Security Governance Associate
Security Governance Associate at Contentsquare. About the role
Contentsquare is on the lookout for a dedicated Security Governance Associate to become a vital member of our Security Team. This position involves direct collaboration with the Security Governance Specialist and plays a crucial role within our global trust team. The Security Team is responsible for overseeing and implementing security practices across Contentsquare and its acquired entities, ensuring that we maintain the highest standards for our clients.
Key facts
- Location: Paris Area, France or Barcelona, Spain
- Engagement: Full-time
- Team: Security Governance & Compliance Team
What you'll do
- Assist in the upkeep of various certifications, including ISO 27001, ISO 27701, ISO 27017, ISO 27018, HIPAA, and SOC 2, ensuring compliance and readiness for audits.
- Facilitate the integration of newly acquired companies into the existing security framework of Contentsquare, aligning their practices with our standards.
- Engage in a variety of security audits, both internal and external, which encompass customer evaluations and certification audits.
- Contribute to risk management initiatives by conducting internal assessments and evaluating third‑party security measures.
- Implement and harmonize security policies and practices for newly integrated companies, ensuring a seamless transition into our governance structure.
- Oversee security governance responsibilities, including conducting bi‑annual reviews, performing risk analyses, and executing supplier risk assessments.
- Work collaboratively with other departments to bolster security measures in critical business processes, such as onboarding and incident management.
- Advocate for security awareness through structured initiatives aimed at educating employees about best practices.
- Ensure compliance with internal security controls and protocols, maintaining a secure environment.
- Address security‑related inquiries from potential clients and existing customers throughout the contract lifecycle, providing clarity and assurance.
- Review and analyze security clauses within legal agreements to ensure they meet our standards.
- Schedule and manage both internal and external security assessments, including penetration testing to identify vulnerabilities.
- Stay informed about emerging security threats and devise strategies to mitigate risks while aligning with business objectives.
- Respond to security incidents promptly, conducting investigations and resolving issues effectively.
- Conduct security assessments and risk analyses as part of the Third‑Party Risk Management (TPRM) process, ensuring comprehensive evaluations.
Requirements
- A genuine interest in security governance, risk management, and compliance, with a proactive approach to learning.
- A passion for AI technologies and a commitment to keeping abreast of industry developments and trends.
- Demonstrated ability to take initiative and ownership of projects, ensuring successful outcomes.
- Strong interpersonal skills coupled with a service‑oriented mindset, facilitating effective communication across teams.
- Experience in addressing technical inquiries from various business functions, with the ability to prioritize tasks effectively.
- Capability to work autonomously in a fast‑paced scale‑up environment, adapting to changing circumstances.
- Background in delivering risk assessments, developing security policies, and providing training with an empathetic approach to diverse teams.
- Familiarity with conducting security assessments, including penetration tests and vulnerability scans.
- A proactive and resourceful attitude towards problem‑solving, with a focus on finding innovative solutions.
- A true passion for information security and its importance in today's digital landscape.
- Proficiency in English is essential; knowledge of French is a plus.
Specific requirements
- A Bachelor's or Master's degree in Information Systems Management or a related field is required.
- Prior experience in Cybersecurity or Security Governance, Risk, and Compliance (GRC) is essential.
- Strong project management skills, with the ability to oversee multiple initiatives simultaneously.
- Familiarity with ISO 27001, SOC 1, and SOC 2 frameworks is highly desirable.
- A demonstrated ability to work with rigor, autonomy, and a proactive mindset, driving initiatives and fostering innovative ideas.
Practical notes
Contentsquare is committed to being an equal opportunity employer. We encourage applications from all qualified individuals, regardless of gender, race, religion, disability, or any other characteristic protected by law. We prioritize the security of your personal information throughout the recruitment process, adhering strictly to applicable data protection regulations.
#J-18808-Ljbffr