Alan
Security Engineer - GRC
83.000 € – 100.000 €Hybrid
- Engineering
- France
- Full time
- 3d ago
About the role
Alan is building a new standard in prevention insurance by integrating insurance, prevention, and care into a single user experience. The Security Engineer - GRC will own the security governance and risk posture for a company handling sensitive health data for over 1 million members. This role involves managing regulatory compliance, security risk cartography, and audit cycles while partnering with legal, internal audit, and engineering teams.
Responsibilities
- Own and operate the ISO 27001 Information Security Management System.
- Translate regulatory requirements into technical controls and flag implementation gaps.
- Lead security risk cartography using EBIOS RM and facilitate risk workshops.
- Define the controls framework and track coverage across infrastructure and engineering teams.
- Manage the security audit programme and coordinate with certification bodies.
- Conduct vendor security assessments and define contractual security requirements.
- Classify and escalate ICT incidents and provide security substance for DORA reporting.
Required skills
- ISO 27001
- GRC
- EBIOS RM
- DORA
- HDS
- RGPD
- PGSSI-S
- Python
- Cloud governance
- Risk management
Nice to have
- CISO Assistant
- ServiceNow GRC
- Archer
- OPA
- SCP
Qualifications
- Experience leading at least one full ISO 27001 certification or recertification cycle
- Experience in handling sensitive health data and understanding ANS/CERT Santé requirements
About the Company
Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. They partner with 40K+ companies and serve more than 1M+ members, with a team of 1000+ people.