Chargement en cours

Security Governance / GRC lead

RENNES, 35
il y a 15 heures

Your mission: Governance, risk & compliance

  • Own and operate the ISO 27001 ISMS – scope definition, Statement of Applicability, internal audit programme, and management review. Lead at least one full certification or recertification cycle.
  • Be the security expert on regulatory and privacy matters – translate DORA, HDS, RGPD, PGSSI‑S and other regulatory requirements into controls, flag implementation gaps, and provide technical substance for regulatory negotiations.
  • Run risk as an ongoing programme with the broader risk function – create risk cartography using EBIOS RM, facilitate workshops, produce treatment plans and apply a security lens to non‑security risk forums.
  • Own the controls framework yet distribute ownership – set standards, track coverage, and work with Infrastructure, Platform and Engineering to embed security requirements in foundational building blocks.
  • Run audit cycles with rigor – manage the security audit programme, coordinate with certification bodies and Internal Audit to align scopes, avoid duplication, and present coherent control effectiveness to the board.
  • Manage third‑party risk – run vendor security assessments and define contractual security requirements (security annexes, DPAs).
  • Bring the health sector context – understand ANS framework, CERT Santé requirements and translate regulatory needs into technical actions.
  • Own incident governance and support DORA reporting – classify and escape ICT incidents, oversee BCP/DRP governance, and provide security substance for incident reports.

What You’ll Build and Who You’ll Work With

  • Compliance Framework – ISO 27001, DORA, HDS, NIS2; design a coherent governance backbone that scales with member growth.
  • Automated Audit & Evidence Engine – replace manual evidence collection with scripted pipelines directly integrated into engineering systems.
  • Risk Cartography – operationalize risk as a signal that feeds business and engineering decisions, centred on EBIOS RM.

Why This Role Is Special

  • Direct Impact – own the trust foundation that lets Alan handle health data for over a million members in highly regulated markets.
  • Complex Problems – manage four regulators across four countries, sensitive health data, and a shifting regulatory landscape (DORA, NIS2, AI Act).
  • Ownership & Growth – board and executive exposure, real influence on company‑wide risk decisions, and autonomy to shape Alan’s security culture across 800+ people.

Technical Enablement

  • Automate compliance work – script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines; use Python or similar to reduce manual audit effort.
  • Configure and own GRC tooling – administer platforms like CISO Assistant, ServiceNow GRC, or Archer; design workflows, build dashboards, and make them useful for data‑feeding teams.
  • Speak cloud governance fluently – understand shared responsibility in HDS‑qualified environments, CSPM tool coverage, and policy‑as‑code (OPA, SCP).
  • Read architecture well enough to challenge it – review proposed architectures, identify control gaps in identity, network segmentation, encryption, or logging, and give credible pushback.
  • Interpret vulnerability data and drive prioritisation – analyze scan outputs, collaborate with engineering to prioritise remediation by business impact, and track resolution KPIs over time.

Qualifications, Mindset, and Soft Skills

  • Translate risk into business language – brief board or audit committees and distinguish findings requiring board calls from quarterly reports.
  • Influence without authority – align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers.
  • Manage programmes with audit‑grade rigor – run structured, traceable roadmaps; own commitments, escalations, and due dates.
  • Build a genuine security culture – launch awareness programmes that resonate, fostering proportionate risk ownership across the company.
  • Think in principles when frameworks shift – reason from first principles and adapt to regulatory changes like DORA, NIS2, and the AI Act.

Location: You must be legally eligible to work from France.

Remote work: We offer flexible remote work, but value in‑person collaboration.

Everyone, no matter how underrepresented, should feel free to apply.

Perks & Benefits

Alan provides a stimulating environment and perks to keep employees happy, efficient, and focused on high‑quality teamwork.

#J-18808-Ljbffr
Entreprise
Alan
Plateforme de publication
WHATJOBS
Offres pouvant vous intéresser
LILLE, 59
il y a 13 heures
MONTPELLIER, 34
il y a 13 heures
GRENOBLE, 38
il y a 13 heures
ANGLET, 64
il y a 13 heures
Soyez le premier à postuler aux nouvelles offres
Soyez le premier à postuler aux nouvelles offres
Créez gratuitement et simplement une alerte pour être averti de l’ajout de nouvelles offres correspondant à vos attentes.
* Champs obligatoires
Ex: boulanger, comptable ou infirmière
Alerte crée avec succès