Senior Security Analyst
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
Senior Security Analyst - GRC
Massy - France
Overview
You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands‑on, with a strong problem‑solving mindset, capable of thinking holistically and providing solutions to address our customers’ long‑term challenges.
Responsibilities
- Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI‑DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800‑53
- Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams.
- Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations.
- Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them.
- Lead or support internal and third‑party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring.
- Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness.
- Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc.
Skills and Experience
- At least 4 years of experience as Security Analyst focused on GRC
- Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800‑53, ISO 27001, SOC, HITRUST, HIPAA, PCI‑DSS, GDPR)
- Direct experience managing audits, self‑assessments, or risk assessments against one or more InfoSec frameworks listed above
- Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis)
- Familiarity with continuous compliance and monitoring platforms
- Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams
- Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments)
- Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800‑39)
- Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired
- Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus
Soft Skills
- Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts
- Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators.
- Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast‑paced environment
- High degree of initiative, self‑motivation, and ability to work independently with limited supervision