Marseille, FR
Internship SOC ANALYST - CYBER DEFENSE CENTER
Led by Rodolphe Saadé, the CMA CGM Group, a global leader in shipping and logistics, serves more than 420 ports around the world on five continents. With its subsidiary CEVA Logistics, a world leader in logistics, and its air freight division CMA CGM AIR CARGO, the CMA CGM Group is continually innovating to offer its customers a complete and increasingly efficient range of new shipping, land, air and logistics solutions.
Committed to the energy transition in shipping, and a pioneer in the use of alternative fuels, the CMA CGM Group has set a target to become Net Zero Carbon by 2050.
Through the CMA CGM Foundation, the Group acts in humanitarian crises that require an emergency response by mobilizing the Group’s shipping and logistics expertise to bring humanitarian supplies around the world.
Present in 160 countries through its network of more than 400 offices and 750 warehouses, the Group employs more than 155,000 people worldwide, including 4,000 in Marseilles where its head office is located.
YOUR ROLE
Your main mission will be to protect the CMA CGM Group by detecting and responding to cyber incidents. In a context where threats are growing in number and complexity, you will have the opportunity to work within a dynamic, motivated team equipped with high-level security solutions. You will report to the SOC Manager.
WHAT WILL YOU DO?
-
24/7 operational monitoring: You will take part in a 24/7 operational SOC, working in rotation (Following the Sun).
-
Analysis and detection: You will analyze, contextualize and monitor security alerts from advanced platforms.
-
Investigation and escalation: You will investigate security events, communicate findings and escalate incidents according to procedures.
-
Stakeholder support: You will handle security service requests (responding to subsidiaries/stakeholders, analyzing malicious or suspicious files).
-
Incident response: You will support incident response (IR) whenever analysis confirms an actionable incident.
-
Threat hunting: You will take part in Threat Hunting exercises and sessions with the CTI (Cyber Threat Intelligence) team.
-
Continuous improvement: You will optimize SOC use cases (detection rule tuning) and contribute to designing and improving playbooks, standard operating procedures (SOPs) and guidelines.
-
Simulations and collaboration: You will take part in incident response simulations and work closely with the SOC RUN Manager, the Lead and the Manager on various tasks and projects.
WHO ARE WE LOOKING FOR?
-
Education: Master's degree in Computer Science, Cybersecurity, Networks or a related field.
-
SOC tools: Proficiency with SIEM, SOAR, as well as network/host logs, firewalls, IPS/IDS and email security gateways.
-
Technical knowledge: Solid understanding of cybersecurity principles and best practices, attack methodologies (Cyber Kill Chain, MITRE ATT&CK), common attack vectors, and concepts such as perimeter defense, endpoint management and data loss prevention (DLP).
-
Programming: Python skills are appreciated.
-
Industry experience: Prior experience in transport, maritime or logistics would be a plus.
-
Personal qualities: Motivated, autonomous and proactive, with strong analytical and synthesis skills, a solid understanding of security logs, real ease working with management, business teams and technical teams, and absolute discretion on sensitive matters.
JOB ENVIRONMENT
-
Location: Marseille
-
From January 2027
Come along on CMA CGM’s adventure !