PhD – ” SBOMs at the heart of software supply chain security” (F/M)
Orange
about the roleOrange Innovation brings together the research and innovation activities and expertise of the Group’s entities and countries. We work every day to ensure that Orange is recognized as an innovative operator by its customers and we create value for the Group and the Brand in each of our projects. With 720 researchers, thousands of marketers, developers, designers and data analysts, it is the expertise of our 6,000 employees that fuels this ambition every day.Orange Innovation anticipates technological breakthroughs and supports the Group’s countries and entities in making the best technological choices to meet the needs of our consumer and business customers.Within Orange Innovation, you will be integrated into the CR-BIS management of IT and Services (IT-S). The “Secure Elements & Safe Applications for Mobile Equipment” (SESAME) department brings together around forty engineers, researchers, and technicians working in the field of security elements to secure access to networks and services (e.g., payment, digital identity) and in the area of securing far-edge computing and IoT.Ready to dive into the world of SBOMs (Software Bills of Material) and the security of software supply chains? Your thesis is waiting for you!Recent regulatory requirements (NIS2, CRA, AI Act, DORA Act) have reinforced the need to understand and control the allocation of responsibilities. However, our infrastructures and software are increasingly the result of the dynamic composition of independent products supplied by various players in different fields and with several levels of delegation. This complexity hampers Orange’s ability to control its supplier chains, its commitments to its customers and its new obligations with regard to the new regulations mentioned above.As part of this PhD thesis, you will be required to solve the following scientific problems:What can we learn from SBOMs and their formalisation in the form of graphs?
Can we create metrics to better characterise/predict threats or problems of responsibility sharing/propagation (dilution, concentration, compliance with commitments, CSR impact/energy costs, exposure to the risk of penalties)?
How can SBOM data and metrics be shared without exposing intellectual property?
Can these metrics be integrated into feedback loops in self-adaptive systems?about youSkills (scientific and technical) and personal qualities required by the position
Education
Engineering or Master’s degree in Computing and SecurityWorking Experience (internships, …)
additional information
departmentOrange Innovation brings together the research and innovation activities and expertise of the Group’s entities and countries. We work every day to ensure that Orange is recognized as an innovative operator by its customers and we create value for the Group and the Brand in each of our projects. With 720 researchers, thousands of marketers, developers, designers and data analysts, it is the expertise of our 6,000 employees that fuels this ambition every day.Orange Innovation anticipates technological breakthroughs and supports the Group’s countries and entities in making the best technological choices to meet the needs of our consumer and business customers.Within Orange Innovation, you will be integrated into the CR-BIS management of IT and Services (IT-S). The “Secure Elements & Safe Applications for Mobile Equipment” (SESAME) department brings together around forty engineers, researchers, and technicians working in the field of security elements to secure access to networks and services (e.g., payment, digital identity) and in the area of securing far-edge computing and IoT.contractThesis
Caen, Calvados
Thu, 03 Apr 2025 22:22:08 GMT
To help us track our recruitment effort, please indicate in your email/cover letter where (vacanciesin.eu) you saw this job posting.
Job title: Catering Assistant (Specified Purpose Contract) Company: Leopardstown Park Hospital Job description Job Title…
Job title: Sales Development Representative Company: Qomodo Job description Ciao, siamo - la fintech che…
Job title: Guest Relations Ambassador Company: The Bicester Collection Job description Something Extraordinary Every Day™As…
Job title: IT Compliance Specialist @ Mettler-Toledo Company: Mettler Toledo Job description We are seeking…
Location: Glasgow (G21) - Lanarkshire, Scotland, United Kingdom Salary: £32000 - £40000 per annum Type:…
Job title: Professorship Artificial Intelligence on Campus (m/f/d) in Berlin Company: IU Internationale Hochschule Job…