Security Engineer - GRC

Alan

Nice

Sur place

EUR 110 000 - 170 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Flexible remote work

Résumé du poste

Alan is seeking a governance, risk and compliance leader who will own and operate the ISO 27001 ISMS, lead audits, and translate complex regulatory requirements into concrete security controls. You will drive risk management practices with cross-functional collaboration across Legal, DPO, Risk, Engineering and Product teams.

The role offers board visibility, exposure to multi-country regulatory landscapes, and autonomy to shape Alan’s security culture while aligning with business growth and

Qualifications

  • Proven ability to translate regulatory requirements into technical controls.
  • Experience in implementing or overseeing ISO 27001 ISMS or similar frameworks.
  • Strong communication to board-level audiences.

Responsabilités

  • Own and operate ISO 27001 ISMS including scope, SoA, internal audits, and mgmt reviews.
  • Lead regulatory and privacy compliance actions across DORA, HDS, RGPD, and other regimes.
  • Run risk management as an ongoing program using risk cartography and governance forums.
  • Embed security requirements in foundational architecture with engineering teams.
  • Manage third-party risk and vendor security assessments with contracts and DPAs.

Connaissances

Risk management
Regulatory understanding
Security governance
Stakeholder alignment

Outils

GRC tooling

Description du poste

Your mission: Governance, risk & compliance
  • Own and operate the ISO 27001 ISMS – scope definition, Statement of Applicability, internal audit programme, and management review. Lead at least one full certification or recertification cycle.
  • Be the security expert on regulatory and privacy matters – translate DORA, HDS, RGPD, PGSSI‑S and other regulatory requirements into controls, flag implementation gaps, and provide technical substance for regulatory negotiations.
  • Run risk as an ongoing programme with the broader risk function – create risk cartography using EBIOS RM, facilitate workshops, produce treatment plans and apply a security lens to non‑security risk forums.
  • Own the controls framework yet distribute ownership – set standards, track coverage, and work with Infrastructure, Platform and Engineering to embed security requirements in foundational building blocks.
  • Run audit cycles with rigor – manage the security audit programme, coordinate with certification bodies and Internal Audit to align scopes, avoid duplication, and present coherent control effectiveness to the board.
  • Manage third‑party risk – run vendor security assessments and define contractual security requirements (security annexes, DPAs).
  • Bring the health sector context – understand ANS framework, CERT Santé requirements and translate regulatory needs into technical actions.
  • Own incident governance and support DORA reporting – classify and escape ICT incidents, oversee BCP/DRP governance, and provide security substance for incident reports.
What You’ll Build and Who You’ll Work With
  • Compliance Framework – ISO 27001, DORA, HDS, NIS2; design a coherent governance backbone that scales with member growth.
  • Automated Audit & Evidence Engine – replace manual evidence collection with scripted pipelines directly integrated into engineering systems.
  • Risk Cartography – operationalize risk as a signal that feeds business and engineering decisions, centred on EBIOS RM.
Why This Role Is Special
  • Direct Impact – own the trust foundation that lets Alan handle health data for over a million members in highly regulated markets.
  • Complex Problems – manage four regulators across four countries, sensitive health data, and a shifting regulatory landscape (DORA, NIS2, AI Act).
  • Ownership & Growth – board and executive exposure, real influence on company‑wide risk decisions, and autonomy to shape Alan’s security culture across 800+ people.
Technical Enablement
  • Automate compliance work – script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines; use Python or similar to reduce manual audit effort.
  • Configure and own GRC tooling – administer platforms like CISO Assistant, ServiceNow GRC, or Archer; design workflows, build dashboards, and make them useful for data‑feeding teams.
  • Speak cloud governance fluently – understand shared responsibility in HDS‑qualified environments, CSPM tool coverage, and policy‑as‑code (OPA, SCP).
  • Read architecture well enough to challenge it – review proposed architectures, identify control gaps in identity, network segmentation, encryption, or logging, and give credible pushback.
  • Interpret vulnerability data and drive prioritisation – analyze scan outputs, collaborate with engineering to prioritise remediation by business impact, and track resolution KPIs over time.
Qualifications, Mindset, and Soft Skills
  • Translate risk into business language – brief board or audit committees and distinguish findings requiring board calls from quarterly reports.
  • Influence without authority – align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers.
  • Manage programmes with audit‑grade rigor – run structured, traceable roadmaps; own commitments, escalations, and due dates.
  • Build a genuine security culture – launch awareness programmes that resonate, fostering proportionate risk ownership across the company.
  • Think in principles when frameworks shift – reason from first principles and adapt to regulatory changes like DORA, NIS2, and the AI Act.

Location: You must be legally eligible to work from France.

Remote work: We offer flexible remote work, but value in‑person collaboration.

Everyone, no matter how underrepresented, should feel free to apply.

Perks & Benefits

Alan provides a stimulating environment and perks to keep employees happy, efficient, and focused on high‑quality teamwork.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Engineer - GRC
Security Engineer - GRC

Alan • Dijon

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Rennes

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Lille

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Limoges

Hybride
EUR 110 000 - 150 000
Flexible remote work
In-person collaboration
Security Engineer - GRC
Security Engineer - GRC

Alan • Montpellier

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Grenoble

Hybride
EUR 90 000 - 120 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Anglet

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Metz

Hybride
EUR 90 000 - 130 000
Remote work flexibility
In-person collaboration
Board exposure
Security Engineer - GRC
Security Engineer - GRC

Alan • La Rochelle-Normande

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Saint-Pierre-d'Eyraud

Hybride
EUR 120 000 - 180 000
Remote work flexibility
Competitive compensation