Security Engineer - GRC

Alan
France, Belgium, Spain
Full timeEUR 83,000 - 100,000 annuallyFunction: CybersecuritySkills: ["Stakeholder management","Communication","Programme management","Influence without authority","Risk prioritization"]

Own the security governance, risk posture, and compliance program for a company handling sensitive health data. Run the ISO 27001 ISMS end-to-end, translate regulatory requirements (DORA, HDS, GDPR, NIS2, etc.) into controls, and lead security risk cartography with EBIOS RM. Manage audit cycles, third-party risk, incident governance, and DORA reporting while automating evidence collection and configuring GRC tooling.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Alan
Alan
1 week ago

Security Engineer - GRC

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Own the security governance, risk posture, and compliance program for a company handling sensitive health data. Run the ISO 27001 ISMS end-to-end, translate regulatory requirements (DORA, HDS, GDPR, NIS2, etc.) into controls, and lead security risk cartography with EBIOS RM. Manage audit cycles, third-party risk, incident governance, and DORA reporting while automating evidence collection and configuring GRC tooling.
Location: France, Belgium, Spain
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Own and operate the ISO 27001 ISMS, including scope definition, Statement of Applicability, internal audit planning, and management review.
  • •Translate regulatory and privacy requirements into a solid controls program, identifying implementation gaps and supporting regulatory negotiations with the ACPR/ANS teams.
  • •Run security risk as an ongoing programme, leading risk cartography with EBIOS RM and feeding security risk into the company-wide risk framework.
  • •Manage security audit cycles with Internal Audit and certification bodies, coordinating scopes and presenting control effectiveness to the board.
  • •Lead third-party security risk and incident governance, including vendor assessments, security annexes/DPAs, ICT incident classification, BCP/DRP governance, and DORA reporting support.

Pay and Benefits

Salary: EUR 83,000 - 100,000 annually

Key Requirements

  • •Own and operate the ISO 27001 ISMS, including scope, Statement of Applicability, internal audit program, and management reviews, with experience in certification or recertification cycles.
  • •Expertise translating regulatory requirements into technical/operational controls across DORA, HDS, RGPD/GDPR, PGSSI-S, and regulatory relationships.
  • •Run ongoing security risk management using EBIOS RM, including risk cartography, workshops, and treatment plans that align with the company-wide risk framework.
  • •Manage security audit cycles in partnership with Internal Audit, coordinating scopes with certification bodies and presenting control effectiveness coherently to the board.
  • •Comfort with GRC tooling and automation (e.g., evidence collection automation) and ability to drive security substance for DORA incident reporting and governance.
Skills:Stakeholder managementCommunicationProgramme managementInfluence without authorityRisk prioritization
Tech Stack:ISO 27001ISMSDORAHDSRGPDGDPRPGSSI-SNIS2AI ActEBIOS RMPythonCISO AssistantServiceNow GRCArcherOPASCPCSPMICT incidentsBCPDRP

Company Brief

Alan
Alan is a Paris-based digital health insurance provider offering employer and individual health plans, telemedicine, prevention services, and a consumer-focused app to simplify access to care and manage reimbursements.
Industry: Health Insurance (Payers)
Company Size: Large (251 to 1,000 employees)
Revenue: USD 250M to 500M
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Paris, France
Founded: 2016
Glassdoor
Glassdoor: 4.4
WebsiteLinkedInGlassdoor