Security Engineer - GRC

Alan
Hybrid

About The Position

Alan is building the new standard in prevention insurance, integrating insurance, prevention, and care into a single user experience. We are seeking a Security Engineer specializing in Governance, Risk, and Compliance (GRC) to own the security governance and risk posture of a company that handles sensitive health data, operates under DORA and HDS certification requirements, and is regulated by the ACPR. This role requires close partnership with Legal, Internal Audit, and the broader Risk function, making it a highly collaborative position. The Security Engineer will be responsible for the ISO 27001 ISMS, acting as the security expert on regulatory and privacy matters, running risk as an ongoing program, owning the controls framework, managing audit cycles, and overseeing third-party risk. They will also bring health sector context and own incident governance and support DORA reporting. The role involves building a coherent governance backbone across multiple regulators and countries, developing an automated audit and evidence engine, and establishing a risk cartography that feeds into business and engineering decisions. This position offers direct impact on the trust foundation of Alan, the opportunity to tackle complex regulatory challenges, and significant ownership and growth potential with board and executive exposure.

Requirements

  • Led at least one full certification or recertification cycle (ISO 27001).
  • Experience with DORA, HDS, RGPD, PGSSI-S regulations.
  • Experience with risk cartography using EBIOS RM.
  • Experience managing security audit programs and coordinating with certification bodies.
  • Experience running vendor security assessments and defining contractual security requirements.
  • Understanding of the ANS framework and CERT Santé requirements.
  • Experience with incident governance, BCP, and DRP.
  • Scripting skills (e.g., Python) to automate compliance tasks.
  • Experience administering GRC tooling (e.g., CISO Assistant, ServiceNow GRC, Archer).
  • Understanding of cloud governance and shared responsibility models.
  • Familiarity with policy-as-code (OPA, SCP).
  • Ability to review architecture and identify security control gaps.
  • Ability to interpret vulnerability data and drive prioritization.
  • Ability to brief a board or audit committee and translate risk into business language.
  • Ability to influence without authority and align diverse teams.
  • Ability to manage programs with audit-grade rigor, including structured, traceable roadmaps.
  • Ability to build a genuine security culture through relevant awareness programs.
  • Ability to foster proportionate risk ownership across the company.
  • Ability to think in principles and adapt to shifting regulatory landscapes.
  • Legally eligible to work from France, Belgium, or Spain.

Nice To Haves

  • Experience with DORA incident reporting.

Responsibilities

  • Own and operate the ISO 27001 ISMS, including scope definition, Statement of Applicability, internal audit program, and management review.
  • Serve as the security expert on regulatory and privacy matters, translating requirements into controls and ensuring the security program is robust for regulatory negotiations.
  • Lead security risk cartography using EBIOS RM, ensuring it integrates with the company-wide risk framework.
  • Facilitate risk workshops, produce treatment plans, and contribute a security perspective to forums discussing non-security risks.
  • Define and maintain the controls framework, set standards, and track coverage, while collaborating with teams to ensure controls are implemented.
  • Work closely with Infrastructure, Platform, and Engineering to embed security requirements into foundational building blocks.
  • Manage security audit programs and coordinate with certification bodies and Internal Audit.
  • Run vendor security assessments and define contractual security requirements.
  • Own the security dimension of third-party risk in partnership with the Risk team.
  • Bring health sector context, understanding ANS framework, CERT Santé requirements, and sensitive health data handling.
  • Classify and escalate ICT incidents internally, own BCP and DRP governance, and provide security substance for DORA incident reports.
  • Automate compliance work, including evidence collection and control testing, by scripting and connecting GRC tooling to engineering pipelines.
  • Configure and administer GRC tooling (e.g., CISO Assistant, ServiceNow GRC, Archer).
  • Understand cloud governance, shared responsibility in HDS-qualified environments, CSPM tools, and policy-as-code.
  • Review proposed architectures to identify control gaps in identity, network segmentation, encryption, or logging.
  • Interpret vulnerability data and drive prioritization of remediation based on business impact.

Benefits

  • Stimulating environment
  • Perks ensuring they are happy, efficient and spend only high-quality time with co-workers
  • Innovative working method
  • Strong cultural values
  • Remote work flexibility
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service