6 ΡΠ°ΡΠΎΠ² Π½Π°Π·Π°Π΄
Senior GRC Security Engineer (AI)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Senior GRC Security Engineer (AI): Driving ISO 27001 and SOC 2 Type II compliance programs, risk management, third-party security reviews, and internal control improvements with an accent on audit readiness, practical control effectiveness, and automation. Focus on building GRC tooling and workflow automation, facilitating risk assessments, leading security awareness initiatives, and supporting technical remediation across the business.
Location: France β Remote
Company
provides an AI-powered cybersecurity platform that detects and blocks bots, fraud, and account abuse across websites, applications, and APIs.
What you will do
- Drive day-to-day execution of the ISO 27001 program, including control maturity, evidence collection, internal audits, and audit preparation.
- Maintain the SOC 2 Type II program and keep controls, evidence, and remediation actions on track.
- Run risk assessments, workshops, the risk register, treatment plans, and follow-up activities with technical and business stakeholders.
- Manage third-party security reviews, internal control checks, gap identification, and remediation tracking.
- Lead security awareness activities, including training, phishing simulations, and effectiveness measurement.
- Partner with Legal, HR, Finance, Business Operations, Sales, and auditors on security controls, questionnaires, audits, and remediation.
Requirements
- At least 7 years of experience in a cybersecurity product company or internet-scale SaaS environment.
- Hands-on experience driving and maintaining an ISO 27001 certification program.
- Experience conducting structured risk assessments and working with technical and non-technical stakeholders.
- Technical fluency to assess tools, systems, and processes and collaborate credibly with engineering teams on remediation.
- Comfortable working in French and English.
- Ability to identify practical control gaps and improve security practices beyond documentation.
Nice to have
- Experience with SOC 2 Type II and third-party risk management in a SaaS environment.
- Experience with Vanta or similar GRC automation platforms.
- Familiarity with AI governance and the security implications of AI tooling.
Culture & Benefits
- Remote, hybrid, and office flexibility is defined by the position; this role is remote in France.
- β¬500 workspace setup stipend for remote or hybrid work and an SNCF discount card for visits to the office.
- Healthcare coverage through Kenko, annual sports or culture allowance, and a bicycle maintenance allowance.
- Internal learning and development platform with additional training support available through the manager.
- Company offsites, events, drinks, winter parties, and lunch-and-learn sessions.
- PTO based on the country of residence, including 25 days in France.
Hiring process
- Interview with a Talent Acquisition Manager focused on cultural fit.
- Technical and cultural interview with the Engineering Manager, including a take-home technical challenge.
- Presentation and review of a technical proposal with the team, followed by a leadership discussion about 's vision.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β