Alan is building the new standard in prevention insurance, integrating insurance, prevention, and care into a single user experience. We are seeking a Security Engineer specializing in Governance, Risk, and Compliance (GRC) to own the security governance and risk posture of a company that handles sensitive health data, operates under DORA and HDS certification requirements, and is regulated by the ACPR. This role requires close partnership with Legal, Internal Audit, and the broader Risk function, making it a highly collaborative position. The Security Engineer will be responsible for the ISO 27001 ISMS, acting as the security expert on regulatory and privacy matters, running risk as an ongoing program, owning the controls framework, managing audit cycles, and overseeing third-party risk. They will also bring health sector context and own incident governance and support DORA reporting. The role involves building a coherent governance backbone across multiple regulators and countries, developing an automated audit and evidence engine, and establishing a risk cartography that feeds into business and engineering decisions. This position offers direct impact on the trust foundation of Alan, the opportunity to tackle complex regulatory challenges, and significant ownership and growth potential with board and executive exposure.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed