Senior Security Analyst - GRC

Ivalua

France

Sur place

EUR 60 000 - 80 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Hybrid working model
Weekly lunches
Training and career development programmes
Regular social events

Résumé du poste

Ivalua, a leading global provider of cloud-based procurement solutions, is seeking a Senior Security Analyst to join our InfoSec team. In this role, you will be responsible for leading governance, risk, and compliance activities and ensuring the security of our systems.

The ideal candidate has at least 4 years of experience in GRC, strong knowledge of security frameworks, and cloud security expertise. We offer a hybrid working model, empowering personal goals while promoting team collaboration.

Qualifications

  • At least 4 years of experience as a Security Analyst in GRC.
  • Strong working knowledge of security, risk, and compliance frameworks.
  • Experience managing audits, self-assessments, or risk assessments.

Responsabilités

  • Lead compliance initiatives across security frameworks.
  • Drive customer security audits and reviews.
  • Support continuous compliance monitoring activities.

Connaissances

GRC experience
Security frameworks (NIST, ISO 27001)
Cloud security knowledge
Audit management
Compliance monitoring
Risk management

Formation

Relevant certifications (CISSP, CISA)

Description du poste

Senior Security Analyst - GRC

(Massy - France)

Company Overview

Founded in 2000, Ivalua is a leading global provider of cloud‑based procurement solutions. At Ivalua we are a global community of exceptional professionals who believe that digital transformation revolutionises supply chain sustainability and resilience to unlock the power of supplier collaboration. We achieve this through our leading cloud‑based spend management platform that empowers hundreds of the world’s most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG performance, lower risk, and enhance productivity.

Opportunity

You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security programme, providing peace of mind and assurance of protection and safety to our customers. Our team is hands‑on, with a strong problem‑solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers’ long‑term challenges.

Role

We are looking for a Senior Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments, and driving new security certifications and compliance initiatives.

Key Responsibilities
  • Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI‑DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53.
  • Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams.
  • Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations.
  • Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them.
  • Lead or support internal and third‑party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring.
  • Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness.
  • Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, and access reviews.
Your Profile – Skills and Experience
  • At least 4 years of experience as a Security Analyst in GRC.
  • Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI‑DSS, GDPR).
  • Direct experience managing audits, self‑assessments, or risk assessments against one or more InfoSec frameworks listed above.
  • Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis).
  • Familiarity with continuous compliance and monitoring platforms.
  • Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams.
  • Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments).
  • Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800-39).
  • Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired.
  • Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus.
Soft Skills
  • Excellent interpersonal, communication, and organisational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts.
  • Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators.
  • Strong organisational skills and attention to detail; able to manage multiple competing priorities in a fast‑paced environment.
  • High degree of initiative, self‑motivation, and ability to work independently with limited supervision.
Benefits
  • Hybrid working model (three days in the office per week).
  • Hybrid working mode to balance office and remote work.
  • Snacks and weekly lunches in the office.
  • Empowered to pursue individual goals with improved team collaboration and increased productivity.
  • Unleash your full professional potential with exceptional training and career development programmes.
  • Diverse and inclusive work environment where unique contributions are highly valued.
  • Regular social events, team running events, and musical activities.
Equal Opportunity

We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Senior Security Analyst - GRC
Senior Security Analyst - GRC

Dormont Manufacturing Co • Massy

Sur place
EUR 45 000 - 65 000
GRC Security Engineer
GRC Security Engineer

DataDome • France

Hybride
EUR 60 000 - 80 000
Remote work stipend
Health benefits
Annual leisure activity allowance
+3
Ingénieur Sécurité Applicative (H/F)
Ingénieur Sécurité Applicative (H/F)

Dormont Manufacturing Co • Massy

Sur place
EUR 45 000 - 60 000
Modèle hybride (3 jours sur site, 2 jours en télétravail)
Programme de formation et développement de carrière
Événements d'équipe organisés
Ingénieur Sécurité Applicative Senior (H/F)
Ingénieur Sécurité Applicative Senior (H/F)

Ivalua • Massy

Hybride
EUR 70 000 - 100 000
Formation et développement de carrière
Environnement inclusif
Événements sociaux / team building
GRC Security Engineer
GRC Security Engineer

DataDome • Paris

Hybride
EUR 75 000 - 110 000
Remote/hybrid/in-office options
Office near Opera Garnier
Kenko health benefits
+2
Sr Solution Consultant (Pre-Sales) Massy -France
Sr Solution Consultant (Pre-Sales) Massy -France

Ivalua • Massy

Hybride
EUR 60 000 - 90 000
Hybrid work model
Snacks and weekly lunches
Training and career development
+1
Manager Sécurité Applicative Senior (H/F) Massy - France
Manager Sécurité Applicative Senior (H/F) Massy - France

Ivalua • Massy

Sur place
EUR 110 000 - 150 000
Ingénieur Sécurité Applicative SaaS – Hybride
Ingénieur Sécurité Applicative SaaS – Hybride

Ivalua • Massy

Sur place
EUR 70 000 - 100 000
Ingénieur Sécurité Applicative (H/F) Massy - France
Ingénieur Sécurité Applicative (H/F) Massy - France

Ivalua • Massy

Sur place
EUR 50 000 - 70 000
GRC Manager
GRC Manager

Welcome to the Jungle France • Paris

Sur place
EUR 55 000 - 75 000