InterviewHack.ai
Empezar gratis
Vacantes / Alan

Security Engineer - GRC

Alan·Anywhere in Francesenior

En corto

  • →Ingeniero de Seguridad GRC responsable del sistema de gestión de seguridad (ISO 27001) y cumplimiento regulatorio.
  • →Trabaja con Legal, Auditoría Interna y Riesgo para gestionar riesgos, auditorías y terceros en entornos altamente regulados.
  • →Destacado: Gestión de cumplimiento con DORA, HDS, RGPD, ACPR y marcos sanitarios como ANS y CERT Santé.
Postularme en la empresa ↗Compartir por WhatsApp

En ~1 minuto te damos: quién te entrevista, las preguntas probables con respuestas desde tu CV, y tu CV adaptado a esta vacante. Gratis, sin tarjeta.

Las preguntas que te van a hacer

1. ¿Cómo estructurarías la declaración de aplicabilidad (SoA) para un ISMS ISO 27001 en una empresa de salud con datos sensibles?

2. ¿Qué controles prioritarios implementarías para cumplir con DORA en un entorno de prevención y seguros?

3. ¿Cómo coordinarías una auditoría conjunta entre seguridad, auditoría interna y proveedores de servicios?

🔒 +7 preguntas más

Sin tarjeta. Subís tu CV y en ~1 minuto tenés el dossier completo.

🎧¿Llegás a la entrevista? Llevá el copiloto. Nuestra extensión escucha la entrevista en vivo y te muestra anclas de 3-4 palabras desde tu CV y tu preparación — mirás, conectás, hablás. Gratis. Ver la extensión →

💵 USD · Remote · No visa

¿No encontrás lo que buscás? Probá Micro1

Micro1 te ubica directo en empresas de EE. UU. que pagan en USD. Un solo proceso de vetting, múltiples ofertas — sin aplicar en frío.

Que Micro1 te matchee →
📬Vacantes elegidas para TU CV, cada mañana por WhatsApp. Gratis: escribí “vacantes” y el bot te manda tus matches del día. Suscribirme →

¿Qué piden?

  • ✓Experiencia comprobada en gestión de ISMS ISO 27001 (definición de alcance, SoA, auditorías).
  • ✓Conocimiento profundo de regulaciones como DORA, HDS, RGPD, PGSSI-S y marcos sanitarios (ANS, CERT Santé).
  • ✓Capacidad para traducir requisitos regulatorios en controles operativos y técnicos.
  • ✓Experiencia en auditorías internas, certificaciones y gestión de terceros con anexos de seguridad.
  • ✓Habilidades colaborativas con Legal, Auditoría Interna y equipos técnicos (infraestructura, plataforma).
  • ✓Conocimiento de herramientas de gestión de riesgos como EBIOS RM.

¿No cumplís todo? Es lo normal — tu dossier gratis te dice qué gaps tenés y cómo cubrirlos en la entrevista.

ISO 27001DORAHDSRGPDPGSSI-SACPRANSCERT SantéEBIOS RMInternal Audit

¿A quién escribirle en Alan?

Tu dossier gratis identifica a las personas que te entrevistarían — con su background, qué valoran y cómo escribirles para destacar antes de aplicar.

Health can’t wait . Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t. Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way. So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. We are on an incredible journey to build a global leading company, with a unique culture . We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR. Prevention as the new norm. That's what we're building with our team of 1000+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond. Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the broader Risk function. It's a highly collaborative role. Your mission: Governance, risk & compliance Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System: scope definition, Statement of Applicability, internal audit programme, and management review. You've led at least one full certification or recertification cycle and know what breaks down in the months between audits. Be the security expert on regulatory and privacy matters. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme is solid when the regulatory team negotiates with the ACPR or ANS. Run risk as an ongoing programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM and ensure it feeds into, and is informed by, the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table. You know when a security risk is really a business risk. Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and track coverage, but the controls live with the teams who build and run the things they protect. You work closely with Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging) are designed with security requirements built in from the start. You work alongside those teams as a partner. Run audit cycles with rigour, in close partnership with Internal Audit. You manage the security audit programme and coordinate with certification bodies. You work with Internal Audit to align scopes, avoid duplication, and present a coherent picture of control effectiveness to the board. You've sat in joint audit planning sessions and know how to make that relationship work well. Manage third-party risk. You run vendor security assessments and define contractual security requirements (security annexes, DPAs). You partner with our Risk team, which oversees third-party risk, and own the security dimension. Bring the health sector context. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive health data in day-to-day operations.

Más empleos como este

Empleos remotos de Security EngineerEmpleos remotos para LATAMEmpleos remotos en cualquier parte

¿Buscando algo parecido?

Dejá tu email y te avisamos cuando salgan vacantes que coincidan con tu perfil.

No apliques sin prepararte

Investigamos quién te entrevista, adaptamos tu CV y te ensayamos en vivo — gratis la primera.

InterviewHack.ai

Preparate para la entrevista exacta: quién te entrevista, tu CV a medida y coach real.

Producto

VacantesEmpresas contratandoRevisar CV (ATS) gratis¿Cómo suena tu inglés?¿Te pagan bien?Respuesta STAR gratisVeredicto de CV (Jev)Reporte de sueldos LATAMCursos gratisBlogCV a medidaPráctica habladaEs gratis

Empleos remotos

ReactPythonFull-StackLATAMArgentinaMéxicoVer todas →

Preparate

Práctica habladaFrontendBackendAI EngineerPor empresaVendete con tu CV

Empresa

Buscás talentoAcerca deContactoPrivacidadTérminos

© 2026 InterviewHack.ai · Tu CV es tuyo. Nunca se usa para entrenar nada. · Un producto de IA-PTY

Vacantes similares activas

Senior IT Engineer

Alan · Paris, France

→

Analytics and pricing expert - Insurance

Alan · Anywhere in France

→

Data Engineer

Alan · Paris, France

→

Senior Engineering Manager (Hands-on) - Offer

Alan · Paris, France

→