SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Alan is a prevention-focused health insurance company serving 1M+ members across multiple European markets. This role owns the security governance and risk posture of a company handling sensitive health data under DORA, HDS, and ACPR regulation.
You will own and operate the ISO 27001 Information Security Management System (ISMS), including scope definition, Statement of Applicability, internal audit programmes, and management reviews. You bring technical and operational security substance to regulatory matters, translating DORA, HDS, RGPD, PGSSI-S, and other requirements into controls and flagging implementation gaps. You partner with Legal, DPO, and Internal Audit to ensure the security programme is solid during regulatory negotiations.
You run security risk as an ongoing programme using EBIOS RM, leading risk cartography and ensuring it feeds into the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring security perspective to broader risk forums. You own the controls framework while distributing control ownership to teams—working closely with Infrastructure, Platform, and Engineering to embed security requirements into foundational building blocks (identity, network, secrets management, logging) from the start.
You manage audit cycles with rigor, coordinating with Internal Audit and certification bodies to present coherent control effectiveness to the board. You run vendor security assessments, define contractual security requirements (security annexes, DPAs), and partner with the Risk team on third-party risk. You understand ANS framework and CERT Santé requirements, providing technical context on health-sector regulation. You own incident governance and support DORA reporting, classifying and escalating ICT incidents, and governing BCP/DRP.
Key technical enablement: you automate compliance work (scripting evidence collection, automating control testing, connecting GRC tooling to engineering pipelines), configure GRC platforms (CISO Assistant, ServiceNow GRC, Archer), speak cloud governance fluently (HDS-qualified environments, CSPM tools, policy-as-code), review architecture for control gaps, and interpret vulnerability data to drive prioritization by business impact.
You translate risk into business language for boards and audit committees. You influence without authority, aligning Legal, DPO, Risk, Engineering, Product, and Operations on security requirements. You manage programmes with audit-grade rigor, running structured, traceable roadmaps. You build genuine security culture through relevant awareness programmes and foster proportionate risk ownership. You think in principles when regulatory frameworks shift (DORA, NIS2, AI Act).
REQUIREMENTS:
- Led at least one full ISO 27001 certification or recertification cycle
- Experience with EBIOS RM risk methodology
- Familiarity with health-sector regulation (ANS framework, CERT Santé, HDS)
- Experience with GRC tooling administration (CISO Assistant, ServiceNow GRC, Archer, or similar)
- Ability to script compliance automation (Python or similar)
- Understanding of cloud governance, shared responsibility models, CSPM tools, and policy-as-code (OPA, SCP)
- Ability to review architecture and identify control gaps in identity, network, encryption, logging
- Experience with vulnerability management and prioritization
- Strong communication skills to brief boards and audit committees
- Ability to influence cross-functional teams without direct authority
- Programme management with audit-grade rigor and traceable roadmaps
- Mindset: translate risk to business language, build security culture, think in principles when frameworks shift