Назад
Company hidden
1 день назад

Senior Security Analyst - GRC (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
France
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Analyst - GRC (Cybersecurity): Driving security governance, risk, and compliance initiatives for a cloud-based procurement platform with an accent on audits, certifications, technical control evaluation, and customer security assurance. Focus on managing risk assessments, translating security requirements for engineering teams, and coordinating business continuity, disaster recovery, and incident response controls.

Location: Massy, France; hybrid model with 3 days in the office per week

Company

hirify.global provides a cloud-based spend management and procurement platform that helps organizations manage suppliers, improve profitability, strengthen ESG performance, and reduce risk.

What you will do

  • Lead and support compliance initiatives across SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus, BSI C5, and NIST 800-53.
  • Evaluate technical controls across networks, infrastructure, applications, cloud environments, encryption, access controls, firewalls, and TLS/SSL configurations.
  • Manage customer security audits, questionnaires, and contract reviews, including French contracts and EMEA-focused engagements.
  • Present security architecture and control information to prospects and customers.
  • Coordinate security risk management, including risk identification, analysis, scoring, treatment planning, and monitoring.
  • Maintain audit readiness through continuous compliance monitoring and coordinate business impact analysis, disaster recovery tests, access reviews, and incident response exercises.

Requirements

  • At least 4 years of experience as a Security Analyst in GRC.
  • Strong knowledge of security, risk, and compliance frameworks, including NIST, ISO 27001, SOC, PCI-DSS, HIPAA, HITRUST, and GDPR.
  • Experience managing audits, self-assessments, risk assessments, risk registers, or business impact analyses.
  • Familiarity with continuous compliance and monitoring platforms.
  • Understanding of Azure, AWS, or GCP security architecture and technical controls across network, infrastructure, web application, and cloud environments.
  • Professional communication in both French and English is required, including contractual, regulatory, and technical contexts.

Nice to have

  • CISSP, CISA, CISM, Azure Cloud Security, or another relevant security or audit certification.
  • Experience at a Big Four firm or in a security and compliance function within a cloud or SaaS environment.
  • Knowledge of OWASP, MITRE ATT&CK, and NIST 800-39.

Culture & Benefits

  • Hybrid working model with 3 office days per week.
  • Training and career development programs.
  • International, diverse, and inclusive working environment.
  • Office snacks, weekly lunches, and regular social and sporting activities.
  • Privately held, stable, and cash-flow-positive company.

Hiring process

  • Initial screening call with the Talent team.
  • Several personalized interviews with relevant internal stakeholders.
  • Interviews may be conducted virtually or on site.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →