GRC Manager

Welcome to the Jungle France

Paris

Sur place

EUR 55 000 - 75 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

A growing technology company in Paris is seeking a Security Governance Manager to lead Governance, Risk & Compliance initiatives. The role involves driving SOC 2 certification, performing risk assessments, and ensuring compliance with GDPR and other regulations. Ideal candidates will have 4 to 7 years of experience in GRC or information security, strong knowledge of SOC 2 and regulatory frameworks, and an action-oriented mindset. Proficiency in English is essential, and knowledge of French is an asset.

Qualifications

  • 4 to 7 years of experience in GRC, information security, or IT audit, ideally in a startup/scaleup.
  • Experience with SOC 2 Type II and other security certifications (ISO 27001, etc.).
  • Knowledge of GDPR and data protection best practices.

Responsabilités

  • Drive SOC2 certification program and coordinate auditor management.
  • Conduct risk assessments and manage the risk register.
  • Execute governance activities like access reviews and internal audits.

Connaissances

Governance Risk Compliance
SOC 2 Type II
GDPR Knowledge
Action-oriented
Excellent English

Formation

4 to 7 years of experience in GRC or information security

Outils

Okta
AWS
Datadog

Description du poste

We're looking for a Security Governance Manager to lead Governance, Risk & Compliance across Welcome to the Jungle. You'll drive our SOC 2 certification, run day-to-day security governance (access reviews, audits, controls, vendor reviews, security questionnaires), and navigate regulatory requirements (GDPR, AI Act, SOC2) to accelerate business growth and meet Enterprise customer needs across our France, UK, and US markets. You'll work in collaboration with our Security Squad (Platform Engineering, Corporate IT, Legal) and cross-functional teams, with a pragmatic mindset and an AI-first approach to GRC.

Reporting to: Kévin Le Roy, VP AI Transformation, IT & Security

🔑 Key Responsibilities
SOC 2 Certification & Compliance
  • Own and drive our SOC2 certification program: gap analysis, control mapping, evidence collection, remediation coordination, and auditor management.
  • Prepare and coach cross-functional teams for audit readiness through mock audits and training sessions.
  • Navigate overlapping regulatory requirements and enterprise customer expectations.
  • Provide security expertise to Legal and DPO on regulatory topics (GDPR, AI Act, etc.).
  • Lay the groundwork for future certifications (ISO 27001).
Risk Management & Vendor Security
  • Conduct and maintain risk assessments following ISO 27005 methodology.
  • Own the risk register with quarterly reviews, prioritizing risks by business impact.
  • Perform SaaS security reviews during procurement and manage third‑party risk assessments for critical vendors.
  • Assess security impact of organizational, technical, or product changes.
  • Respond to customer security questionnaires and support sales cycles with accurate, timely answers.
Security Governance & Controls
  • Execute recurring governance activities: monthly control checks, quarterly access reviews (Ploy), periodic internal audits.
  • Monitor security dashboards and KPIs with Corporate IT and Platform Engineering teams.
  • Coordinate security incident response and lead post‑incident reviews.
  • Coordinate penetration tests with external providers and track vulnerability remediation with Platform Engineering.
  • Track and report on security & compliance metrics to leadership.
Policy, Awareness & Communication
  • Develop and maintain security policies that improve our security posture while minimizing productivity impact.
  • Maintain and enrich the Security Knowledge Base with up‑to‑date documentation.
  • Contribute to Security Committee preparation, facilitate meetings, and drive action items.
  • Design and deliver security awareness content: onboarding sessions, ongoing trainings (Elba), and internal communications.
  • Partner with Engineering to continuously improve security in the SDLC and products.
Qualifications
  • 4 to 7 years of experience in GRC, information security, or IT audit, ideally in a startup/scaleup.
  • Experience with SOC 2 Type II and other security certifications (ISO 27001, etc.).
  • Knowledge of GDPR and data protection best practices.
  • Autonomous, action‑oriented, comfortable with AI tools.
  • Excellent English; French is a strong plus.
Technical Environment
  • Identity & Security: Okta (SSO), Kandji (MDM), Cloudflare Zero Trust, Ploy (access reviews), Elba (security awareness).
  • Monitoring & SIEM: Datadog, AWS CloudTrail.
  • Cloud Infrastructure: AWS, GCP.
  • Daily tools: Notion, Slack, Google Workspace, Dust AI.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

GRC Engineer (Governance, Risk, and Compliance)
GRC Engineer (Governance, Risk, and Compliance)

Revevol • Paris

Sur place
EUR 90 000 - 120 000
GRC Security Engineer
GRC Security Engineer

DataDome • France

Hybride
EUR 60 000 - 80 000
Remote work stipend
Health benefits
Annual leisure activity allowance
+3
GRC Security Engineer
GRC Security Engineer

DataDome • Paris

Hybride
EUR 75 000 - 110 000
Remote/hybrid/in-office options
Office near Opera Garnier
Kenko health benefits
+2
Senior Security Analyst - GRC
Senior Security Analyst - GRC

Dormont Manufacturing Co • Massy

Sur place
EUR 45 000 - 65 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Nice

Hybride
EUR 110 000 - 170 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Dijon

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Rennes

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Montpellier

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Grenoble

Hybride
EUR 90 000 - 120 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Lille

Hybride
EUR 90 000 - 130 000