Expert(e) GRC Sénior (H/F)
Core
Senior GRC expert leading governance, risk, and compliance frameworks for the IT department, ensuring alignment with regulatory standards and security norms.
Role type
Senior GRC Expert (Cybersecurity & Compliance)
Builds
Governance frameworks, risk mitigation plans, compliance documentation, and audit readiness for the IT department.
Domain
Cybersecurity, Regulatory Compliance, IT Governance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
ISO 27001, CORA, NIS, RGPD, SOC 2, EBIOS Risk Manager, MEHARI, GRC tools (RSA Archer, MetricStream, ServiceNow GRC), risk assessment, audit management, policy writing
Preferred skills
Experience in regulated sectors (nuclear, health, retail, aerospace)
Technologies
ISO 27001, CORA, NIS, RGPD, SOC 2, RSA Archer, MetricStream, ServiceNow GRC
Responsibilities
Pilot implementation and maintenance of GRC frameworks aligned with standards; Assess and map cyber risks and propose mitigation plans; Support teams in preparing for internal and external compliance audits; Lead awareness workshops and training on security best practices; Collaborate with stakeholders to integrate regulatory requirements into operational processes; Write and maintain security and compliance policies and procedures
Seniority
Senior, hands-on IC