Security Engineer - GRC

Alan

Anglet

Sur place

EUR 90 000 - 130 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Alan is seeking a senior Governance, Risk & Compliance leader to own the ISO 27001 ISMS, define its scope, lead internal audits, and manage certification cycles. You will act as the security expert on regulatory matters and translate requirements into concrete controls.

You will run risk programmes using EBIOS RM, embed security across Infrastructure, Platform and Engineering, oversee vendor risk, incident governance, DORA reporting, and liaise with the board to shape Alan’s security culture for

Qualifications

  • Experience implementing ISO 27001 ISMS and internal audit programmes.
  • Knowledge of regulatory frameworks: DORA, HDS, RGPD, PGSSI-S.
  • Ability to run risk programmes using EBIOS RM.
  • Ability to coordinate with Infrastructure, Platform and Engineering to embed security requirements.

Responsabilités

  • Own and operate the ISO 27001 ISMS, scope definition, SoA, audit programme, and mgmt review.
  • Lead risk management with EBIOS RM and facilitate workshops.
  • Run audit cycles and coordinate with certification bodies and Internal Audit.
  • Manage third-party risk including vendor security assessments and DPAs.
  • Translate regulatory needs into technical actions and controls.

Connaissances

Regulatory understanding
Risk management
Security governance

Outils

ISO 27001 ISMS
EBIOS RM

Description du poste

Your mission: Governance, risk & compliance
  • Own and operate the ISO 27001 ISMS – scope definition, Statement of Applicability, internal audit programme, and management review. Lead at least one full certification or recertification cycle.
  • Be the security expert on regulatory and privacy matters – translate DORA, HDS, RGPD, PGSSI‑S and other regulatory requirements into controls, flag implementation gaps, and provide technical substance for regulatory negotiations.
  • Run risk as an ongoing programme with the broader risk function – create risk cartography using EBIOS RM, facilitate workshops, produce treatment plans and apply a security lens to non‑security risk forums.
  • Own the controls framework yet distribute ownership – set standards, track coverage, and work with Infrastructure, Platform and Engineering to embed security requirements in foundational building blocks.
  • Run audit cycles with rigor – manage the security audit programme, coordinate with certification bodies and Internal Audit to align scopes, avoid duplication, and present coherent control effectiveness to the board.
  • Manage third‑party risk – run vendor security assessments and define contractual security requirements (security annexes, DPAs).
  • Bring the health sector context – understand ANS framework, CERT Santé requirements and translate regulatory needs into technical actions.
  • Own incident governance and support DORA reporting – classify and escape ICT incidents, oversee BCP/DRP governance, and provide security substance for incident reports.
What You’ll Build and Who You’ll Work With
  • Compliance Framework – ISO 27001, DORA, HDS, NIS2; design a coherent governance backbone that scales with member growth.
  • Automated Audit & Evidence Engine – replace manual evidence collection with scripted pipelines directly integrated into engineering systems.
  • Risk Cartography – operationalize risk as a signal that feeds business and engineering decisions, centred on EBIOS RM.
Why This Role Is Special
  • Direct Impact – own the trust foundation that lets Alan handle health data for over a million members in highly regulated markets.
  • Complex Problems – manage four regulators across four countries, sensitive health data, and a shifting regulatory landscape (DORA, NIS2, AI Act).
  • Ownership & Growth – board and executive exposure, real influence on company‑wide risk decisions, and autonomy to shape Alan’s security culture across 800+ people.
Technical Enablement
  • Automate compliance work – script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines; use Python or similar to reduce manual audit effort.
  • Configure and own GRC tooling – administer platforms like CISO Assistant, ServiceNow GRC, or Archer; design workflows, build dashboards, and make them useful for data‑feeding teams.
  • Speak cloud governance fluently – understand shared responsibility in HDS‑qualified environments, CSPM tool coverage, and policy‑as‑code (OPA, SCP).
  • Read architecture well enough to challenge it – review proposed architectures, identify control gaps in identity, network segmentation, encryption, or logging, and give credible pushback.
  • Interpret vulnerability data and drive prioritisation – analyze scan outputs, collaborate with engineering to prioritise remediation by business impact, and track resolution KPIs over time.
Qualifications, Mindset, and Soft Skills
  • Translate risk into business language – brief board or audit committees and distinguish findings requiring board calls from quarterly reports.
  • Influence without authority – align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers.
  • Manage programmes with audit‑grade rigor – run structured, traceable roadmaps; own commitments, escalations, and due dates.
  • Build a genuine security culture – launch awareness programmes that resonate, fostering proportionate risk ownership across the company.
  • Think in principles when frameworks shift – reason from first principles and adapt to regulatory changes like DORA, NIS2, and the AI Act.

Location: You must be legally eligible to work from France.

Remote work: We offer flexible remote work, but value in‑person collaboration.

Everyone, no matter how underrepresented, should feel free to apply.

Perks & Benefits

Alan provides a stimulating environment and perks to keep employees happy, efficient, and focused on high‑quality teamwork.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Engineer - GRC
Security Engineer - GRC

Alan • Dijon

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Rennes

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Limoges

Hybride
EUR 110 000 - 150 000
Flexible remote work
In-person collaboration
Security Engineer - GRC
Security Engineer - GRC

Alan • Nice

Hybride
EUR 110 000 - 170 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Lille

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Grenoble

Hybride
EUR 90 000 - 120 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Montpellier

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Strasbourg

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • La Rochelle-Normande

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Bordeaux

Hybride
EUR 120 000 - 180 000