Back to results

Alan

Security Engineer - GRC

83.000 € – 100.000 €Hybrid

  • Engineering
  • France
  • Full time
  • 3d ago
Newly posted

About the role

Alan is building a new standard in prevention insurance by integrating insurance, prevention, and care into a single user experience. The Security Engineer - GRC will own the security governance and risk posture for a company handling sensitive health data for over 1 million members. This role involves managing regulatory compliance, security risk cartography, and audit cycles while partnering with legal, internal audit, and engineering teams.

Responsibilities

  • Own and operate the ISO 27001 Information Security Management System.
  • Translate regulatory requirements into technical controls and flag implementation gaps.
  • Lead security risk cartography using EBIOS RM and facilitate risk workshops.
  • Define the controls framework and track coverage across infrastructure and engineering teams.
  • Manage the security audit programme and coordinate with certification bodies.
  • Conduct vendor security assessments and define contractual security requirements.
  • Classify and escalate ICT incidents and provide security substance for DORA reporting.

Required skills

  • ISO 27001
  • GRC
  • EBIOS RM
  • DORA
  • HDS
  • RGPD
  • PGSSI-S
  • Python
  • Cloud governance
  • Risk management

Nice to have

  • CISO Assistant
  • ServiceNow GRC
  • Archer
  • OPA
  • SCP

Qualifications

  • Experience leading at least one full ISO 27001 certification or recertification cycle
  • Experience in handling sensitive health data and understanding ANS/CERT Santé requirements

About the Company

Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. They partner with 40K+ companies and serve more than 1M+ members, with a team of 1000+ people.