Назад
Company hidden
2 дня назад

Security Governance and Risk Lead

83 000 - 100 000€
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
France/Spain/Belgium
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Governance and Risk Lead (ISO 27001/DORA/HDS): Owning Alan’s information security management system, security risk cartography, controls framework, audit programme, and third-party risk for a healthcare insurance platform handling sensitive health data. with an accent on regulatory governance, automated audit evidence, and operational risk management. Focus on building continuous compliance pipelines, aligning Legal, Internal Audit, Risk, and Engineering, and translating complex security findings into business decisions.

Location: Hybrid, with legal eligibility to work from France, Belgium, or Spain. Remote work flexibility is available, with in-person collaboration valued.

Salary: €83,000–€100,000 annually, depending on level D–E, plus equity.

Company

hirify.global builds a healthcare platform combining insurance, prevention, and care, serving more than 1 million members and operating with sensitive health data in regulated markets.

What you will do

  • Own and operate the ISO 27001 Information Security Management System, including scope definition, the Statement of Applicability, internal audits, and management reviews.
  • Translate DORA, HDS, RGPD, PGSSI-S, NIS2, and related regulatory requirements into effective security controls and implementation plans.
  • Lead security risk cartography with EBIOS RM, facilitate risk workshops, and connect security risks with the company-wide risk framework.
  • Define the controls framework and partner with Infrastructure, Platform, Engineering, Product, Operations, Legal, DPO, Internal Audit, and Risk.
  • Manage certification and internal audit cycles, third-party security assessments, incident governance, and BCP/DRP oversight.
  • Automate evidence collection and control testing through scripted pipelines and GRC tooling.

Requirements

  • Experience owning at least one complete ISO 27001 certification or recertification cycle.
  • Strong understanding of security governance, risk management, audit programmes, and regulated health data environments.
  • Practical knowledge of EBIOS RM, DORA, HDS, NIS2, ANS and CERT Santé requirements.
  • Ability to assess cloud architecture, identity, network segmentation, encryption, logging, vulnerability data, and policy-as-code.
  • Experience configuring GRC platforms such as CISO Assistant, ServiceNow GRC, or Archer.
  • Legal eligibility to work from France, Belgium, or Spain is required.

Nice to have

  • Experience using Python or similar tools to automate audit evidence collection and control testing.
  • Experience supporting DORA incident reporting and working with multiple regulators across countries.

Culture & Benefits

  • Hybrid work with flexibility for remote work and an emphasis on in-person collaboration.
  • Equity package in addition to the base salary.
  • High-impact work supporting healthcare access, prevention, and the protection of sensitive health data.
  • Exposure to board and executive-level risk decisions.
  • Collaborative work across Legal, DPO, Internal Audit, Risk, Engineering, Product, and Operations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →