Anywhere in France Hybrid Employment

Alan is hiring a Security Engineer - GRC

Responsibilities

  • Lead and maintain the ISO 27001 information security management system, including scope definition, control applicability assessments, internal audits, and executive reviews.
  • Serve as the primary security resource for regulatory and data privacy compliance, interpreting legal requirements into actionable technical and organizational controls.
  • Manage continuous risk assessment using EBIOS RM methodology, organize risk evaluation sessions, and develop mitigation strategies.
  • Develop and maintain the organization’s security controls framework, set baseline standards, monitor implementation, and collaborate with engineering teams to integrate security by design.
  • Oversee the security audit lifecycle, coordinate with external auditors and certification bodies, and align with internal audit functions.
  • Assess and manage cybersecurity risks associated with third-party vendors, including security evaluations and defining contractual security obligations.
  • Apply healthcare-specific regulatory knowledge, including ANS guidelines and CERT Santé standards, particularly in handling sensitive patient information.
  • Lead incident response governance processes and support compliance with DORA reporting obligations, including business continuity and disaster recovery planning.

Work Arrangement

Hybrid — available in France, Spain, Belgium, and Canada

Team

Collaborate with Legal, Data Protection Officer, Internal Audit, Risk Management, Infrastructure, Platform, Engineering, Product, and Operations teams to build and maintain compliance and risk programs.

What you'll build and who you'll work with

Develop compliance frameworks for ISO 27001, DORA, HDS, and NIS2; build automated audit and evidence collection systems using scripted pipelines; implement operational risk cartography with EBIOS RM; partner closely with Legal, DPO, Internal Audit, Risk, Infrastructure, Platform, Engineering, Product, and Operations.

Why this role is special

Drive foundational trust in health data handling; tackle complex challenges across four regulators in four countries; influence executive-level decisions with board exposure and shape enterprise-wide risk posture and security culture.

What you will also do: Technical enablement

Automate compliance tasks through scripting, configure and manage GRC platforms, understand cloud governance models, analyze system architectures to challenge design choices, and interpret vulnerability findings.

Qualifications, mindset and soft skills

Communicate risk in business terms, influence stakeholders without direct authority, manage complex programs rigorously, foster a proactive security culture, and apply first principles when adapting to evolving regulatory frameworks.

How we work

Role requires legal eligibility to work in France; remote work is supported with flexibility, but in-person collaboration is encouraged and valued.

Other

  • Applicant must be legally eligible to work in France.
  • Remote work is flexible, but face-to-face interaction is considered important for team effectiveness.
About company
Alan
Alan is on a mission to make prevention the new norm of care. We help people live healthier lives while turning health benefits into a strategic investment for employers. Our vertically integrated health partner connects all aspects of care — private, public, and direct-to-consumer — creating the most member-centric experience.
All jobs at Alan Visit website
Job Details
Department Corporate
Category security
Posted 3 months ago