Senior Security Analyst - GRC

Dormont Manufacturing Co

Massy

Sur place

EUR 45 000 - 65 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Dormont Manufacturing Co is looking for a Senior Security Analyst focused on GRC based in Massy, France. You will be part of the InfoSec team tasked with enhancing our Information Security program and ensuring compliance across multiple frameworks.

The ideal candidate has at least 4 years of experience in security analysis, a strong grasp of security and compliance frameworks, and excellent communication skills in both French and English. This role involves leading audits and evaluations to safeguard our systems and customer trust.

Qualifications

  • Minimum 4 years of experience as a Security Analyst focused on GRC.
  • Strong knowledge of security frameworks like NIST and ISO 27001.
  • Good understanding of cloud platforms and security architecture.

Responsabilités

  • Lead compliance initiatives for various security frameworks.
  • Evaluate technical controls across the technology stack.
  • Drive customer security audits and develop security documentation.

Connaissances

Security compliance frameworks
Risk management
Cloud security knowledge
Interpersonal communication

Formation

Relevant audit and/or Information Security certifications
Bachelor's degree in a relevant field

Outils

Azure
AWS
GCP

Description du poste

Senior Security Analyst - GRC

Massy - France

Overview

You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands‑on, with a strong problem‑solving mindset, capable of thinking holistically and providing solutions to address our customers’ long‑term challenges.

Responsibilities
  • Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI‑DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800‑53
  • Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams.
  • Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations.
  • Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them.
  • Lead or support internal and third‑party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring.
  • Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness.
  • Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc.
Skills and Experience
  • At least 4 years of experience as Security Analyst focused on GRC
  • Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800‑53, ISO 27001, SOC, HITRUST, HIPAA, PCI‑DSS, GDPR)
  • Direct experience managing audits, self‑assessments, or risk assessments against one or more InfoSec frameworks listed above
  • Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis)
  • Familiarity with continuous compliance and monitoring platforms
  • Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams
  • Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments)
  • Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800‑39)
  • Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired
  • Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus
Soft Skills
  • Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts
  • Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators.
  • Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast‑paced environment
  • High degree of initiative, self‑motivation, and ability to work independently with limited supervision
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Senior Security Analyst - GRC
Senior Security Analyst - GRC

Ivalua • France

Hybride
EUR 60 000 - 80 000
Hybrid working model
Weekly lunches
Training and career development programmes
+1
GRC Manager
GRC Manager

Welcome to the Jungle France • Paris

Sur place
EUR 55 000 - 75 000
Senior GRC Security Analyst - Audits & Compliance
Senior GRC Security Analyst - Audits & Compliance

Dormont Manufacturing Co • Massy

Sur place
EUR 45 000 - 65 000
Cybersécurité GRC - Senior
Cybersécurité GRC - Senior

TMC • Avignon

Sur place
EUR 70 000 - 90 000
Cyber & IT Control Compliance Analyst (H/F/X)
Cyber & IT Control Compliance Analyst (H/F/X)

Digital Realty • Paris

Sur place
EUR 45 000 - 65 000
GRC Security Engineer
GRC Security Engineer

DataDome • France

Hybride
EUR 60 000 - 80 000
Remote work stipend
Health benefits
Annual leisure activity allowance
+3
Security Engineer - GRC
Security Engineer - GRC

Alan • Lille

Hybride
EUR 90 000 - 130 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Grenoble

Hybride
EUR 90 000 - 120 000
Flexible remote work
Security Engineer - GRC
Security Engineer - GRC

Alan • Montpellier

Hybride
EUR 90 000 - 140 000
Security Engineer - GRC
Security Engineer - GRC

Alan • Nice

Hybride
EUR 110 000 - 170 000
Flexible remote work