Job Description

Role Overview

As a Security Engineer - GRC, you will own the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operating under DORA and HDS certification requirements, and regulated by the ACPR. You will work in close partnership with Legal, Internal Audit, and the broader Risk function. It's a highly collaborative role.

What You Will Do

Your main day-to-day responsibilities will include owning and operating the ISO 27001 ISMS, being the security expert on regulatory and privacy matters, running risk as an ongoing programme, and owning the controls framework.

Why It Might Be a Fit

This role is special because you will have direct impact on the trust foundation that lets Alan handle health data for 1M+ members and operate in highly regulated markets. You will have complex problems to solve, ownership and growth opportunities, and the autonomy to shape Alan's security culture across 800+ people.

Requirements

  • At least one full certification or recertification cycle experience
  • Knowledge of regulatory requirements such as DORA, HDS, RGPD, PGSSI-S, and NIS2
  • Experience with risk management frameworks such as EBIOS RM
  • Ability to translate risk into business language
  • Experience with GRC tooling such as CISO Assistant, ServiceNow GRC, or Archer
  • Understanding of cloud governance and policy-as-code (OPA, SCP)
  • Ability to interpret vulnerability data and drive prioritisation

Benefits

  • Stimulating environment
  • Perks ensuring happiness and efficiency
  • Strong culture
  • Innovative working method
  • Cultural values that guide approach to work
Apply now
Report job

More job openings