Security Governance / GRC lead

alan
Marseille

Health can’t wait .

Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t.

Alan exists to end the wait.

Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way.

So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience.

We are on an incredible journey to build a global leading company, with a unique culture . We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR.

Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond.

Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the broader Risk function — this is a collaborative role, not a siloed one.

️ Your mission — Governance, risk & compliance

Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System — scope definition, Statement of Applicability, internal audit programme, and management review. You've led at least one full certification or recertification cycle and know what breaks down in the months between audits.

Be the security expert in the room on regulatory and privacy matters — not the owner. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme holds up when the regulatory team negotiates with the ACPR or ANS.

Run risk as a living programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM and ensure it feeds into — and is informed by — the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table. You know when a security risk is actually a business risk in disguise.

Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and track coverage — but the controls live with the teams who build and run the things they protect. You work closely with Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging) are designed with security requirements embedded, not bolted on. You're a partner to those teams, not an auditor standing over them.

Run audit cycles with rigour, in close partnership with Internal Audit. You manage the security audit programme and coordinate with certification bodies, but you're not operating in a vacuum. You work with Internal Audit to align scopes, avoid duplication, and present a coherent picture of control effectiveness to the board. You've sat in joint audit planning sessions and know how to make that relationship productive rather than territorial.

Manage third-party risk with real teeth. You run vendor security assessments, define contractual security requirements (security annexes, DPAs). You partner with our Risk team, which oversees third-party risk, and own the security dimension.

Bring the health sector context. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive health data operationally — not just on paper. You're a useful partner to Legal when the question is "what does this regulation actually require us to do technically?"

Own incident governance and support DORA reporting. You classify and escalate ICT incidents internally, own BCP and DRP governance, and provide the security substance for DORA incident reports.

What you'll build and who you'll work with

Next-Gen Compliance Framework : ISO 27001, DORA, HDS, NIS2 — multiple regulators, multiple countries, one coherent governance backbone. Build the system that lets Alan scale from 1M to many millions of members without rebuilding compliance every time.

Automated Audit & Evidence Engine : Replace manual evidence collection with scripted pipelines plugged directly into engineering systems. Turn audit cycles from quarterly fire drills into a continuous capability.

Living Risk Cartography : Risk treated as an operational signal, not a static deliverable. EBIOS RM at the core, feeding directly into business and engineering decisions.

You'll work closely with Legal, DPO, Internal Audit, and the broader Risk function — and partner day-to-day with Infrastructure, Platform, Engineering, Product, and Operations. You're the bridge between regulatory complexity and operational simplicity.

⚡ Why this role is special

Direct Impact : You own the trust foundation that lets Alan handle health data for 1M+ members and operate in highly regulated markets. Your work is the precondition for everything else Alan does.

Complex Problems : 4 regulators across 4 countries, sensitive health data, and a regulatory landscape that keeps shifting (DORA, NIS2, AI Act) — to be modeled into a single, coherent control system.

Ownership & Growth : Board and executive exposure, real influence on company-wide risk decisions, and the autonomy to shape Alan's security culture across 800+ people.

What you will also do — Technical enablement

Automate compliance work wherever possible. You script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines. You've used Python or similar to reduce the manual lift of an audit cycle, and you actively look for the next process to streamline.

Configure and own GRC tooling, not just use it. You can administer platforms like CISO Assistant, ServiceNow GRC, or Archer — designing workflows, building dashboards, and making them actually useful for the teams that feed them data.

Speak cloud governance fluently. You understand shared responsibility in HDS-qualified environments, know what CSPM tools surface and what they miss, and can reason about policy-as-code (OPA, SCP) without needing an engineer to translate.

Read architecture well enough to challenge it. You can review a proposed architecture, identify control gaps in identity, network segmentation, encryption, or logging, and push back credibly in a room of engineers — without pretending to be one.

Interpret vulnerability data and drive prioritisation. You read scan outputs, work with engineering teams to prioritise remediation by business risk rather than CVSS score, and track resolution KPIs over time.

⭐️ Qualifications — Mindset and soft skills

You translate risk into business language. You can brief a board or an audit committee and make them feel informed — not overwhelmed or underwhelmed. You know the difference between a finding that requires an emergency board call and one that belongs in a quarterly report.

You influence without authority. You align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers or adversarial dynamics. People don't avoid you — they come to you early because you make their lives easier, not harder.

You manage programmes with audit-grade rigor. You run structured, traceable roadmaps. You know where every commitment is, who owns it, and when it's due. You escalate proactively and don't let dependencies surprise you.

You build security culture, not compliance theatre. Your awareness programmes land because they're relevant, not because they're mandatory. You foster proportionate risk ownership across the company — the goal is teams making better decisions, not teams checking boxes.

You think in principles when frameworks shift. DORA is live. NIS2 transposition pace varies. The AI Act is arriving. You don't freeze when the regulatory landscape moves — you reason from first principles and adapt without waiting to be told what to do.

How we work

Location : Paris-based, hybrid. We value in-person collaboration and ask Alaners to be in the office part of the week.

We hire people, not checklists. If you're excited by this scope but don't check every box, we'd still love to hear from you.

Publié le 2026-06-24

Emplois Recommandés

CHEF.FE DE PROJET INSERTION H/F

Acta Vista
Marseille 7e

A propos de Acta Vista: Depuis 2002, ACTA VISTA développe des chantiers d'insertion et de formation qualifiante aux métiers du patrimoine, dédiés aux personnes les plus éloignées de l'emploi. Nos Mis…

Voir les Détails
Publié le 2026-06-03

Gestionnaire de copropriété confirmé - F/H

Marseille

Entreprise : Le CabRH , cabinet de recrutement et d'approche directe, recrute pour son client référent de la gestion de copropriété sur Marseille et ses environs. Notre client est une agence immobi…

Voir les Détails
Publié le 2026-05-28

Directeur Achats-Marchés H/F

Unicil - Groupe Action Logement
Marseille 6e

A propos de Unicil - Groupe Action Logement: Acteur majeur de l'immobilier, Unicil Groupe Action Logement est le premier producteur de logements sociaux en région Sud depuis 5 ans. Fort de plus de 35…

Voir les Détails
Publié le 2026-06-16

HOTE HOTESSE D'ACCUEIL (H/F)

VILLA M MARSEILLE
Marseille

Qui sommes-nous ? Situé dans le 8ème arrondissement de Marseille, à deux pas des plages et à proximité du centre-ville, l'Hôtel Villa M Marseille est le nouvel établissement lifestyle 4 étoiles qui…

Voir les Détails
Publié le 2026-03-07

Intervenant(e) garde d'enfants diplômé(e) petite enfance MARSEILLE (13)

BAMBINOS
Marseille

Bambinos.care est un acteur reconnu de la garde d’enfants à domicile avec comme ADN d'être : “ smart et no paper” De la réservation à la gestion quotidienne, les process sont optimisés et…

Voir les Détails
Publié le 2026-02-23

TÉLÉCONSEILLER BANCAIRE (F/H)

Randstad
Marseille

Poste ouvert aux personnes en situation de handicap.Rejoignez une entreprise innovante dans les solutions de paiement ! Vous avez le goût du challenge et un talent pour la négociation ? Nous recrutons…

Voir les Détails
Publié le 2026-05-30

Recruteur Indépendant (H/F)

Les Experts de l'Emploi
Marseille 1er

A propos de Les Experts de l'Emploi: Rejoignez Les Experts de l'Emploi, un réseau de recruteurs indépendants qui bouscule les codes du secteur. Lancez-vous dans l'aventure entrepreneuriale en deve…

Voir les Détails
Publié le 2026-06-19

Alternance Manager de rayon - Marseille (F/H)

ISCOD
Marseille

L’ISCOD , spécialiste de la formation en Digital Learning, recherche pour son entreprise, une enseigne de grande distribution, un manager de rayon en contrat d'apprentissage , pour préparer l’une …

Voir les Détails
Publié le 2026-05-21

Senior Software Engineer IA / Full Stack - Studio IA/Data - Remote H/F (IT)

EASY PARTNER
Marseille

MissionsConcevoir et développer des applications de A à Z Développer des APIs et services backend robustes en Python Participer au développement frontend et aux interfaces utilisateurs Déployer …

Voir les Détails
Publié le 2026-06-21

RECEPTIONNISTE CDI H/F

ACCOR
Marseille

Description de l'entreprise Envie de travailler sous le Soleil de Marseille ? Le Sofitel Marseille Vieux Port 5*, adresse iconique au cœur de la cité phocéenne recherche un.e Réceptionniste en …

Voir les Détails
Publié le 2026-05-19