Security Engineer – GRC

🔥 0 minutes ago

🌐 France, Belgium, +1 more countries – Remote

infoinfo

💵 €83k - €100k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo

🗣️🇫🇷 French Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Alan

Alan

501 - 1000 employees

Founded 2016

🏥 Healthcare

🛡️ Insurance

⚕️ Healthcare Insurance

Healthcare • Insurance • Healthcare Insurance

Alan is a digital health insurance company offering a transparent and efficient health insurance experience. It distinguishes itself by providing fair prices, lightning-fast reimbursements, exceptional customer care, and easy administration through a 100% digital app. Alan boasts a +69 Net Promoter Score, indicating high member satisfaction, and aims to expand its successful model to Canada. With over 650,000 members and a streamlined administration process, Alan focuses on making health insurance simple and accessible. Their digital platform ensures members and administrators have a seamless experience, with quick claim reimbursements and transparent pricing policies. Alan is committed to redefining health insurance by being a preventer, insurer, and caregiver every day.

📋 Description

• Own and operate the ISO 27001 Information Security Management System, including scope definition, Statement of Applicability, internal audit programme, and management review • Translate DORA, HDS, RGPD, PGSSI-S, and other regulatory requirements into technical and operational security controls • Lead security risk cartography using EBIOS RM and integrate it with the company-wide risk framework • Facilitate risk workshops, produce treatment plans, and bring security risk analysis to broader risk forums • Define the controls framework, set standards, track coverage, and distribute control ownership to operational teams • Partner with Infrastructure, Platform, and Engineering on identity, network, secrets management, and logging security requirements • Manage the security audit programme and coordinate with certification bodies and Internal Audit • Run vendor security assessments and own the security dimension of third-party risk • Provide technical security guidance on ANS, CERT Santé, and sensitive health-data requirements • Classify and escalate ICT incidents, own BCP and DRP governance, and support DORA incident reporting • Build a coherent compliance framework for ISO 27001, DORA, HDS, and NIS2 across multiple countries • Develop automated audit and evidence pipelines integrated with engineering systems • Build operational risk cartography using EBIOS RM to inform business and engineering decisions • Automate evidence collection and control testing • Configure and administer GRC tooling, workflows, and dashboards • Assess cloud governance and policy-as-code controls • Review architectures for identity, network segmentation, encryption, and logging gaps • Interpret vulnerability data, drive remediation prioritization, and track resolution KPIs • Collaborate with Legal, DPO, Internal Audit, Risk, Infrastructure, Platform, Engineering, Product, and Operations

🎯 Requirements

• Experience owning and operating an ISO 27001 ISMS • Led at least one full ISO 27001 certification or recertification cycle • Knowledge of DORA, HDS, RGPD, PGSSI-S, NIS2, and AI Act requirements • Experience translating regulatory requirements into technical and operational security controls • Experience with security risk cartography using EBIOS RM • Experience facilitating risk workshops and producing treatment plans • Experience defining controls frameworks and tracking control coverage • Experience working with Infrastructure, Platform, and Engineering teams on identity, network, secrets management, and logging controls • Experience managing security audit programmes and coordinating with certification bodies • Experience partnering with Internal Audit • Experience conducting vendor security assessments and defining contractual security requirements, including security annexes and DPAs • Understanding of ANS framework and CERT Santé requirements • Experience with incident classification, escalation, BCP and DRP governance, and DORA incident reporting • Experience scripting evidence collection and automating control testing using Python or similar • Experience administering GRC platforms such as CISO Assistant, ServiceNow GRC, or Archer • Understanding of cloud governance, shared responsibility in HDS-qualified environments, CSPM, and policy-as-code including OPA or SCP • Ability to review architecture and identify gaps in identity, network segmentation, encryption, and logging • Ability to interpret vulnerability scan outputs and prioritize remediation by business impact • Ability to brief boards or audit committees on security risk • Ability to influence Legal, DPO, Risk, Engineering, Product, and Operations without formal authority • Ability to manage structured, traceable security programmes and roadmaps • Must be legally eligible to work from France, Belgium, or Spain • Fluent in English and French

🏖️ Benefits

• Attractive equity package on top of an above market-average base salary • Remote work flexibility • In-person collaboration opportunities • Stimulating environment and perks • Innovative working method • Strong culture and cultural values guiding the approach to work

Apply Now

Similar Jobs

🕒 Yesterday

P1 Security

11 - 50

📡 Telecommunications

🔒 Cybersecurity

🔐 Security

Telecom signalling security specialist auditing telecom networks with PTA and supporting PTM IDS deployments. Delivering customer reports, presentations, troubleshooting, and operational improvements.

Linux

Python

🕒 6 days ago

Wiz

201 - 500

🔒 Cybersecurity

Security Engineer securing Wiz’s cloud and AI security platform. Building cloud-native defenses, automation, threat modeling, and detection capabilities across products and infrastructure.

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

Python

Terraform

Go

🕒 August 5

EUROPEAN DYNAMICS

501 - 1000

💼 Consulting

📦 Logistics

📣 Marketing

Senior Security Engineer developing and securing enterprise, cloud, and infrastructure cybersecurity solutions for European public-sector clients. Automating operations, hardening systems, and resolving security issues.

AWS

Cloud

Cyber Security

Firewalls

Linux

TCP/IP

Unix

🕒 July 29

EverAI

51 - 200

🤖 Artificial Intelligence

🎮 Gaming

Security Engineer safeguarding users and product from threats in a fast-growing AI dating platform. Involves hands-on application security, risk & compliance, and monitoring emerging threats.

🕒 July 29

Jones Lang LaSalle Americas, Inc.

10,000+ employees

🏠 Real Estate

🤝 B2B

💼 Consulting

HSSE Advisor managing Health, Safety, Security, and Environmental strategies for EMEA clients at JLL. Supporting operational excellence and compliance across multiple countries in dynamic environments.