Responsibilities
- Lead and maintain the ISO 27001 information security management system, including scope definition, control applicability assessments, internal audits, and executive reviews.
- Serve as the primary security resource for regulatory and data privacy compliance, interpreting legal requirements into actionable technical and organizational controls.
- Manage continuous risk assessment using EBIOS RM methodology, organize risk evaluation sessions, and develop mitigation strategies.
- Develop and maintain the organization’s security controls framework, set baseline standards, monitor implementation, and collaborate with engineering teams to integrate security by design.
- Oversee the security audit lifecycle, coordinate with external auditors and certification bodies, and align with internal audit functions.
- Assess and manage cybersecurity risks associated with third-party vendors, including security evaluations and defining contractual security obligations.
- Apply healthcare-specific regulatory knowledge, including ANS guidelines and CERT Santé standards, particularly in handling sensitive patient information.
- Lead incident response governance processes and support compliance with DORA reporting obligations, including business continuity and disaster recovery planning.
Work Arrangement
Hybrid — available in France, Spain, Belgium, and Canada
Team
Collaborate with Legal, Data Protection Officer, Internal Audit, Risk Management, Infrastructure, Platform, Engineering, Product, and Operations teams to build and maintain compliance and risk programs.
What you'll build and who you'll work with
Develop compliance frameworks for ISO 27001, DORA, HDS, and NIS2; build automated audit and evidence collection systems using scripted pipelines; implement operational risk cartography with EBIOS RM; partner closely with Legal, DPO, Internal Audit, Risk, Infrastructure, Platform, Engineering, Product, and Operations.
Why this role is special
Drive foundational trust in health data handling; tackle complex challenges across four regulators in four countries; influence executive-level decisions with board exposure and shape enterprise-wide risk posture and security culture.
What you will also do: Technical enablement
Automate compliance tasks through scripting, configure and manage GRC platforms, understand cloud governance models, analyze system architectures to challenge design choices, and interpret vulnerability findings.
Qualifications, mindset and soft skills
Communicate risk in business terms, influence stakeholders without direct authority, manage complex programs rigorously, foster a proactive security culture, and apply first principles when adapting to evolving regulatory frameworks.
How we work
Role requires legal eligibility to work in France; remote work is supported with flexibility, but in-person collaboration is encouraged and valued.
Other
- Applicant must be legally eligible to work in France.
- Remote work is flexible, but face-to-face interaction is considered important for team effectiveness.