SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Compliance, GRC Engineer

Mistral - Paris, Île-de-France, France - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Mistral is a full-stack AI company providing frontier models, developer tools, applications, and compute infrastructure. They partner with enterprises across finance, manufacturing, defense, healthcare, and the public sector to co-create customized AI systems. As a GRC (Governance, Risk, and Compliance) Engineer, you will be central to Mistral's compliance and risk management program. You'll design, implement, and maintain technical and operational frameworks ensuring the organization meets regulatory, security, and risk obligations. Key responsibilities include: • Automating GRC workflows: design and deploy automation scripts to streamline compliance monitoring, evidence collection, risk assessments, and control testing • Integrating GRC tools with enterprise systems (SIEM, IAM, ticketing) for real-time risk and compliance visibility • Developing automated dashboards and reports providing stakeholder visibility into compliance status and control effectiveness • Implementing automated control testing for technical controls (access reviews, patch management, configuration compliance) • Enforcing policy-as-code across cloud and on-premise environments • Automating risk assessments by integrating vulnerability scanning with GRC platforms • Streamlining audit evidence collection and organization to support internal and external audits • Setting up continuous compliance monitoring with automated alerts for non-compliance events • Automating third-party risk management workflows including vendor assessments and scoring • Collaborating with Security teams to automate incident response and remediation workflows • Maintaining and optimizing GRC platforms for scalability and performance You bring 5+ years in GRC, IT audit, cybersecurity, or related fields. You have hands-on GRC tool experience and deep knowledge of compliance frameworks (ISO 27001, SOC 2, NIST CSF, COBIT, GDPR, NIS2, HIPAA). You're proficient in scripting and automation, understand IT controls and risk methodologies, and have experience with SIEM, IAM, and vulnerability management tools. Cloud security experience (AWS, Azure, GCP) is valued. You excel at analyzing complex data, communicating technical concepts to non-technical stakeholders, and working cross-functionally with IT, Security, Legal, and Business teams. Professional English proficiency required; French is a plus. Relevant certifications (CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor) are preferred.

Similar roles