2 дня назад
Security Governance and Risk Lead
83 000 - 100 000€
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Governance and Risk Lead (ISO 27001/DORA/HDS): Owning Alan’s information security management system, security risk cartography, controls framework, audit programme, and third-party risk for a healthcare insurance platform handling sensitive health data. with an accent on regulatory governance, automated audit evidence, and operational risk management. Focus on building continuous compliance pipelines, aligning Legal, Internal Audit, Risk, and Engineering, and translating complex security findings into business decisions.
Location: Hybrid, with legal eligibility to work from France, Belgium, or Spain. Remote work flexibility is available, with in-person collaboration valued.
Salary: €83,000–€100,000 annually, depending on level D–E, plus equity.
Company
builds a healthcare platform combining insurance, prevention, and care, serving more than 1 million members and operating with sensitive health data in regulated markets.
What you will do
- Own and operate the ISO 27001 Information Security Management System, including scope definition, the Statement of Applicability, internal audits, and management reviews.
- Translate DORA, HDS, RGPD, PGSSI-S, NIS2, and related regulatory requirements into effective security controls and implementation plans.
- Lead security risk cartography with EBIOS RM, facilitate risk workshops, and connect security risks with the company-wide risk framework.
- Define the controls framework and partner with Infrastructure, Platform, Engineering, Product, Operations, Legal, DPO, Internal Audit, and Risk.
- Manage certification and internal audit cycles, third-party security assessments, incident governance, and BCP/DRP oversight.
- Automate evidence collection and control testing through scripted pipelines and GRC tooling.
Requirements
- Experience owning at least one complete ISO 27001 certification or recertification cycle.
- Strong understanding of security governance, risk management, audit programmes, and regulated health data environments.
- Practical knowledge of EBIOS RM, DORA, HDS, NIS2, ANS and CERT Santé requirements.
- Ability to assess cloud architecture, identity, network segmentation, encryption, logging, vulnerability data, and policy-as-code.
- Experience configuring GRC platforms such as CISO Assistant, ServiceNow GRC, or Archer.
- Legal eligibility to work from France, Belgium, or Spain is required.
Nice to have
- Experience using Python or similar tools to automate audit evidence collection and control testing.
- Experience supporting DORA incident reporting and working with multiple regulators across countries.
Culture & Benefits
- Hybrid work with flexibility for remote work and an emphasis on in-person collaboration.
- Equity package in addition to the base salary.
- High-impact work supporting healthcare access, prevention, and the protection of sensitive health data.
- Exposure to board and executive-level risk decisions.
- Collaborative work across Legal, DPO, Internal Audit, Risk, Engineering, Product, and Operations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Security GRC Engineer
9 дней назад
Senior Security Engineer (Cloud Security)
110 000 - 130 000€
8 дней назад
Sr. Identity and Access Management Engineer (Cybersecurity)
4 дня назад
IT Administrator - AI & Cybersecurity
4 дня назад
AI Security Governance Strategy Consultant
9 дней назад
Technical Advisor (Identity Security; French or German)
59 400 - 100 064€