Назад
Company hidden
6 часов Π½Π°Π·Π°Π΄

Senior GRC Security Engineer (AI)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
remote (Ρ‚ΠΎΠ»ΡŒΠΊΠΎ France)
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
senior
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
France
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Senior GRC Security Engineer (AI): Driving ISO 27001 and SOC 2 Type II compliance programs, risk management, third-party security reviews, and internal control improvements with an accent on audit readiness, practical control effectiveness, and automation. Focus on building GRC tooling and workflow automation, facilitating risk assessments, leading security awareness initiatives, and supporting technical remediation across the business.

Location: France β€” Remote

Company

hirify.global provides an AI-powered cybersecurity platform that detects and blocks bots, fraud, and account abuse across websites, applications, and APIs.

What you will do

  • Drive day-to-day execution of the ISO 27001 program, including control maturity, evidence collection, internal audits, and audit preparation.
  • Maintain the SOC 2 Type II program and keep controls, evidence, and remediation actions on track.
  • Run risk assessments, workshops, the risk register, treatment plans, and follow-up activities with technical and business stakeholders.
  • Manage third-party security reviews, internal control checks, gap identification, and remediation tracking.
  • Lead security awareness activities, including training, phishing simulations, and effectiveness measurement.
  • Partner with Legal, HR, Finance, Business Operations, Sales, and auditors on security controls, questionnaires, audits, and remediation.

Requirements

  • At least 7 years of experience in a cybersecurity product company or internet-scale SaaS environment.
  • Hands-on experience driving and maintaining an ISO 27001 certification program.
  • Experience conducting structured risk assessments and working with technical and non-technical stakeholders.
  • Technical fluency to assess tools, systems, and processes and collaborate credibly with engineering teams on remediation.
  • Comfortable working in French and English.
  • Ability to identify practical control gaps and improve security practices beyond documentation.

Nice to have

  • Experience with SOC 2 Type II and third-party risk management in a SaaS environment.
  • Experience with Vanta or similar GRC automation platforms.
  • Familiarity with AI governance and the security implications of AI tooling.

Culture & Benefits

  • Remote, hybrid, and office flexibility is defined by the position; this role is remote in France.
  • €500 workspace setup stipend for remote or hybrid work and an SNCF discount card for visits to the office.
  • Healthcare coverage through Kenko, annual sports or culture allowance, and a bicycle maintenance allowance.
  • Internal learning and development platform with additional training support available through the manager.
  • Company offsites, events, drinks, winter parties, and lunch-and-learn sessions.
  • PTO based on the country of residence, including 25 days in France.

Hiring process

  • Interview with a Talent Acquisition Manager focused on cultural fit.
  • Technical and cultural interview with the Engineering Manager, including a take-home technical challenge.
  • Presentation and review of a technical proposal with the team, followed by a leadership discussion about hirify.global's vision.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’