Remotely
iso 27001doraopanis2servicenow grchdsscpebios rm
Job Description
📋 Description
- Own ISO 27001 ISMS scope, SOA, internal audit programme, and management reviews.
- Lead regulatory and privacy matters (DORA, HDS, RGPD, PGSSI-S) and translate requirements into
- Run security risk cartography with EBIOS RM; integrate into company risk framework.
- Define and track the controls framework; partner with Infrastructure, Platform, and Engineering.
- Manage security audit programme and coordinate with certification bodies.
- Oversee third‑party risk and vendor security assessments.
🎯 Requirements
- Proven experience owning an ISMS and at least one full certification/recertification cycle.
- Deep knowledge of ISO 27001, DORA, HDS, NIS2; familiarity with RGPD and related regulatory
- Experience with risk methodologies (EBIOS RM) and risk workshops; ability to translate risk into
- Strong GRC tooling skills (e.g., ServiceNow GRC, Archer, CISO Assistant) and automation experience
- Ability to read architecture, identify control gaps, and collaborate with engineering teams.
- Excellent communication to brief boards or audit committees; ability to influence across Legal
🎁 Benefits
- Remote work option with in‑person collaboration; must be eligible to work from France, Belgium or
- Competitive salary (€83K – €100K per year) and Europe‑based compensation packages.
- Join a global team building a unified compliance backbone across multiple regulators/countries.
- Access to growth opportunities within a rapid, health‑tech focused company.
Back to all jobs