
Security Engineer – GRC
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in France, +2 more countries.
• Take ownership of the ISO 27001 Information Security Management System, which encompasses scope definition, the Statement of Applicability, internal audit programs, and management reviews.
• Convert DORA, HDS, RGPD, PGSSI-S, and additional regulatory mandates into technical and operational security measures.
• Drive security risk mapping utilizing EBIOS RM and align it with the organization's comprehensive risk framework.
• Lead risk workshops, create treatment plans, and present security risk evaluations at broader risk forums.
• Establish the controls framework, set standards, monitor coverage, and delegate control responsibilities to operational teams.
• Collaborate with Infrastructure, Platform, and Engineering on requirements related to identity, network, secrets management, and logging security.
• Oversee the security audit program and liaise with certification bodies and Internal Audit.
• Conduct vendor security evaluations and manage the security aspects of third-party risks.
• Offer technical security advice concerning ANS, CERT Santé, and sensitive health data requirements.
• Classify and escalate ICT incidents, manage BCP and DRP governance, and assist in DORA incident reporting.
• Create a comprehensive compliance framework for ISO 27001, DORA, HDS, and NIS2 across various nations.
• Develop automated audit and evidence collection pipelines integrated with engineering systems.
• Construct operational risk mapping using EBIOS RM to guide business and engineering decisions.
• Automate evidence gathering and control testing processes.
• Configure and manage GRC tools, workflows, and dashboards.
• Evaluate cloud governance and policy-as-code controls.
• Examine architectures for identity, network segmentation, encryption, and logging vulnerabilities.
• Analyze vulnerability data, prioritize remediation efforts, and monitor resolution KPIs.
• Collaborate with Legal, DPO, Internal Audit, Risk, Infrastructure, Platform, Engineering, Product, and Operations teams.
• Proven experience in managing and operating an ISO 27001 ISMS.
• Successfully led at least one complete ISO 27001 certification or recertification process.
• Familiarity with DORA, HDS, RGPD, PGSSI-S, NIS2, and AI Act regulations.
• Experience in translating regulatory requirements into technical and operational security measures.
• Proficient in security risk mapping using EBIOS RM.
• Experience in conducting risk workshops and generating treatment plans.
• Experienced in defining control frameworks and monitoring control coverage.
• Background in collaborating with Infrastructure, Platform, and Engineering teams on identity, network, secrets management, and logging controls.
• Experience in managing security audit programs and working with certification bodies.
• Proven partnership with Internal Audit.
• Conducted vendor security assessments and established contractual security requirements, including security annexes and DPAs.
• Understanding of the ANS framework and CERT Santé stipulations.
• Experience in incident classification, escalation, BCP and DRP governance, and DORA incident reporting.
• Skilled in scripting for evidence collection and automating control tests using Python or similar languages.
• Experience in administering GRC platforms such as CISO Assistant, ServiceNow GRC, or Archer.
• Understanding of cloud governance, shared responsibility in HDS-qualified settings, CSPM, and policy-as-code including OPA or SCP.
• Ability to review architecture and identify identity, network segmentation, encryption, and logging deficiencies.
• Capacity to interpret vulnerability scan results and prioritize remediation based on business impact.
• Ability to present security risks to boards or audit committees effectively.
• Skill in influencing Legal, DPO, Risk, Engineering, Product, and Operations teams without formal authority.
• Proven track record of managing structured and traceable security programs and roadmaps.
• Must have legal authorization to work in France, Belgium, or Spain.
• Fluent in both English and French.
• Competitive equity package in addition to a salary above the market average.
• Flexibility for remote work.
• Opportunities for in-person collaboration.
• A stimulating work environment with various perks.
• Innovative working methods.
• Strong organizational culture and values that shape the work approach.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.