Security Engineer - GRC

Alan

Limoges

Sur place

EUR 110 000 - 150 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Flexible remote work
In-person collaboration

Résumé du poste

Alan is seeking a senior governance, risk & compliance leader to own the ISO 27001 ISMS, translate regulatory demands into controls, and drive risk management across the organization. You will lead audits, vendor risk, and incident governance while shaping security culture and architecture decisions.

You will collaborate with Legal, DPO, Risk, and Engineering across multiple countries, with a flexible remote option and valued in-person collaboration.

Qualifications

  • Translate risk into business language and brief the board on security posture.
  • Influence Legal, DPO, Risk, Engineering and Product without blockers.
  • Manage programmes with audit-grade rigor and defined roadmaps.
  • Build a genuine security culture with awareness programs across the company.
  • Think from first principles to adapt to regulatory shifts (DORA, NIS2, AI Act).

Responsabilités

  • Own and operate ISO 27001 ISMS including scope, SoA, internal audits, and management reviews.
  • Lead regulatory and privacy controls and translate requirements into actionable actions.
  • Run risk as a programme; create cartography using EBIOS RM and influence business decisions.
  • Own the controls framework and embed security in architecture and platforms.
  • Coordinate security audits with bodies and Internal Audit; report control effectiveness to the board.
  • Manage third-party risk; conduct vendor assessments and define security annexes/DPAs.
  • Support incident governance, DORA reporting, and BCP/DRP oversight.
  • Read architectures to identify control gaps and push for remediation prioritised by impact.

Connaissances

Governance & risk management
Regulatory compliance
Stakeholder influence
Security culture building
Cloud governance understanding
Board-level communication

Outils

CISO Assistant
ServiceNow GRC
Archer
Python scripting

Description du poste

Your mission: Governance, risk & compliance
  • Own and operate the ISO 27001 ISMS – scope definition, Statement of Applicability, internal audit programme, and management review. Lead at least one full certification or recertification cycle.
  • Be the security expert on regulatory and privacy matters – translate DORA, HDS, RGPD, PGSSI‑S and other regulatory requirements into controls, flag implementation gaps, and provide technical substance for regulatory negotiations.
  • Run risk as an ongoing programme with the broader risk function – create risk cartography using EBIOS RM, facilitate workshops, produce treatment plans and apply a security lens to non‑security risk forums.
  • Own the controls framework yet distribute ownership – set standards, track coverage, and work with Infrastructure, Platform and Engineering to embed security requirements in foundational building blocks.
  • Run audit cycles with rigor – manage the security audit programme, coordinate with certification bodies and Internal Audit to align scopes, avoid duplication, and present coherent control effectiveness to the board.
  • Manage third‑party risk – run vendor security assessments and define contractual security requirements (security annexes, DPAs).
  • Bring the health sector context – understand ANS framework, CERT Santé requirements and translate regulatory needs into technical actions.
  • Own incident governance and support DORA reporting – classify and escape ICT incidents, oversee BCP/DRP governance, and provide security substance for incident reports.
What You’ll Build and Who You’ll Work With
  • Compliance Framework – ISO 27001, DORA, HDS, NIS2; design a coherent governance backbone that scales with member growth.
  • Automated Audit & Evidence Engine – replace manual evidence collection with scripted pipelines directly integrated into engineering systems.
  • Risk Cartography – operationalize risk as a signal that feeds business and engineering decisions, centred on EBIOS RM.
Why This Role Is Special
  • Direct Impact – own the trust foundation that lets Alan handle health data for over a million members in highly regulated markets.
  • Complex Problems – manage four regulators across four countries, sensitive health data, and a shifting regulatory landscape (DORA, NIS2, AI Act).
  • Ownership & Growth – board and executive exposure, real influence on company‑wide risk decisions, and autonomy to shape Alan’s security culture across 800+ people.
Technical Enablement
  • Automate compliance work – script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines; use Python or similar to reduce manual audit effort.
  • Configure and own GRC tooling – administer platforms like CISO Assistant, ServiceNow GRC, or Archer; design workflows, build dashboards, and make them useful for data‑feeding teams.
  • Speak cloud governance fluently – understand shared responsibility in HDS‑qualified environments, CSPM tool coverage, and policy‑as‑code (OPA, SCP).
  • Read architecture well enough to challenge it – review proposed architectures, identify control gaps in identity, network segmentation, encryption, or logging, and give credible pushback.
  • Interpret vulnerability data and drive prioritisation – analyze scan outputs, collaborate with engineering to prioritise remediation by business impact, and track resolution KPIs over time.
Qualifications, Mindset, and Soft Skills
  • Translate risk into business language – brief board or audit committees and distinguish findings requiring board calls from quarterly reports.
  • Influence without authority – align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers.
  • Manage programmes with audit‑grade rigor – run structured, traceable roadmaps; own commitments, escalations, and due dates.
  • Build a genuine security culture – launch awareness programmes that resonate, fostering proportionate risk ownership across the company.
  • Think in principles when frameworks shift – reason from first principles and adapt to regulatory changes like DORA, NIS2, and the AI Act.

Location: You must be legally eligible to work from France.

Remote work: We offer flexible remote work, but value in‑person collaboration.

Everyone, no matter how underrepresented, should feel free to apply.

Perks & Benefits

Alan provides a stimulating environment and perks to keep employees happy, efficient, and focused on high‑quality teamwork.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Engineer - GRC
Security Engineer - GRC

Alan • Montpellier

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Nice

Hybride
EUR 110 000 - 170 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Anglet

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Dijon

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Rennes

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Grenoble

Hybride
EUR 90 000 - 120 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Lille

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • La Rochelle-Normande

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Bordeaux

Hybride
EUR 120 000 - 180 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Marseille

Hybride
EUR 110 000 - 145 000
Remote work flexibility