Groupe SII
Security Specialist – Application Security (Pentest Coordination)
At a Glance
About This Role
About Groupe SII
Groupe SII (SII Group) is a French multinational technology consulting and engineering firm founded in 1979. Headquartered in Paris, the company specializes in digital transformation, IT services, system integration, and engineering solutions for major international clients. With a workforce of approximately 16,000 employees across 100 locations in 21 countries, SII has established a strong global presence and reported a turnover of €1,022.5 million for the 2022/2023 fiscal year. SII offers a wide range of services, including consulting and research, system integration, and engineering solutions. Their expertise spans various sectors such as aerospace, banking, telecommunications, automotive, energy, and healthcare. The company emphasizes innovation, operational excellence, and strong client partnerships, providing tailored solutions to meet the needs of large corporations and blue-chip clients.
Security at Groupe SII
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- SII positions itself as a strategic partner in cybersecurity with a DevSecOps approach that strengthens security from the design stage.
- The philosophy emphasizes embedding Secure & Privacy by Design concepts and adopting a comprehensive, proactive, and iterative risk approach.
- The focus is on automated security testing and developer enablement through shift-left practices.
Security Team
The AppSec Team includes Muthu Balaraman driving shift-left security initiatives and DevSecOps. Team size details are not publicly available. The team is actively hiring with focus on Shift Left, SAST, DAST, SCA, CI/CD integration, IaC tools (Ansible, Terraform), container security, secrets detection, Nexus IQ, Fortify, and SonarQube.
Key Initiatives
Security Champions program has been revamped and embedded. Shift-left security initiatives and DevSecOps are core priorities. AppSec role-based training has been rolled out. Recent initiatives include deployment of secrets detection capabilities. Vulnerability management intake includes automated security testing, though detailed remediation SLAs are not publicly available.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn