Security Engineer - GRC

Alan

United States

Remote

USD 150,000 - 230,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Alan is seeking a Security Governance & Risk professional to own the ISO 27001 ISMS, define scope and ensure ongoing compliance with DORA, HDS and other regulatory requirements. You will lead audit programmes, coordinate with Internal Audit, and collaborate with Legal and Risk teams to manage third‑party security and incidents.

The role emphasizes translating complex regulations into practical controls, maintaining a robust security posture across infrastructure, platform, and engineering teams.

Qualifications

  • Experience leading ISO 27001 ISMS programmes and audits.
  • Deep understanding of DORA, RGPD, HDS and related health data regulations.
  • Ability to translate regulatory requirements into technical controls.

Responsibilities

  • Own the security governance and risk posture for the company.
  • Lead security audits and coordinate with internal/external auditors.
  • Manage third‑party security risk and vendor assessments.
  • Collaborate with Legal, Internal Audit and Risk teams to ensure regulatory compliance.

Skills

ISO 27001
DORA compliance
Risk management
Regulatory liaison
Audit coordination

Job description

Health can’t wait . Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t. Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way. So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. We are on an incredible journey to build a global leading company, with a unique culture . We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR. Prevention as the new norm. That's what we're building with our team of 1000+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond. Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the broader Risk function. It's a highly collaborative role.

Your mission:

Governance, risk & compliance Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System: scope definition, Statement of Applicability, internal audit programme, and management review. You've led at least one full certification or recertification cycle and know what breaks down in the months between audits. Be the security expert on regulatory and privacy matters. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme is solid when the regulatory team negotiates with the ACPR or ANS. Run risk as an ongoing programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM and ensure it feeds into, and is informed by, the company‑wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table. You know when a security risk is really a business risk. Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and track coverage, but the controls live with the teams who build and run the things they protect. You work closely with Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging) are designed with security requirements built in from the start. You work alongside those teams as a partner. Run audit cycles with rigour, in close partnership with Internal Audit. You manage the security audit programme and coordinate with certification bodies. You work with Internal Audit to align scopes, avoid duplication, and present a coherent picture of control effectiveness to the board. You've sat in joint audit planning sessions and know how to make that relationship work well. Manage third‑party risk. You run vendor security assessments and define contractual security requirements (security annexes, DPAs). You partner with our Risk team, which oversees third‑party risk, and own the security dimension. Bring the health sector context. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive health data in day‑to‑day operations. You're a useful partner to Legal when the question is “what does this regulation actually require us to do technically?” Own incident governance and support DORA reporting. You classify and escalat ICT incidents internally, own BCP and DRP governance, and provide the security substance for DORA incident reports.

What you'll build and who you'll work with

Compliance Framework : ISO 27001, DORA, HDS, NIS2. Multiple regulators, multiple countries, one coherent governance backbone. Build the system that lets Alan scale from 1M to many millions of members without rebuilding compliance every time. Automated Audit & Evidence Engine : Replace manual evidence collection with scripted pipelines plugged directly into engineering systems. Turn audit cycles into a continuous capability instead of a quarterly rush. Risk Cartography : Risk treated as an operational signal that feeds directly into business and engineering decisions, with EBIOS RM at the core. You'll work closely with Legal, DPO, In

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Lead
Security Lead

Alan • United States

Hybrid
USD 137,000 - 205,000
Senior IT Engineer
Senior IT Engineer

Alan • United States

Remote
USD 120,000 - 170,000
Remote Security Lead – AI & Global Compliance
Remote Security Lead – AI & Global Compliance

Alan • United States

Hybrid
USD 137,000 - 205,000
Security & Legal Specialist - Customer Care
Security & Legal Specialist - Customer Care

Portage Ventures GP Inc. • Indiana (PA)

On-site
USD 90,000 - 150,000
Equity package
Hybrid office in Canada HQ
Lunch allowance
+8
Sr. Security Assurance Engineer
Sr. Security Assurance Engineer

6sense • United States

On-site
USD 140,000 - 200,000
Senior Platform Engineer (x/f/m) - Data Retention & Privacy
Senior Platform Engineer (x/f/m) - Data Retention & Privacy

Alan • United States

On-site
USD 136,550 - 193,446
GRC Manager
GRC Manager

OpenRouter, Inc • United States

Remote
USD 100,000 - 150,000
Security Compliance, GRC Engineer
Security Compliance, GRC Engineer

Mistral AI • Paris (KY)

On-site
USD 120,000 - 180,000
Healthcare coverage
Parental leave
Relocation support
+3
Senior Data Security Engineer
Senior Data Security Engineer

I.T. Solutions, Inc. • United States

On-site
USD 160,000 - 220,000
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s
Head of Information Security & GRC – GRC, Compliance, Information Security, ISO27001, DDQ’s

Stott and May • New York (NY)

On-site
USD 180,000 - 260,000