Security Engineer - GRC

Alan

Grenoble

Sur place

EUR 90 000 - 120 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Flexible remote work

Résumé du poste

Alan seeks a Governance, Risk & Compliance leader to own ISO 27001 ISMS, translate regulatory requirements into concrete controls, and partner with Engineering to embed security in our platforms.

You will run risk programs, manage audits and vendor assessments, and provide security posture updates to the board across multiple markets, while collaborating with Legal, Risk, and Product teams.

Qualifications

  • Experience translating regulatory requirements into technical controls.
  • Ability to lead auditable risk programs with governance rigor.
  • Strong stakeholder management across Legal, Risk and Engineering.
  • Proven track record in ISO 27001 and GRC tooling.
  • Excellent communication to board and executives.

Responsabilités

  • Own ISO 27001 ISMS scope, SoA, audits, and management reviews.
  • Lead regulatory/privacy program alignment (DORA, RGPD, etc.).
  • Build risk cartography using EBIOS RM and manage risk workshops.
  • Embed security requirements in infrastructure and product builds.
  • Oversee third-party security assessments and vendor risk.
  • Manage incident governance and DORA reporting.
  • Coordinate with certification bodies and internal audit.

Connaissances

ISO 27001 ISMS
Regulatory translation
Risk management
Audit management
Vendor risk
Incident governance
Security architecture review

Outils

Python
ServiceNow GRC
Archer
CSPM
OPA

Description du poste

Your mission: Governance, risk & compliance
  • Own and operate the ISO 27001 ISMS – scope definition, Statement of Applicability, internal audit programme, and management review. Lead at least one full certification or recertification cycle.
  • Be the security expert on regulatory and privacy matters – translate DORA, HDS, RGPD, PGSSI‑S and other regulatory requirements into controls, flag implementation gaps, and provide technical substance for regulatory negotiations.
  • Run risk as an ongoing programme with the broader risk function – create risk cartography using EBIOS RM, facilitate workshops, produce treatment plans and apply a security lens to non‑security risk forums.
  • Own the controls framework yet distribute ownership – set standards, track coverage, and work with Infrastructure, Platform and Engineering to embed security requirements in foundational building blocks.
  • Run audit cycles with rigor – manage the security audit programme, coordinate with certification bodies and Internal Audit to align scopes, avoid duplication, and present coherent control effectiveness to the board.
  • Manage third‑party risk – run vendor security assessments and define contractual security requirements (security annexes, DPAs).
  • Bring the health sector context – understand ANS framework, CERT Santé requirements and translate regulatory needs into technical actions.
  • Own incident governance and support DORA reporting – classify and escape ICT incidents, oversee BCP/DRP governance, and provide security substance for incident reports.
What You’ll Build and Who You’ll Work With
  • Compliance Framework – ISO 27001, DORA, HDS, NIS2; design a coherent governance backbone that scales with member growth.
  • Automated Audit & Evidence Engine – replace manual evidence collection with scripted pipelines directly integrated into engineering systems.
  • Risk Cartography – operationalize risk as a signal that feeds business and engineering decisions, centred on EBIOS RM.
Why This Role Is Special
  • Direct Impact – own the trust foundation that lets Alan handle health data for over a million members in highly regulated markets.
  • Complex Problems – manage four regulators across four countries, sensitive health data, and a shifting regulatory landscape (DORA, NIS2, AI Act).
  • Ownership & Growth – board and executive exposure, real influence on company‑wide risk decisions, and autonomy to shape Alan’s security culture across 800+ people.
Technical Enablement
  • Automate compliance work – script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines; use Python or similar to reduce manual audit effort.
  • Configure and own GRC tooling – administer platforms like CISO Assistant, ServiceNow GRC, or Archer; design workflows, build dashboards, and make them useful for data‑feeding teams.
  • Speak cloud governance fluently – understand shared responsibility in HDS‑qualified environments, CSPM tool coverage, and policy‑as‑code (OPA, SCP).
  • Read architecture well enough to challenge it – review proposed architectures, identify control gaps in identity, network segmentation, encryption, or logging, and give credible pushback.
  • Interpret vulnerability data and drive prioritisation – analyze scan outputs, collaborate with engineering to prioritise remediation by business impact, and track resolution KPIs over time.
Qualifications, Mindset, and Soft Skills
  • Translate risk into business language – brief board or audit committees and distinguish findings requiring board calls from quarterly reports.
  • Influence without authority – align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers.
  • Manage programmes with audit‑grade rigor – run structured, traceable roadmaps; own commitments, escalations, and due dates.
  • Build a genuine security culture – launch awareness programmes that resonate, fostering proportionate risk ownership across the company.
  • Think in principles when frameworks shift – reason from first principles and adapt to regulatory changes like DORA, NIS2, and the AI Act.

Location: You must be legally eligible to work from France.

Remote work: We offer flexible remote work, but value in‑person collaboration.

Everyone, no matter how underrepresented, should feel free to apply.

Perks & Benefits

Alan provides a stimulating environment and perks to keep employees happy, efficient, and focused on high‑quality teamwork.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Engineer - GRC
Security Engineer - GRC

Alan • Nice

Hybride
EUR 110 000 - 170 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Dijon

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Lille

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Rennes

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Montpellier

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Limoges

Hybride
EUR 110 000 - 150 000
Flexible remote work
In-person collaboration
Security Engineer - GRC
Security Engineer - GRC

Alan • Anglet

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Toulouse

Hybride
EUR 100 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Bordeaux

Hybride
EUR 120 000 - 180 000
Security Engineer - GRC
Security Engineer - GRC

Alan • La Rochelle-Normande

Hybride
EUR 90 000 - 140 000