обновлено 6 дней назад
Information Security Analyst (GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Analyst (GRC): Operationalizing the ISO 27001 program and managing recurring security activities with an accent on audit readiness, evidence collection, and vulnerability triage. Focus on automating compliance workflows using AI tooling and optimizing security processes to reduce manual overhead.
Location: Remote (France)
Company
is a consent management platform specializing in privacy and compliance solutions.
What you will do
- Maintain and improve the ISO 27001 management system, ensuring controls remain effective and documented.
- Triage vulnerability findings from AWS GuardDuty and Inspector, defining and driving remediation priorities.
- Conduct recurring security activities, including quarterly access reviews, risk assessments, and business continuity tests.
- Perform security and compliance reviews for new tools, vendors, and SaaS applications.
- Support initiatives regarding AI governance, SaaS governance, and the integration of acquired business units.
- Handle security questionnaires, RFPs, and customer due diligence requests.
Requirements
- Must be based in France
- 3+ years of experience in GRC, compliance, or information security, ideally within a SaaS environment.
- Solid working knowledge of ISO 27001, including Annex A controls and the audit process.
- Hands-on experience with Vanta for running ISO 27001 audits end-to-end.
- Experience with AWS security suite (GuardDuty, Inspector) and AI tooling for automation.
- English: Strong written communication skills required
Nice to have
- Experience supporting HIPAA or HITRUST programs.
- Familiarity with AWS cloud environments and common SaaS administration.
- Exposure to security questionnaire platforms and trust center tooling.
Culture & Benefits
- Remote-first workplace.
- Pragmatic security culture that favors practical controls over paperwork.
- Strong bias toward removing unnecessary processes and leveraging automation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Information Security Governance Specialist (SaaS)
Coinhako
4 дня назад
Senior Security Engineer (GRC)
3 дня назад
Information Security & Compliance Analyst
2 дня назад
Information Security Governance Specialist (SaaS)
4 дня назад
Senior AI Risk Analyst (AI GRC)
6 часов назад