Senior Security Analyst

Il y a 4 jours

Massy, Île-de-France Ivalua Temps plein 45 000 € - 65 000 € Contrat

Senior Security Analyst - GRC

Massy - France

Overview

You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands‑on, with a strong problem‑solving mindset, capable of thinking holistically and providing solutions to address our customers’ long‑term challenges.

Responsibilities

  • Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI‑DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800‑53
  • Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams.
  • Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations.
  • Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them.
  • Lead or support internal and third‑party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring.
  • Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness.
  • Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc.

Skills and Experience

  • At least 4 years of experience as Security Analyst focused on GRC
  • Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800‑53, ISO 27001, SOC, HITRUST, HIPAA, PCI‑DSS, GDPR)
  • Direct experience managing audits, self‑assessments, or risk assessments against one or more InfoSec frameworks listed above
  • Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis)
  • Familiarity with continuous compliance and monitoring platforms
  • Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams
  • Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments)
  • Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800‑39)
  • Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired
  • Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus

Soft Skills

  • Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts
  • Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators.
  • Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast‑paced environment
  • High degree of initiative, self‑motivation, and ability to work independently with limited supervision