Senior Security Analyst - GRC

Ivalua

Massy

Sur place

EUR 45 000 - 65 000

Plein temps

14 jours+
Générateur de candidature

Une candidature conçue pour ce poste — un CV et une lettre de motivation personnalisés qui correspondent à l’offre.

Passez les filtres ATS

Résumé du poste

Dormont Manufacturing Co is looking for a Senior Security Analyst focused on GRC based in Massy, France. You will be part of the InfoSec team tasked with enhancing our Information Security program and ensuring compliance across multiple frameworks.

The ideal candidate has at least 4 years of experience in security analysis, a strong grasp of security and compliance frameworks, and excellent communication skills in both French and English. This role involves leading audits and evaluations to safeguard our systems and customer trust.

Qualifications

  • Minimum 4 years of experience as a Security Analyst focused on GRC.
  • Strong knowledge of security frameworks like NIST and ISO 27001.
  • Good understanding of cloud platforms and security architecture.

Responsabilités

  • Lead compliance initiatives for various security frameworks.
  • Evaluate technical controls across the technology stack.
  • Drive customer security audits and develop security documentation.

Connaissances

Security compliance frameworks
Risk management
Cloud security knowledge
Interpersonal communication

Formation

Relevant audit and/or Information Security certifications
Bachelor's degree in a relevant field

Outils

Azure
AWS
GCP

Description du poste

Senior Security Analyst - GRC

Massy - France

Overview

You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands‑on, with a strong problem‑solving mindset, capable of thinking holistically and providing solutions to address our customers’ long‑term challenges.

Responsibilities
  • Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI‑DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800‑53
  • Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams.
  • Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations.
  • Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them.
  • Lead or support internal and third‑party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring.
  • Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness.
  • Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc.
Skills and Experience
  • At least 4 years of experience as Security Analyst focused on GRC
  • Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800‑53, ISO 27001, SOC, HITRUST, HIPAA, PCI‑DSS, GDPR)
  • Direct experience managing audits, self‑assessments, or risk assessments against one or more InfoSec frameworks listed above
  • Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis)
  • Familiarity with continuous compliance and monitoring platforms
  • Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams
  • Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments)
  • Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800‑39)
  • Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired
  • Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus
Soft Skills
  • Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts
  • Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators.
  • Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast‑paced environment
  • High degree of initiative, self‑motivation, and ability to work independently with limited supervision
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Security Analyst - GRC
Senior Security Analyst - GRC

Ivalua • France

Sur place
EUR 60 000 - 80 000
Hybrid working model
Weekly lunches
Training and career development programmes
+1
GRC Manager
GRC Manager

Welcome to the Jungle France • Paris

Sur place
EUR 55 000 - 75 000
Senior GRC Security Analyst - Audits & Compliance
Senior GRC Security Analyst - Audits & Compliance

Dormont Manufacturing Co • Massy

Sur place
EUR 45 000 - 65 000
Cybersécurité GRC - Senior
Cybersécurité GRC - Senior

TMC • Avignon

Sur place
EUR 70 000 - 90 000
Consultant/e Cybersécurité GRC senior - Défense & Sécurité - Le Plessis Robinson
Consultant/e Cybersécurité GRC senior - Défense & Sécurité - Le Plessis Robinson

Sopra Steria Company • France

Hybride
EUR 65 000 - 90 000
Academy
Parcours d’intégration
Environnement flexible
+1
Consultant expérimenté GRC - Spécialité conformité/business
Consultant expérimenté GRC - Spécialité conformité/business

Onyx-Conseil • Courbevoie

Sur place
EUR 90 000 - 130 000
Security & Compliance Manager (GRC)
Security & Compliance Manager (GRC)

Imagino • France

Hybride
EUR 70 000 - 110 000
Consultant GRC confirmé [F/H]
Consultant GRC confirmé [F/H]

SEC-IT • Lyon

Sur place
EUR 50 000 - 70 000
Intégration accompagnée
Missions variées à forte valeur ajoutée
Équipe experte et collaborative
Consultant(e ) GRC H/F
Consultant(e ) GRC H/F

FAYAT BÂTIMENT • Paris

Sur place
EUR 70 000 - 80 000
Télétravail 2 jours/semaine
Rémunération compétitive 75K
Cybersecurity Project Manager (M/F)
Cybersecurity Project Manager (M/F)

Make IT Safe • Nantes

Hybride
EUR 55 000 - 82 000