- Company Name
- FORMIND
- Job Title
- Consultant(e) Senior GRC F/H
- Job Description
-
**Job Title**
Senior GRC Consultant
**Role Summary**
Provide advanced Governance, Risk, and Compliance (GRC) consulting services to France’s large enterprise clients across varied sectors. Lead security strategy, risk assessment, policy development, third‑party risk management, audits, and resilience initiatives. Contribute to pre‑sale activities, community engagement, tool development, and training to enhance the firm’s GRC portfolio.
**Expectations**
- Deliver high‑impact security strategies and risk frameworks tailored to client needs.
- Demonstrate proven expertise in risk mapping, security assurance planning, and compliance auditing.
- Build strong client relationships, guide stakeholders through complex GRC initiatives, and champion continuous improvement.
- Collaborate with internal teams on solution enhancement, knowledge sharing, and best‑practice dissemination.
**Key Responsibilities**
1. Conduct comprehensive risk cartographies and analysis for enterprise environments.
2. Design and implement ISPs (Information Security Plans) and security assurance programs.
3. Benchmark and integrate risk‑analysis technologies; develop classification and information protection roadmaps.
4. Manage third‑party risk (TPRM) assessment and monitoring.
5. Execute security governance, security operations oversight, and resilience planning.
6. Perform audit and compliance reviews, preparing reports and actionable recommendations.
7. Support pre‑sales, product positioning, community outreach, tooling, training, and internal communications.
8. Mentor junior consultants and share knowledge across the organization.
**Required Skills**
- Deep knowledge of GRC frameworks (ISO 27001, NIST, CIS, COBIT).
- Expertise in risk assessment, threat modeling, and security policy development.
- Strong analytical, problem‑solving, and project‑management capabilities.
- Excellent written and verbal communication; ability to explain complex concepts to non‑technical stakeholders.
- Leadership, teamwork, and a results‑driven mindset.
- Proficiency in English (written & spoken).
**Required Education & Certifications**
- Graduate of a top engineering school or Master’s in Computer Science/Information Systems with a specialization in Information Security.
- Minimum 3 years of demonstrable experience in cybersecurity/GRC with concrete deliverables (risk maps, strategies, policies, audits).
- Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer, or equivalent are strongly preferred.
Issy-les-moulineaux, France
On site
Senior
30-10-2025