Skip to main content
Alan

Security Engineer - GRC

RemoteBelgium, Spain, France only
Published
Role
Fullstack
Experience
Senior
Employment
Full-time
€83k–€100k/yr
Check eligibility

Open to BE, ES, FR only. Set where you work from to check your eligibility.

No BS summary

Alan is hiring a Security Engineer - GRC to own the security governance and risk posture of a company handling sensitive health data for 1M+ members, operating under DORA and HDS certification requirements, and regulated by the ACPR.

Core skills

ISO 27001/EBIOS RM/DORA/HDS/NIS2/RGPD/PGSSI-S/AI ActPython/CISO Assistant/ServiceNow GRC/Archer/OPA/SCP/CSPM

Required languages

English unknown

What you'll do

  • Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System: scope definition, Statement of Applicability, internal audit programme, and management review.
  • Be the security expert on regulatory and privacy matters. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme is solid when the regulatory team negotiates with the ACPR or ANS.
  • Run risk as an ongoing programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM and ensure it feeds into, and is informed by, the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table.
  • Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and track coverage, but the controls live with the teams who build and run the things they protect. You work closely with Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging) are designed with security requirements built in from the start.
  • Run audit cycles with rigour, in close partnership with Internal Audit. You manage the security audit programme and coordinate with certification bodies. You work with Internal Audit to align scopes, avoid duplication, and present a coherent picture of control effectiveness to the board.
  • Manage third-party risk. You run vendor security assessments and define contractual security requirements (security annexes, DPAs). You partner with our Risk team, which oversees third-party risk, and own the security dimension.
  • Bring the health sector context. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive health data in day-to-day operations.
  • Own incident governance and support DORA reporting. You classify and escalate ICT incidents internally, own BCP and DRP governance, and provide the security substance for DORA incident reports.
  • Automate compliance work wherever possible. You script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines.
  • Configure and own GRC tooling. You can administer platforms like CISO Assistant, ServiceNow GRC, or Archer, designing workflows, building dashboards, and making them genuinely useful for the teams that feed them data.
  • Speak cloud governance fluently. You understand shared responsibility in HDS-qualified environments, know what CSPM tools surface and what they miss, and can reason about policy-as-code (OPA, SCP) without needing an engineer to translate.
  • Read architecture well enough to challenge it. You can review a proposed architecture, identify control gaps in identity, network segmentation, encryption, or logging, and push back credibly with engineers even though you're not one.
  • Interpret vulnerability data and drive prioritisation. You read scan outputs, work with engineering teams to prioritise remediation by business impact over CVSS score alone, and track resolution KPIs over time.

What they require

  • You've led at least one full certification or recertification cycle and know what breaks down in the months between audits.
  • You've sat in joint audit planning sessions and know how to make that relationship work well.
  • You translate risk into business language. You can brief a board or an audit committee and leave them genuinely informed.
  • You influence without authority. You align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers or adversarial dynamics.
  • You manage programmes with audit-grade rigor. You run structured, traceable roadmaps. You know where every commitment is, who owns it, and when it's due.
  • You build a genuine security culture. Your awareness programmes land because they're relevant to the people who take them.
  • You think in principles when frameworks shift. DORA is live. NIS2 transposition pace varies. The AI Act is arriving. When the regulatory landscape moves, you reason from first principles and adapt without waiting to be told what to do.

Benefits

  • Remote work flexibility, but we value in-person collaboration
  • A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of cultural values that guide our approach to work
  • Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high-quality time with co-workers.

Alan integrates insurance, prevention, and care into a single user experience and is building prevention insurance.

🇧🇪 BelgiumHealthcareEnterprise
€83k–€100k/yr