (Azure and AWS)
  • Experience with vulnerability management, Endpoint Detection & Response (EDR), and SOAR tools
  • Proficiency in Python and PowerShell scripting
  • Advanced use of AI technologies for improving operations

Soft Skills

  • Strong