SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Compliance Specialist

Mistral - Paris, Île-de-France, France - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Mistral is a full-stack AI company providing frontier models, developer tools, applications, and compute infrastructure. They partner with enterprises across finance, manufacturing, defense, healthcare, and the public sector to co-create customized AI systems. As a Security Compliance Specialist, you will be central to building and operating Mistral's cybersecurity compliance program. Your responsibilities include developing and maintaining the Information Security Management System, coordinating compliance activities across the organization, and supporting the achievement of key certifications (ISO 27001, SOC 2, HDS, SecNumCloud, C5) required for enterprise growth. Key responsibilities: - Develop and manage Mistral's cybersecurity compliance program - Support implementation and maintenance of security frameworks and ISMS - Coordinate internal reviews, control assessments, and external audits - Collect and organize evidence for compliance and certification requirements - Develop compliance training and awareness materials for teams - Participate in cybersecurity risk assessments and track remediation - Maintain compliance documentation, policies, procedures, and audit records - Monitor changes in cybersecurity standards (NIS2, Cyber Resilience Act, DORA, LPM) and assess organizational impact - Collaborate with Sales, Marketing, Legal, and other teams to identify business-critical certifications - Evaluate and prioritize new certification initiatives based on business value and implementation effort You bring 5+ years of experience in cybersecurity compliance, information security governance, or risk management. You have hands-on experience supporting compliance programs, certification processes, and external audits. You understand frameworks like ISO 27001, SOC 2, HDS, SecNumCloud, and C5, and are familiar with regulations including NIS2, the Cyber Resilience Act, and DORA. Knowledge of sensitive/classified information requirements (II 901, IGI 1300) is advantageous. You are highly organized with strong attention to detail, excellent written and verbal communication skills, and proven ability to work collaboratively across technical, legal, commercial, and operational teams. Professional English proficiency required; French is a plus.

Similar roles