Information Security Analyst

RemoteLeads

France

Sur place

EUR 60 000 - 90 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

RemoteLeads is seeking a GRC/Information Security Analyst to maintain ISO 27001 controls, ensuring they stay effective, documented, and evidenced. You will support audits, coordinate corrective actions, and run recurring security activities such as vulnerability reviews, access reviews, and policy refresh cycles across AWS, Google Workspace, Slack, and other platforms.

The role includes evaluating new tools for security risk, helping with AI governance initiatives, and integrating acquired

Qualifications

  • 3+ years of experience in GRC, compliance, or information security
  • Solid knowledge of ISO 27001 and Annex A controls
  • Hands-on with vulnerability management tools and access governance processes
  • Experience with AWS security tools and triaging findings
  • Exposure to AI tooling to accelerate compliance work
  • Ability to explain security topics to engineers and executives
  • Familiarity with cloud environments and SaaS administration tools
  • Experience mapping requirements across frameworks (HIPAA/HITRUST preferred)

Responsabilités

  • Maintain and improve ISO 27001 controls, ensuring they remain effective and documented
  • Support audits, surveillance audits, and recertification cycles
  • Track corrective actions, nonconformities, and continuous improvement
  • Run recurring security activities: vulnerability campaigns, access reviews, risk assessments, and policy reviews
  • Triage vulnerability findings from AWS GuardDuty/Inspector and define remediation priorities
  • Perform periodic access reviews for critical systems (Google Workspace, AWS, Slack, etc.)
  • Review new tools/vendors for security and compliance risks before adoption
  • Help harden internal workflows focusing on IAM, MFA, SSO, and data handling
  • Support security questionnaires, RFPs, and customer due diligence
  • Assist AI governance, SaaS governance, and integration of acquired entities into ISO scope

Connaissances

English communications
Governance & compliance
Risk assessment
Vulnerability management
Access governance
AI tooling for compliance

Outils

Vanta
AWS GuardDuty
AWS Inspector
Google Workspace
Slack
IAM / SSO

Description du poste

Description:


  • Maintain and improve the ISO 27001 management system so controls remain effective, documented, and continuously evidenced.

  • Support internal audits, surveillance audits, and recertification cycles, including the unified audit covering Didomi and acquired business units.

  • Track corrective actions, nonconformities, and continuous improvement initiatives through to closure.

  • Run recurring security calendar activities, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles.

  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources and help define remediation priorities.

  • Perform periodic access reviews across critical systems such as Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications.

  • Review new tools, vendors, and SaaS applications for security and compliance risks before adoption.

  • Help assess and harden internal workflows with a focus on identity and access management, MFA, SSO, and data handling.

  • Support security questionnaires, RFPs, and customer due diligence requests.

  • Support broader initiatives such as AI governance, SaaS governance, and integrating acquired entities into the ISO scope.


Requirements:


  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally in a SaaS or technology company.

  • Solid working knowledge of ISO 27001, including Annex A controls and the audit process.

  • Hands-on experience with vulnerability management tools and access governance processes.

  • Hands-on experience with Vanta, including running ISO 27001 or comparable audits end-to-end on the platform.

  • Hands-on experience with AWS security tools, especially GuardDuty and Inspector, including triaging findings and proposing remediation priorities.

  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work, with concrete examples of what you have built or automated.

  • Strong bias toward removing unnecessary process and proposing lighter alternatives.

  • Strong written communication in English, with the ability to explain security topics clearly to engineers, executives, and customers.

  • Pragmatic mindset focused on controls that work in practice rather than only on paper.

  • Experience supporting HIPAA or HITRUST programs and mapping requirements across frameworks, preferred.

  • Familiarity with cloud environments, especially AWS, and common SaaS administration tools such as Google Workspace, Slack, and identity providers, preferred.

  • Exposure to security questionnaire platforms and trust center tooling, preferred.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Information Security Analyst
Information Security Analyst

Didomi • Paris

Sur place
EUR 65 000 - 90 000
ISO 27001 & GRC Security Analyst
ISO 27001 & GRC Security Analyst

RemoteLeads • France

Sur place
EUR 60 000 - 90 000
Senior Security Analyst - GRC
Senior Security Analyst - GRC

Dormont Manufacturing Co • Massy

Sur place
EUR 45 000 - 65 000
GRC Engineer (Governance, Risk, and Compliance)
GRC Engineer (Governance, Risk, and Compliance)

Revevol • Paris

Sur place
EUR 90 000 - 120 000
GRC Manager
GRC Manager

Welcome to the Jungle France • Paris

Sur place
EUR 55 000 - 75 000
Senior Security Engineer
Senior Security Engineer

Xpandium Coberon Ltd • Eu

Hybride
EUR 70 000 - 90 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Rennes

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Dijon

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Anglet

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Grenoble

Hybride
EUR 90 000 - 120 000
Flexible remote work