Mission Overview
Keystone Solutions is seeking a Medior GRC Cyber Security Expert for a consultancy mission at a client site. The successful candidate will join a multidisciplinary team dedicated to cybersecurity and will primarily contribute to risk management activities and the updating of security documentation.
Main Responsibilities
The Medior GRC Expert will contribute to the operational implementation of Governance, Risk, and Compliance (GRC) activities. This role will be performed under the supervision of senior experts and will include:
- Conducting cyber risk management activities;
- Reviewing and updating security policies, standards, and procedures;
- Executing various operational activities related to governance, compliance, and information security management systems.
The expert will play an operational role, contributing to deliverables, executing processes, and monitoring GRC activities defined by senior management.
Activities
- Conducting cyber risk analyses and monitoring treatment plans;
- Maintaining risk registers and producing associated reports;
- Reviewing and drafting security policies, standards, and procedures under senior expert supervision;
- Contributing to compliance activities (NIS2, CyFun, ISO 27001) and audits;
- Feeding GRC tools, ISMS, and governance dashboards;
- Supporting the Governance, Risk, and Compliance activities of the Security Pole.
Depending on service priorities, the expert may also work on other security program themes.
Profile Requirements
Education & Experience
- Higher education degree (Bachelor's or Master's) in computer science, cybersecurity, risk management, or equivalent;
- Minimum 3 years of experience in a cybersecurity, risk management, or compliance role;
- Practical experience in conducting risk analyses;
- Experience in drafting or updating governance or compliance documents.
Technical Skills
- Good knowledge of cybersecurity risk management principles;
- Familiarity with ISO 27005 and ISO 27001 standards;
- Knowledge of NIS2 requirements;
- Knowledge of CyFun is a plus;
- Good understanding of IT environments: infrastructures, networks, systems, Active Directory, cloud, applications;
- Ability to use tracking, reporting tools, and GRC platforms.
Personal Qualities
- Excellent writing skills;
- Ability to structure and synthesize complex information;
- Documentary rigor;
- Organizational skills and prioritization;
- Good listening and communication skills;
- Ability to work with technical and business stakeholders;
- Team spirit;
- Autonomy in task execution.
What We Are Looking For
We are looking for a GRC expert capable of producing risk analyses, drafting quality security documents, and ensuring rigorous follow-up of GRC activities. The expert will join an existing team and work under the guidance of senior experts. Their added value lies in their ability to effectively execute defined processes, produce quality deliverables, and advance the governance, risk management, and compliance activities.
Soft Skills
- Rigor in task execution;
- Organizational skills;
- Analytical mindset;
- Good written and oral communication;
- Team spirit.
Evaluation Method
- Fit for the mission;
- Skills;
- Communication and personal qualities;
- Motivation and cultural fit.
Duration
04/01/2027 - 14/06/2027 6 months (full time)
Skills required
- Compétence GRC
- (mandatory) - Level: T2 - Confirmed - Most recent: This year
- Gestion des fournisseurs, marchés publics - Level: T1 - Junior - Most recent: Any time
- Gestion des risques
- (mandatory) - Level: T2 - Confirmed - Most recent: This year
- Gouvernance sécurité / Rédaction de politiques de sécurité
- (mandatory) - Level: T2 - Confirmed - Most recent: This year
- Référentiels Cyber sécurité (NIS2/ISO27001)
- (mandatory) - Level: T2 - Confirmed - Most recent: This year
- Utilisation d'outils GRC - Level: T2 - Confirmed - Most recent: This year
Language requirements
French
(mandatory)
Level Proficiency (C2)