SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer - GRC

Alan - Remote - Remote - posted 2026-08-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Alan is a prevention-focused health insurance company serving 1M+ members across Europe with €800M+ ARR. This role owns the security governance and risk posture for a company handling sensitive health data under DORA, HDS, and ACPR regulation. You will own and operate the ISO 27001 Information Security Management System (ISMS), including scope definition, Statement of Applicability, internal audit programmes, and management review. You bring technical and operational security substance to regulatory matters (DORA, HDS, RGPD, PGSSI-S), translating requirements into controls and flagging implementation gaps for the Legal and regulatory teams. You run security risk as an ongoing programme using EBIOS RM methodology, partnering with the broader Risk function to ensure security risk cartography feeds into company-wide risk frameworks. You facilitate risk workshops, produce treatment plans, and ensure security considerations inform business decisions. You own the controls framework while distributing control ownership to the teams building and running protected systems. You work closely with Infrastructure, Platform, and Engineering to embed security requirements into foundational building blocks (identity, network, secrets management, logging) from the start. You manage the security audit programme in partnership with Internal Audit and certification bodies, aligning scopes and presenting coherent control effectiveness to the board. You run vendor security assessments, define contractual security requirements (security annexes, DPAs), and partner with the Risk team on third-party security oversight. You bring health sector context, understanding ANS framework and CERT Santé requirements for handling sensitive health data. You own incident governance and support DORA reporting, classifying and escalating ICT incidents, and managing business continuity and disaster recovery governance. Key projects include building a compliance framework spanning ISO 27001, DORA, HDS, and NIS2 across multiple regulators and countries; automating audit and evidence collection through scripted pipelines integrated with engineering systems; and operationalizing risk cartography as a continuous signal feeding into business and engineering decisions. You work closely with Legal, DPO, Internal Audit, Risk, and day-to-day with Infrastructure, Platform, Engineering, Product, and Operations—serving as the bridge between regulatory complexity and operational simplicity.

Similar roles