Security Engineer – GRC
Posted 5hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security Engineer owning governance, risk, and compliance for Alan’s health insurance and prevention platform. Managing ISO 27001, DORA, HDS, audits, risk, and security automation.
Responsibilities:
- Own and operate the ISO 27001 Information Security Management System, including scope definition, Statement of Applicability, internal audit programme, and management review
- Translate DORA, HDS, RGPD, PGSSI-S, and other regulatory requirements into technical and operational security controls
- Lead security risk cartography using EBIOS RM and integrate it with the company-wide risk framework
- Facilitate risk workshops, produce treatment plans, and bring security risk analysis to broader risk forums
- Define the controls framework, set standards, track coverage, and distribute control ownership to operational teams
- Partner with Infrastructure, Platform, and Engineering on identity, network, secrets management, and logging security requirements
- Manage the security audit programme and coordinate with certification bodies and Internal Audit
- Run vendor security assessments and own the security dimension of third-party risk
- Provide technical security guidance on ANS, CERT Santé, and sensitive health-data requirements
- Classify and escalate ICT incidents, own BCP and DRP governance, and support DORA incident reporting
- Build a coherent compliance framework for ISO 27001, DORA, HDS, and NIS2 across multiple countries
- Develop automated audit and evidence pipelines integrated with engineering systems
- Build operational risk cartography using EBIOS RM to inform business and engineering decisions
- Automate evidence collection and control testing
- Configure and administer GRC tooling, workflows, and dashboards
- Assess cloud governance and policy-as-code controls
- Review architectures for identity, network segmentation, encryption, and logging gaps
- Interpret vulnerability data, drive remediation prioritization, and track resolution KPIs
- Collaborate with Legal, DPO, Internal Audit, Risk, Infrastructure, Platform, Engineering, Product, and Operations
Requirements:
- Experience owning and operating an ISO 27001 ISMS
- Led at least one full ISO 27001 certification or recertification cycle
- Knowledge of DORA, HDS, RGPD, PGSSI-S, NIS2, and AI Act requirements
- Experience translating regulatory requirements into technical and operational security controls
- Experience with security risk cartography using EBIOS RM
- Experience facilitating risk workshops and producing treatment plans
- Experience defining controls frameworks and tracking control coverage
- Experience working with Infrastructure, Platform, and Engineering teams on identity, network, secrets management, and logging controls
- Experience managing security audit programmes and coordinating with certification bodies
- Experience partnering with Internal Audit
- Experience conducting vendor security assessments and defining contractual security requirements, including security annexes and DPAs
- Understanding of ANS framework and CERT Santé requirements
- Experience with incident classification, escalation, BCP and DRP governance, and DORA incident reporting
- Experience scripting evidence collection and automating control testing using Python or similar
- Experience administering GRC platforms such as CISO Assistant, ServiceNow GRC, or Archer
- Understanding of cloud governance, shared responsibility in HDS-qualified environments, CSPM, and policy-as-code including OPA or SCP
- Ability to review architecture and identify gaps in identity, network segmentation, encryption, and logging
- Ability to interpret vulnerability scan outputs and prioritize remediation by business impact
- Ability to brief boards or audit committees on security risk
- Ability to influence Legal, DPO, Risk, Engineering, Product, and Operations without formal authority
- Ability to manage structured, traceable security programmes and roadmaps
- Must be legally eligible to work from France, Belgium, or Spain
- Fluent in English and French
Benefits:
- Attractive equity package on top of an above market-average base salary
- Remote work flexibility
- In-person collaboration opportunities
- Stimulating environment and perks
- Innovative working method
- Strong culture and cultural values guiding the approach to work




















