Information Security Analyst

Didomi

Paris

Sur place

EUR 65 000 - 90 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Didomi is seeking an Information Security Analyst to support ISO 27001 program and audit readiness. You will handle recurring compliance work, evidence collection, access reviews, and vendor assessments, while driving automation and AI-enabled improvements.

You will report to the Security Manager and collaborate across the Security & IT team to strengthen identity, access management, and data handling practices.

Qualifications

  • 3+ years in a GRC, compliance, or information security analyst role.
  • Solid knowledge of ISO 27001, Annex A controls, and audit processes.
  • Hands-on with vulnerability management tools and access governance.
  • Experience with Vanta and end-to-end ISO 27001 audits.
  • Experience with AWS security services: GuardDuty, Inspector, and remediation.
  • Demonstrated use of AI tooling to accelerate compliance tasks.
  • Bias toward simplifying and removing ineffective processes.
  • Strong written English communication for engineers, execs, and customers.
  • Pragmatic mindset; prioritizes usable controls over paperwork.

Responsabilités

  • Maintain and improve ISO 27001 management system with evidence.
  • Support internal, surveillance, and recertification audits including unified audit.
  • Track corrective actions, nonconformities, and improvements.
  • Carry out recurring security activities: vulnerability scans, access reviews, risk assessments.
  • Triage findings from AWS tools and define remediation priorities.
  • Run periodic access reviews across core systems and surface findings.
  • Review new tools/vendors for security risk before adoption.
  • Help harden workflows, with focus on identity, MFA, SSO, and data handling.
  • Support security questionnaires, RFPs, and customer due diligence.

Connaissances

GRC experience
ISO 27001
Vulnerability mgmt
Access governance
AI tooling for automation
English written comms
Strong process improvement

Formation

Bachelor's in CS/IS/related

Outils

Vanta
AWS GuardDuty
AWS Inspector
AWS Security Hub
Google Workspace
Slack
JAMF
GitLab
GitHub

Description du poste

We are looking for an Information Security Analyst to join our Security & IT team and become the operational backbone of our ISO 27001 program. You will support the day‑to‑day work that keeps Didomi audit‑ready year‑round and run recurring security activities across the company.

This role is roughly 80% recurring compliance work: evidence collection, audit preparation, access reviews, vendor reviews, and security questionnaire responses. Leverage is the whole game. We want someone who reaches for automation and AI tooling as a default and who actively pushes back on process that no longer earns its keep, rather than someone who accepts that compliance work has to be slow or manual.

This role reports to the Security Manager.

ISO 27001 program and audit readiness
  • Help maintain and improve our ISO 27001 management system, ensuring controls remain effective, documented, and continuously evidenced
  • Contribute to internal audits, surveillance audits, and recertification cycles, including the upcoming unified audit covering Didomi and recently acquired business units
  • Track corrective actions, nonconformities, and continuous improvement initiatives, supporting the security team in driving them to closure
Security operations and recurring activities
  • Carry out recurring activities on the security calendar in support of the security team, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles
  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources, then work with the Security Manager to define remediation priorities and follow them through to closure
  • Run periodic access reviews across critical systems (Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications), surfacing findings to the Security Manager and helping ensure they are remediated
Cross‑functional security support
  • Contribute to the security team's reviews of new tools, vendors, and SaaS applications for security and compliance risks before adoption
  • Help the security team assess and harden internal workflows, with a particular focus on identity, access management, MFA, SSO, and data handling
  • Support the security team on security questionnaires, RFPs, and customer due diligence requests
  • Support the security team on broader initiatives such as AI governance, SaaS governance, and integration of acquired entities into the ISO scope
Preferred skills & experience
  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally within a SaaS or technology company
  • Solid working knowledge of ISO 27001, including Annex A controls, the audit process, and how to operationalize the standard rather than treat it as paperwork
  • Hands‑on experience with vulnerability management tools and access governance processes
  • Hands‑on experience with Vanta, including running ISO 27001 (or comparable) audits end‑to‑end on the platform
  • Hands‑on experience with the AWS security suite, in particular GuardDuty and Inspector, including triaging findings and proposing remediation priorities
  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work. You should be able to walk us through concrete examples of what you have built or automated
  • A strong bias toward removing process. You actively challenge controls, paperwork, and workflows that no longer earn their keep, and you propose lighter alternatives
  • Strong written communication in English. You can explain security topics clearly to engineers, executives, and customers alike
  • A pragmatic mindset: you favor controls that work in practice over controls that only look good on paper
Nice to have
  • Experience supporting HIPAA or HITRUST programs, and comfort mapping requirements across frameworks
  • Familiarity with cloud environments (AWS in particular) and with common SaaS administration (Google Workspace, Slack, identity providers)
  • Exposure to security questionnaire platforms and trust center tooling
Tools you’ll work with on a regular basis
  • Compliance and GRC: Vanta
  • Cloud and security monitoring: AWS, AWS GuardDuty, AWS Inspector, AWS Security Hub
  • Identity and access: Google Workspace, SSO and MFA providers
  • Endpoint and device management: JAMF
  • Code and engineering: GitLab, GitHub
  • Collaboration and documentation: Slack, Notion, Google Workspace
  • SaaS governance and vendor review: internal review workflows and questionnaire tooling
Recruitment process
  • HR Screen with our Talent Acquisition Expert (15 min, video) – Motivation, fit, logistics, salary
  • Hiring Manager Interview with our Security & IT Manager (45 min, video) – ISO 27001 depth, mindset, ownership style
  • Case Study Presentation with our Security & IT Manager & CTO (60 min, video)
  • Final Interview with our CTO (optional) (30 min, video) – Strategic alignment

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Information Security Analyst
Information Security Analyst

RemoteLeads • France

Sur place
EUR 60 000 - 90 000
GRC Security Engineer
GRC Security Engineer

DataDome • France

Hybride
EUR 60 000 - 80 000
Remote work stipend
Health benefits
Annual leisure activity allowance
+3
GRC Security Engineer
GRC Security Engineer

DataDome • Paris

Hybride
EUR 75 000 - 110 000
Remote/hybrid/in-office options
Office near Opera Garnier
Kenko health benefits
+2
ISO 27001 Compliance & Automation Analyst
ISO 27001 Compliance & Automation Analyst

Didomi • Paris

Sur place
EUR 65 000 - 90 000
Senior Security Engineer
Senior Security Engineer

DataDome • France

Hybride
EUR 70 000 - 90 000
500€ stipend for workspace setup
Generous health benefits
Annual allowance for leisure activities
+2
CDI - Chief of Staff to CTO - H/F
CDI - Chief of Staff to CTO - H/F

CHARGE GURU • Paris

Sur place
EUR 80 000 - 120 000
Senior Security Analyst - GRC
Senior Security Analyst - GRC

Ivalua • France

Hybride
EUR 60 000 - 80 000
Hybrid working model
Weekly lunches
Training and career development programmes
+1
GRC Manager
GRC Manager

Welcome to the Jungle France • Paris

Sur place
EUR 55 000 - 75 000
GRC Engineer (Governance, Risk, and Compliance)
GRC Engineer (Governance, Risk, and Compliance)

Revevol • Paris

Sur place
EUR 90 000 - 120 000
Associate Security Engineer
Associate Security Engineer

Spendesk • Paris

Sur place
EUR 40 000 - 70 000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care for wellbeing
+2