Security Governance / GRC lead
RENNES, 35
il y a 15 heures
Your mission: Governance, risk & compliance
- Own and operate the ISO 27001 ISMS – scope definition, Statement of Applicability, internal audit programme, and management review. Lead at least one full certification or recertification cycle.
- Be the security expert on regulatory and privacy matters – translate DORA, HDS, RGPD, PGSSI‑S and other regulatory requirements into controls, flag implementation gaps, and provide technical substance for regulatory negotiations.
- Run risk as an ongoing programme with the broader risk function – create risk cartography using EBIOS RM, facilitate workshops, produce treatment plans and apply a security lens to non‑security risk forums.
- Own the controls framework yet distribute ownership – set standards, track coverage, and work with Infrastructure, Platform and Engineering to embed security requirements in foundational building blocks.
- Run audit cycles with rigor – manage the security audit programme, coordinate with certification bodies and Internal Audit to align scopes, avoid duplication, and present coherent control effectiveness to the board.
- Manage third‑party risk – run vendor security assessments and define contractual security requirements (security annexes, DPAs).
- Bring the health sector context – understand ANS framework, CERT Santé requirements and translate regulatory needs into technical actions.
- Own incident governance and support DORA reporting – classify and escape ICT incidents, oversee BCP/DRP governance, and provide security substance for incident reports.
What You’ll Build and Who You’ll Work With
- Compliance Framework – ISO 27001, DORA, HDS, NIS2; design a coherent governance backbone that scales with member growth.
- Automated Audit & Evidence Engine – replace manual evidence collection with scripted pipelines directly integrated into engineering systems.
- Risk Cartography – operationalize risk as a signal that feeds business and engineering decisions, centred on EBIOS RM.
Why This Role Is Special
- Direct Impact – own the trust foundation that lets Alan handle health data for over a million members in highly regulated markets.
- Complex Problems – manage four regulators across four countries, sensitive health data, and a shifting regulatory landscape (DORA, NIS2, AI Act).
- Ownership & Growth – board and executive exposure, real influence on company‑wide risk decisions, and autonomy to shape Alan’s security culture across 800+ people.
Technical Enablement
- Automate compliance work – script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines; use Python or similar to reduce manual audit effort.
- Configure and own GRC tooling – administer platforms like CISO Assistant, ServiceNow GRC, or Archer; design workflows, build dashboards, and make them useful for data‑feeding teams.
- Speak cloud governance fluently – understand shared responsibility in HDS‑qualified environments, CSPM tool coverage, and policy‑as‑code (OPA, SCP).
- Read architecture well enough to challenge it – review proposed architectures, identify control gaps in identity, network segmentation, encryption, or logging, and give credible pushback.
- Interpret vulnerability data and drive prioritisation – analyze scan outputs, collaborate with engineering to prioritise remediation by business impact, and track resolution KPIs over time.
Qualifications, Mindset, and Soft Skills
- Translate risk into business language – brief board or audit committees and distinguish findings requiring board calls from quarterly reports.
- Influence without authority – align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers.
- Manage programmes with audit‑grade rigor – run structured, traceable roadmaps; own commitments, escalations, and due dates.
- Build a genuine security culture – launch awareness programmes that resonate, fostering proportionate risk ownership across the company.
- Think in principles when frameworks shift – reason from first principles and adapt to regulatory changes like DORA, NIS2, and the AI Act.
Location: You must be legally eligible to work from France.
Remote work: We offer flexible remote work, but value in‑person collaboration.
Everyone, no matter how underrepresented, should feel free to apply.
Perks & Benefits
Alan provides a stimulating environment and perks to keep employees happy, efficient, and focused on high‑quality teamwork.
#J-18808-Ljbffr
Entreprise
Alan
Plateforme de publication
WHATJOBS
Offres pouvant vous intéresser
LILLE, 59
il y a 13 heures
MONTPELLIER, 34
il y a 13 heures
GRENOBLE, 38
il y a 13 heures
ANGLET, 64
il y a 13 heures