Patch Velocity & Software Lifecycle Lead
About this opportunity
Le contenu du poste est libellé en anglais car il nécessite de nombreuses interactions avec nos filiales à l’international, l'anglais étant la langue de travail.
This job offer is accessible to all, regardless of gender.
Job title: Patch Velocity & Software Lifecycle Lead
Location: Lyon or Gentilly, France
Type:Permanent,Full-time,Hybrid
About the job
At Sanofi, we are strengthening our cybersecurity posture by accelerating the remediation of vulnerabilities and enforcing robust software lifecycle governance.
As Patch Velocity & Software Lifecycle Lead within our Vulnerability Operations Center Team, you’ll play a critical role in reducing the organization’s exposure to cyber risks by driving patching velocity and coverage, controlling software obsolescence, and ensuring compliance across our Digital landscape.
This role combines operational acceleration, effective orchestration and transversal leadership to deliver measurable risk reduction at scale.
One-line Mission:Accelerate vulnerability remediation and enforce software lifecycle governance to sustainably reduce Sanofi’s exposure to cybersecurity risks.
Ready to get started?
About Sanofi:
We’re an R&D-driven, AI-powered biopharma company committed to improving people’s lives and delivering compelling growth. Our deep understanding of the immune system – and innovative pipeline – enables us to invent medicines and vaccines that treat and protect millions of people around the world. Together, we chase the miracles of science to improve people’s lives.
Main responsibilities
Drive Patch Velocity & Remediation Performance
Accelerate patch deployment across servers, middleware, endpoints, and application layers
Reduce Mean Time To Patch (MTTP) and vulnerability backlog
Ensure adherence to remediation SLAs, especially for critical and high-risk vulnerabilities
Identify and remove bottlenecks impacting remediation speed
Enforce Software Lifecycle & Obsolescence Management
Define and drive software lifecycle standards (EOL/EOS management)
Ensure continuous upgrade and modernization of software components
Reduce risks related to obsolete and unsupported technologies
Strengthen Software Governance & Catalog Control
Enforce compliance with the Digital-approved software catalog
Implement mechanisms to detect and remove unauthorized software
Reduce exposure linked to shadow IT and unmanaged software components
Ensure Security Compliance by Design
Guarantee that systems are secure and compliant at delivery (golden images, baselines)
Maintain compliance throughout the asset lifecycle
Embed patching and lifecycle requirements into operational processes
Define Policies, Standards & Operating Model
Formalize patch management and software lifecycle policies
Define clear roles, responsibilities, and governance frameworks
Ensure alignment between Security, IT, and Business stakeholders
Drive Transversal Execution
Engage and align cross-functional teams: Infrastructure & Cloud
Digital Workplace
Application Owners
CyberSecurity & Risk and Compliance
Activate the right organizational and technical levers to meet objectives
Measure Performance & Drive Continuous Improvement
Define and monitor key KPIs: Mean Time To Patch (MTTP)
SLA compliance for vulnerability remediation
Patch and lifecycle compliance rates
Unauthorized software rate
Track progress and ensure sustainable improvement (non-regression)
Provide clear reporting and executive visibility
About you
Experience:
Proven experience in cybersecurity, vulnerability management, or infrastructure security
Track record in driving cross-functional transformation or remediation programs
Strong understanding of: Patch management processes and tools
Software lifecycle and obsolescence risks
Enterprise IT environments (endpoints, servers, applications)
Technical skills:
Experience with Windows and Linux environments, and patch management tools (Intune, SCCM, Microsoft Azure Arc, Red Hat Satellite, etc.)
Experience with cloud environments (Azure and AWS)
Experience with vulnerability management, Endpoint Detection & Response (EDR), and SOAR tools
Proficiency in Python and PowerShell scripting
Advanced use of AI technologies for improving operations
Soft skills:
Strong result orientation with focus on measurable risk reduction
Ability to drive performance and accountability across teams
Excellent stakeholder management and influencing skills
Data-driven mindset with experience defining and tracking KPIs
Structured, pragmatic, and execution-focused
Education: Bachelor’s or Master’s degree in Information Security, IT, or related field
Languages: Anglais, Français
Key Success Factor:
Measurable improvement in patching velocity and SLA compliance
Reduction in critical and high vulnerabilities exposure
Decrease in obsolete and unauthorized software footprint
Sustainable increase in global IT compliance levels
Why choose us?
Play a key role in reducing cyber risk exposure at scale
Drive a high-impact, outcome-oriented transformation
Work at the intersection of security, IT, and digital transformation
Contribute to building a more resilient and secure Sanofi environment
What we offer you:
A fixed salary over 12 months, supplemented by a short-term incentive, as well as a collective variable compensation based on Sanofi Group results.
Because taking care of our employees is also our mission: 31 days of paid leave + RTT depending on your status, remote work up to 2 days/week, quality health insurance, public transport coverage up to 80%, extended maternity/parental leave (18/14 weeks), Group Savings Plan & PERCOL with employer matching, PERO, numerous CSE benefits, internal and international mobility opportunities, learning & development opportunities, and many other benefits to discover here .
#LI-FRA
#LI-Hybrid
Pursue progress , discover extraordinary
Better is out there. Better medications, better outcomes, better science. But progress doesn’t happen without people – people from different backgrounds, in different locations, doing different roles, all united by one thing: a desire to make miracles happen. So, let’s be those people.
At Sanofi, we provide equal opportunities to all regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, ability or gender identity.
Watch our ALL IN video and check out our Diversity Equity and Inclusion actions at sanofi.com !
La fourchette salariale pour ce poste est:€64 000,00 - €85 333 Final compensation will be determined based on demonstrated experience, skills, location, and other relevant factors. Employees may be eligible to participate in Company employee benefit programs.
Job details
How this role compares
Computed from every other active Data & Digital role in our database, not just this employer's listings.
We currently track 292 comparable Data & Digital roles across 41 biopharma companies.
Salary context
60 of 292 peers report a salary range (USD, annualized)
Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.
Where these roles are based
Top locations among the 292 comparable roles
+ 14 more countries
Seniority mix
158 of 292 peers have a known seniority level
Therapeutic area mix
6 of 292 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden
Similar opportunities
The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.
How we calculate "similar"
No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.
Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.
0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.