Senior Information Security Compliance Officer

Il y a 11 minutes


Greater Paris Metropolitan Region, France Sodexo Temps plein

Founded in Marseille in 1966 by Pierre Bellon, Sodexo is the global leader in sustainable food and valued experiences at every moment in life: learn, work, heal and play.

Operating in 45 countries, our 430,000 employees serve 100 million consumers each day. The Sodexo Group stands out for its independence and its founding family shareholding, its responsible business model and its portfolio of activities including Food Services, Facilities Management Services and Employee Benefit Solutions.

Our mission: to improve the quality of life of our employees and those we serve, and contribute to the economic, social and environmental progress in the communities where we operate
.

For Sodexo, growth and social commitment go hand in hand.

Our purpose is to create a better every day for everyone to build a better life for all.

We are looking for a Senior Information Security Compliance expert to join our Global Cybersecurity team and play a key role in ensuring that risk management processes are properly followed across the TDDI function and among business stakeholders.

Your main assignments will be :

  • Build an annual consolidated Information Security Compliance Programme that provides the business, IT visibility of internal and external Audit & Assurance activity to allow appropriate demand & resource planning
  • Deliver effective Security Compliance reporting to inform Risk & Issue reporting to the CISO, IT & Business Senior Leadership
  • Ensure Audit & Assurance actions are managed, tracked, and reported through to mitigation

ISO27001

  • Ensure the ISMS is managed and maintained in alignment with the Statement of Applicability and ISO27001/2 framework
  • Define requirements for the ISMS, document and implement security policies to develop and maintain the ISMS
  • Manage and maintain the ISMS documentation
  • Conduct and supervise Sodexo Group's regular audits and review the implemented controls covered by the ISMS scope to align to the business need
  • Develop a plan to scale up ISO27001 practices to a wider scope to improve overall security maturity
  • Explore opportunities for consolidation of ISMS where practical and appropriate
  • Manage ISO22301 compliance improvements and coordinate annual testing requirements
  • Build and maintain IT business continuity and the disaster recovery plan aligned to business needs
  • Ensure annual recovery testing coordination of IT environment and revise requirements for critical recovery strategy aligns with business requirements

Information Security Third Party Assurance

  • Manage and maintain questionnaires within the Third Party Risk Management platform used by internal and external stakeholders, enhancing the product and supporting processes where applicable.
  • Conduct risk-based information security due diligence activities against vendors to provide appropriate levels of assurance to key stakeholders
  • Enhance Information Security Third Party Assurance processes and engagement activities across IS&T,transversal functions and the wider business

PCI DSS, NIS2, AI Act and relevant regulations

  • Coordinate and report on PCI-DSS, NIS2, AI Act compliance programmes to provide direction and assurance of operational controls and meet Sodexo's compliance requirements

Your profile and competencies :

  • 6+ years of experience in Information Security and related fields
  • Expert knowledge and practical experience of ISO27001 certification requirements and ISMS
  • documentation
  • Expert knowledge and practical experience in implementing compliance action plans regarding applicable
  • regulations (i.e: NIS2, AI Act, PCI-DSS etc)
  • Experience of leading and performing internal or external IT audits
  • Experience of dealing with third party supplier audits
  • Experience of negotiating with stakeholders in designing relevant action plans
  • Experience of comprehensive IT internal audit program design and development
  • General knowledge of IT environments and technologies
  • General Knowledge of Security Architecture or Enterprise Architecture
  • Desirable Certifications: CISA, CRISC, QSA, ISO27001 LI, ISO27001 LA.
  • Ability to communicate effectively in French and in English, both written and verbally
  • Analytical and problem-solving capabilities
  • Strong minded
  • Rigorous and organised
  • Ability to gain Government Security Clearance


What we offer :


Competitive employee benefits
: 13th month salary, works council (CSE), health insurance, 50% reimbursement of public transport subscription, additional leave for family events (wedding, birth, etc.), PERECO ...


Position based in Issy-les-Moulineaux
, easily accessible via Tram T2 and RER C

if you are interested, do not hesitate to apply


  • Compliance Officer

    Il y a 55 minutes


    Greater Paris Metropolitan Region, France matchpoint. Temps plein

    We are recruiting aCompliance Officerfor the account of one of our clients, aleading consulting and technology group, operating in an international environment and currently undergoing a significant phase of transformation following a strategic acquisition.The role is positioned at group level and focuses oncorporate and operational compliance, within a...

  • Information Security Officer

    Il y a 3 minutes


    Paris, France La Fosse Temps plein

    I’m currently working with a huge global business who are undergoing a significant tech and cyber transformation, and they’re looking for an Info Security GRC Officer to be a senior member of the team and help drive their Information Security transformation. This is a well-rounded role and perfect for someone who likes a broad remit where they can get...

  • Information Security Officer

    Il y a 50 minutes


    Paris, Île-de-France La Fosse Temps plein

    Information Security Officer - GRCI'm currently working with a huge global business who are undergoing a significant tech and cyber transformation, and they're looking for an Info Security GRC Officer to be a senior member of the team and help drive their Information Security transformation. This is a well-rounded role and perfect for someone who likes a...


  • Paris, Île-de-France CyberInterim Temps plein

    Company DescriptionCyberInterim is one of the largest global networks of Information Security Experts. Dedicated to addressing complex cybersecurity challenges, CyberInterim provides expertise across industries to ensure an organization's digital security and resilience. The company is committed to delivering tailored solutions and maintaining the highest...

  • Senior Cloud Security Engineer

    Il y a 45 minutes


    Greater Paris Metropolitan Region, France INKcredible Design & Printing Temps plein

    Job title: Senior Cloud Security EngineerLocation: ParisAbout LedgerWe're a team of experts pushing the limits of what's possible, united by our common goal to unlock true freedom through digital ownership, making technology accessible for all. We believe in a world where users, creators and enterprises manage their value with ownership and freedom. Our...

  • Defence Compliance Officer

    Il y a 7 minutes


    Greater Paris Metropolitan Region, France EGIDE Temps plein

    Defense Compliance Officer – FranceLocalisation :Région parisienne - PrésentielSecteur :Défense & technologies souverainesType :CDI – Temps pleinSéniorité :Confirmé / SeniorRémunération :Compétitive selon profil + equity + couverture santé complèteÀ propos d'EGIDEEGIDE développe des architectures de défense aérienne de nouvelle...

  • Senior Security Consultant

    Il y a 18 minutes


    Greater Paris Metropolitan Region, France Insight Temps plein

    We are looking for a seasoned Senior Cybersecurity Consultant to join our team. The ideal candidate will have extensive experience in designing and implementing secure-by-design solutions, with a strong emphasis on enterprise protection technologies. This role requires a comprehensive understanding of threat and vulnerability management, cloud security...

  • Senior Security Consultant

    Il y a 40 minutes


    Greater Paris Metropolitan Region, France Insight Temps plein

    We are looking for a seasoned Senior Cybersecurity Consultant to join our team. The ideal candidate will have extensive experience in designing and implementing secure-by-design solutions, with a strong emphasis on enterprise protection technologies. This role requires a comprehensive understanding of threat and vulnerability management, cloud security...


  • Paris, Île-de-France BAO Temps plein

    The company is a fast-growing fintech / digital assets platform operating in a highly regulated environment, building a Crypto-as-a-Service (CaaS) solution for financial institutions.The platform is rebuilt from scratch and supported by a large, international engineering organization.AsCISO, you own theglobal information security and GRC strategy. You'll...


  • Paris, Île-de-France Natixis Temps plein

    Company DescriptionNatixis Corporate & Investment Banking is a leading global financial institution that provides advisory, investment banking, financing, corporate banking and capital markets services to corporations, financial institutions, financial sponsors and sovereign and supranational organizations worldwide.Our teams of experts in 30 countries...