Information Security & Compliance Manager

Oticon Medical

Nice

Sur place

EUR 110 000 - 140 000

Plein temps

Il y a 10 jours
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Résumé du poste

Oticon Medical in Vallauris, France, develops bone-anchored hearing systems within an international group. We seek an Information Security & Compliance Manager to define, deploy, and continuously improve measures that ensure the security, availability, integrity, and confidentiality of health data.

You will drive the organization’s cybersecurity strategy, risk management framework, and compliance roadmap, aligning ISMS with ISO 27001, GDPR, and health data hosting standards (HDS) where

Qualifications

  • Master's degree in Engineering, Cybersecurity, or Information Systems Security.
  • 5-10 years of experience as a CISO or similar information security leadership role.
  • Proven hands-on experience leading an ISO 27001 ISMS, including end-to-end project management.
  • Strong command of GDPR, ISO 27001, HDS, EBIOS RM.
  • Solid technical expertise: secure architecture, IAM, SOC/SIEM, PKI, vulnerability management.
  • Strong executive-level communication and leadership skills.
  • Knowledge of AI governance and responsible AI security principles.

Responsabilités

  • Define, maintain, and deploy the Information Systems Security Policy and the ISO 27001-based Information Security Management System.
  • Ensure alignment with GDPR, ISO 27001, HDS, and healthcare data protection requirements.
  • Lead cybersecurity risk management, including asset and risk mapping, EBIOS RM analysis, and risk treatment plans.
  • Report regularly to senior management on cybersecurity risks, compliance status, key indicators, dashboards, and roadmap progress.
  • Define and oversee secure architecture, infrastructure, identity and access management, monitoring tools, encryption, and certificate management.
  • Supervise backup, business continuity, disaster recovery, incident response, and cyber crisis exercises, including ransomware and data exfiltration scenarios.
  • Prepare and support audits, penetration tests, vulnerability scans, remediation plans, and threat monitoring activities.
  • Deploy cybersecurity awareness initiatives and manage security requirements for suppliers and subcontractors, including contracts and audits.

Connaissances

CISO leadership
ISO 27001
GDPR compliance
Information security
IAM management
SOC/SIEM
Vulnerability management
Executive communication
AI governance

Formation

Master's degree in Engineering, Cybersecurity, or Information Systems Security

Outils

SOC/SIEM tools
PKI tooling
Vulnerability scanning tools

Description du poste

Would you like to contribute to strengthening the security, resilience, and compliance of a healthcare information system?

At Oticon/ITSA Medical, we develop, manufacture, and market bone-anchored hearing systems within an international organization. The group has a presence in several countries, with its main offices located in France and Sweden. At our Vallauris site (Sophia Antipolis), in the south of France, we specialize in the production of active implantable Class III medical devices and manage the worldwide distribution of the company's complete product portfolio. The site also hosts an R&D team and the French sales organization.

Although the position is based in France, its scope extends across all geographies where the group operates.

As part of the development and security enhancement of the organization’s information system, and in the context of a newly created position, we are looking for an Information Security & Compliance Manager to define, deploy, manage, and continuously improve the technical, organizational, and human measures required to ensure the security, availability, integrity, and confidentiality of information, particularly personal health data.

The role will support full alignment of the information system with ISO/IEC 27001, GDPR requirements, and health data hosting standards, including HDS certification where applicable.

Reporting to senior management, your main responsibility will be to lead the global organization’s cybersecurity strategy, risk management framework, compliance roadmap, and continuous improvement of the Information Security Management System.

Main Tasks
  • Define, maintain, and deploy the Information Systems Security Policy and the ISO 27001-based Information Security Management System.
  • Ensure alignment with GDPR, ISO 27001, HDS, and healthcare data protection requirements.
  • Lead cybersecurity risk management, including asset and risk mapping, EBIOS RM analysis, Statement of Applicability, and risk treatment plans.
  • Report regularly to senior management on cybersecurity risks, compliance status, key indicators, dashboards, and roadmap progress.
  • Define and oversee secure architecture, infrastructure, identity and access management, monitoring tools, encryption, and certificate management.
  • Supervise backup, business continuity, disaster recovery, incident response, and cyber crisis exercises, including ransomware and data exfiltration scenarios.
  • Prepare and support audits, penetration tests, vulnerability scans, remediation plans, and threat monitoring activities.
  • Deploy cybersecurity awareness initiatives and manage security requirements for suppliers and subcontractors, including contracts and audits.

Work closely with the DPO, IT, medical leadership, operations, and key stakeholders.

Required Skills
  • Master's degree (Bac+5) in Engineering, Cybersecurity, or Information Systems Security, or equivalent
  • 5-10 years of experience as a CISO or in a similar information security leadership role
  • Proven hands-on experience leading an ISO 27001 Information Security Management System (ISMS), including full end-to-end project management responsibility
  • Strong command of relevant frameworks and standards: GDPR, ISO 27001, HDS, EBIOS RM
  • Solid technical expertise: secure architecture, IAM management, SOC/SIEM, PKI, vulnerability management and cyber crisis management
  • Strong soft skills: leadership, executive-level communication, and the ability to translate complex technical topics for senior management/Executive Committee (COMEX)
  • Knowledge of AI, generative AI security risks, AI governance, and responsible AI principles, with the ability to support secure and compliant adoption of AI solutions.
Desired Skills
  • ISO 27001 Lead Implementer and/or Lead Auditor certification.
  • CISSP, CISM, CEH, EBIOS RM, or equivalent cybersecurity certification.
  • Experience in healthcare, medical technologies, regulated environments, or health data protection.
  • Knowledge of HDS requirements and healthcare cybersecurity constraints.
  • Experience coordinating suppliers, audits, security committees, or cyber crisis exercises.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Global Information Security & Compliance Manager
Global Information Security & Compliance Manager

Demant Polska • France

À distance
EUR 110 000 - 150 000
Global Information Security & Compliance Leader
Global Information Security & Compliance Leader

Oticon Medical • Nice

Sur place
EUR 110 000 - 140 000
NPI & CI Engineer (New Product Introduction & Continuous Improvement)
NPI & CI Engineer (New Product Introduction & Continuous Improvement)

Demant Polska • Valbonne, Vallauris

Sur place
EUR 45 000 - 65 000
Responsable IT Omnicanal H/F (Business Technology Partner DHH)
Responsable IT Omnicanal H/F (Business Technology Partner DHH)

MSD France • Paris

Hybride
EUR 90 000 - 120 000
Responsable IT Omnicanal H/F (Business Technology Partner DHH)
Responsable IT Omnicanal H/F (Business Technology Partner DHH)

Merck Gruppe - MSD Sharp & Dohme • Paris

Hybride
EUR 90 000 - 120 000
RESPONSABLE INFRASTRUCTURE ET SECURITE - H/F
RESPONSABLE INFRASTRUCTURE ET SECURITE - H/F

Carte Blanche Partenaires • Paris

Sur place
EUR 65 000 - 70 000
Mutuelle prise en charge à 100%
Chèques cadeaux Noël
Tickets CESU
+1
Senior Security Analyst - GRC
Senior Security Analyst - GRC

Ivalua • Massy

Sur place
EUR 45 000 - 65 000
Security Engineer - GRC
Security Engineer - GRC

United States Digital Space LLC • France

Hybride
EUR 95 000 - 135 000
Senior IT Project Manager - OT Security & Secure File Transfer in Pharma
Senior IT Project Manager - OT Security & Secure File Transfer in Pharma

Jobgether • France

Sur place
EUR 85 000 - 120 000
Professional development budget
Visa/permits support and international
Global teams collaboration
+1
Senior RA/QA Manager - Paris
Senior RA/QA Manager - Paris

Dental Monitoring • Paris

Hybride
EUR 120 000 - 165 000
Hybrid working
Office in Paris