Senior Security Analyst - GRC

Ivalua
France
Workplace: HybridFull timeFunction: CybersecurityExperience: 4+ yearsSkills: ["Communication","Interpersonal","Problem-solving","Organization","Leadership"]

Senior Security Analyst to drive GRC activities across global and regional frameworks, manage audits and questionnaires, maintain security policies, and coordinate certifications. You will engage with engineering, infrastructure, and customers to translate security requirements into actionable guidance, oversee risk management processes, and ensure audit readiness in a hybrid, Massy-based environment.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ivalua
Ivalua
1 year ago

Senior Security Analyst - GRC

âś“ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Senior Security Analyst to drive GRC activities across global and regional frameworks, manage audits and questionnaires, maintain security policies, and coordinate certifications. You will engage with engineering, infrastructure, and customers to translate security requirements into actionable guidance, oversee risk management processes, and ensure audit readiness in a hybrid, Massy-based environment.
Location: France
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53
  • •Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams
  • •Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations
  • •Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them
  • •Lead or support internal and third party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring

Key Requirements

  • •At least 4 years of experience as Security Analyst GRC
  • •Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR)
  • •Direct experience managing audits, self-assessments, or risk assessments against one or more InfoSec frameworks listed above
  • •Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis)
  • •Familiarity with continuous compliance and monitoring platforms
Experience:4+ yearsSaaSCloudProcurementEnterprise software
Skills:CommunicationInterpersonalProblem-solvingOrganizationLeadership
Certifications:CISSPCISACISMAzure Cloud Security
Languages:EnglishFrench
Tech Stack:TLSTLS/SSLIDS/IPSNetwork securityCloud securityISO 27001NISTSOC 1SOC 2PCI-DSSGDPRAzureAWSGCPBIADisaster RecoverySecurity architectures

Company Brief

Ivalua
Provides a cloud-based procure-to-pay and sourcing platform that helps organizations manage procurement, supplier relationships, sourcing events, and spend analytics to drive cost savings, compliance, and supplier collaboration across global enterprises.
Industry: Procurement Platforms
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: Paris, France
Founded: 2000
WebsiteLinkedIn