Senior Cybersecurity GRC

il y a 1 semaine


Paris, Île-de-France Believe Temps plein

Company DescriptionBelieve is a global artist development company. We empower local artists, labels andpublishers to grow their audiences at each stage of their careers with expertise, respect,fairness and transparency.Operating in 50+ countries, with more than 2,000 employees, Believe oCers a full rangeof services including audience development, publishing, marketing and distribution,with a tailor-made approach to fit any artist, label or publisher.Believe champions independence and innovation through a unique model thatcombines local expertise with a global tech platform, delivering exclusive solutions forartists to promote and monetize their music thanks to strategic partnerships withleading global digital service providers.With a leading portfolio of brands that includes Nuclear Blast, naïve, TuneCore, GrooveAttack, Sentric, AllPoints and Byond, Believe artists generated more than 800 billionstreams worldwide in 2024 across all genres, and were recognized with more than 70leading industry awards.Believe is a simplified joint-stock company under French law.Ready to set the tone with Believe ?Job DescriptionWe're hiring a Security GRC Engineer to help us build governance, risk, and compliance in a way that actually works in a modern tech organization: pragmatic, automation-friendly, and aligned with agile delivery.This is not a "paperwork" job. You'll partner closely with engineering, product, workplace, auditors and security to turn risk management and compliance into clear, usable guardrails and you'll challenge processes that create friction without improving security.What you'll doRisk management that drives decisionsRun lightweight, continuous risk assessment and threat modelings with teams (not once-a-year rituals).Translate risk into clear options: impact, likelihood, tradeoffs, and recommended actions.Track remediation plans and provide visibility through simple reporting. Build practical governanceMaintain and improve security policies/standards so they're short, actionable, and adopted.Create control objectives that fit real engineering workflows (CI/CD, cloud, SaaS, identity). Compliance, without the theaterSupport audits and evidence collection with a focus on efficiency and reusability.Help align our program with recognized frameworks (e.g., NIST ) in a pragmatic way.Develop "compliance-as-code" habits where possible (automated checks, continuous evidence). Third-party risk (vendors, partners)Drive assessments, follow-ups, and risk treatment with procurement and stakeholders.Push for scalable vendor processes (tiering, standard questionnaires, measurable requirements). Security enablementCreate playbooks, templates, and self-service material that teams can use without heavy guidance.Coach teams to understand risk and make better security choices early in delivery.QualificationsExperience in GRC / risk / compliance in a tech environment (security, cloud, SaaS, engineering orgs).Strong understanding of security fundamentals: identity, access, logging, incident response, cloud shared responsibility, secure SDLC (at a practical level).Ability to write simple, clear policies/standards and translate requirements into engineering-friendly controls.Comfort with ambiguity and agility: you can iterate, prioritize, and deliver incremental improvements.Excellent stakeholder skills: you can influence without authority, challenge respectfully, and get things done.Bonus pointsExperience aligning programs to frameworks (NIST CSF, ISO 27001, SOC 2, etc.).Experience with vendor risk platforms or automation (workflows, evidence collection, dashboards).Familiarity with "compliance as code" concepts, continuous controls monitoring, or security tooling.Experience partnering with product/engineering teams on secure-by-design practices.How we workWe value ownership, transparency, and pragmatism.We prefer automation and repeatability over manual processes.We challenge "the old way" when it's slow, fragile, or meaningless.We aim to be a security team that teams want to work with.Additional InformationSET THE TONE WITH US:Working at Believe means having individual and collective impact in a fast-growing companyAt all stages of their careers, Believers are an important part of what we are doing: shaping the future of the music industry.We need teams that truly reflect the diversity of our clients: our international presence is an inspiring and enriching work environment for each one of us, with daily opportunities to connect with our colleagues all over the world.We have two hearts at Believe - our People and our Artists.We believe in THE POWER OF OUR PEOPLE, who grow every day to develop their potential… We aim to provide our Believers with the best environment to thrive.ROCK THE JOBTailor-made training and coaching programRemote working policyA wellness program "Pauses" with many activities and animations in-houseAccess to Eutelmed, a digital mental health and well-being platform that allows you to speak with an experienced psychologistA healthy and eco-responsible company restaurantIndividual or family health insuranceCSE benefitsA rooftopA gym with free classesSING IN HARMONYAmbassador program: an employee volunteering initiative dedicated to all Believers interested in having a positive impact on Diversity, Equity & Inclusion (DEI), wellbeing and the planet.Implementation of the sustainable mobility package "Forfait mobilité durable" => Reimbursement of up to 600€ for public transport/low carbon footprint5 calendar days 2nd parent leave with 100% pay (in addition to the legal paternity or adoption leave)We are committed to having a workforce that is representative of the community it serves at all levels of the organisation. We, therefore, welcome applications from all backgrounds and all sections of the community regardless of age, disability, gender, race, religion and sexual orientation.


  • Senior Cybersecurity GRC

    il y a 2 semaines


    Paris, Île-de-France Believe Temps plein

    Company Description Believe is a global artist development company. We empower local artists, labels and publishers to grow their audiences at each stage of their careers with expertise, respect, fairness and transparency.Operating in 50+ countries, with more than 2,000 employees, Believe oCers a full range of services including audience development,...

  • Senior Cybersecurity GRC

    il y a 1 semaine


    Paris, Île-de-France Believe Temps plein

    Company Description Believe is a global artist development company. We empower local artists, labels and publishers to grow their audiences at each stage of their careers with expertise, respect, fairness and transparency.Operating in 50+ countries, with more than 2,000 employees, Believe oCers a full range of services including audience development,...

  • OT Cybersecurity

    il y a 2 semaines


    Paris, Île-de-France MA (Montreal Associates) Temps plein

    Job Description: OT Cybersecurity & Automation ConsultantParis, Belgium or Netherlands base with frequent travel across Europe and worldwide (up to 50%)6-12 months (renewable)Fluent in English and FrenchMission SummaryWe are looking for an experienced and autonomous OT Cybersecurity & Automation Consultant to support our Global Engineering team. This...

  • Cybersecurity Manager

    il y a 2 semaines


    Paris, Île-de-France CyberVadis Temps plein

    Company Description Our missionAt CyberVadis we are proud to help our growing number of customers with a cost-effective and scalable solution for third-party cybersecurity risk management, which is one of the hottest cyber topics in the market.Our mission is to provide reliable, globally recognized security assessments and insights, enabling all companies to...

  • Consultant GRC Senior

    il y a 1 semaine


    Paris, Île-de-France Neosoft Temps plein

    Groupe indépendant de conseil en transformation digitale de près de 1800 collaborateurs, Néosoft s'est construit, depuis 2005, sur un modèle qui place l'excellence, le dépassement de soi et la RSE au cœur de sa stratégie.En nous rejoignant, vous intégrez des communautés d'experts et de talents qui vous permettent de développer vos compétences et...

  • Cyber GRC – Expert Industrie

    il y a 2 semaines


    Paris, Île-de-France Collective Temps plein

    ContexteNous recherchons un(e) freelance Cyber GRC senior avec une forte culture industrie / nucléaire pour intervenir sur des sujets de classification opérationnelle de l'information, souveraineté des données et conformité réglementaire liée à la sécurité de la donnée.Missions (exemples)Cadrer / renforcer une règle de classification...

  • Cyber GRC – Expert Industrie

    il y a 2 semaines


    Paris, Île-de-France Collective Temps plein

    ContexteNous recherchons un(e) freelance Cyber GRC senior avec une forte culture industrie / nucléaire pour intervenir sur des sujets de classification opérationnelle de l'information, souveraineté des données et conformité réglementaire liée à la sécurité de la donnée.Missions (exemples)Cadrer / renforcer une règle de classification...


  • Paris, Île-de-France IDEXX Temps plein 120 000 $US - 140 000 $US

    Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware enterprise prepared to navigate today's evolving threat landscape. We have complex, multi-dimensional programs across the organization that support all the technology needed to deliver products and solutions to customers - enabling them to...


  • Paris, Île-de-France Neosoft Temps plein

    Nous recherchons pour intégrer notre Practice Cybersecurité , unConsultant GRC Indus(H/F).Directement rattaché au Practice Lead, vous bénéficierez dans un premier temps d'une période d'intégration vous permettant de découvrir le groupe, nos enjeux et nos équipes.En intégrant notre Practice, voici des exemples de missions qui vous seront proposées...

  • Senior Product Designer

    il y a 2 semaines


    Paris, Île-de-France Riot Security Temps plein

    We're a product-first team on a mission to help grow the cybersecurity culture. We want to instill cybersecurity good practices to employees in a way that's actually effective, and entertaining enough so that employees don't feel like they're working. Think Duolingo but for cybersecurity. We created a platform to easily rollout a cybersecurity awareness...