Chargement en cours

Information Security Analyst

FRANCE
il y a 1 jour

Description:

  • Maintain and improve the ISO 27001 management system so controls remain effective, documented, and continuously evidenced.
  • Support internal audits, surveillance audits, and recertification cycles, including the unified audit covering Didomi and acquired business units.
  • Track corrective actions, nonconformities, and continuous improvement initiatives through to closure.
  • Run recurring security calendar activities, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles.
  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources and help define remediation priorities.
  • Perform periodic access reviews across critical systems such as Google Workspace, AWS, Slack, JAMF, Git

    Lab, Git

    Hub, and internal applications.
  • Review new tools, vendors, and SaaS applications for security and compliance risks before adoption.
  • Help assess and harden internal workflows with a focus on identity and access management, MFA, SSO, and data handling.
  • Support security questionnaires, RFPs, and customer due diligence requests.
  • Support broader initiatives such as AI governance, SaaS governance, and integrating acquired entities into the ISO scope.

Requirements:

  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally in a SaaS or technology company.
  • Solid working knowledge of ISO 27001, including Annex A controls and the audit process.
  • Hands-on experience with vulnerability management tools and access governance processes.
  • Hands-on experience with Vanta, including running ISO 27001 or comparable audits end-to-end on the platform.
  • Hands-on experience with AWS security tools, especially GuardDuty and Inspector, including triaging findings and proposing remediation priorities.
  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work, with concrete examples of what you have built or automated.
  • Strong bias toward removing unnecessary process and proposing lighter alternatives.
  • Strong written communication in English, with the ability to explain security topics clearly to engineers, executives, and customers.
  • Pragmatic mindset focused on controls that work in practice rather than only on paper.
  • Experience supporting HIPAA or HITRUST programs and mapping requirements across frameworks, preferred.
  • Familiarity with cloud environments, especially AWS, and common SaaS administration tools such as Google Workspace, Slack, and identity providers, preferred.
  • Exposure to security questionnaire platforms and trust center tooling, preferred.
#J-18808-Ljbffr
Entreprise
RemoteLeads
Plateforme de publication
WHATJOBS
Soyez le premier à postuler aux nouvelles offres
Soyez le premier à postuler aux nouvelles offres
Créez gratuitement et simplement une alerte pour être averti de l’ajout de nouvelles offres correspondant à vos attentes.
* Champs obligatoires
Ex: boulanger, comptable ou infirmière
Alerte crée avec succès