- Company Name
- Hornetsecurity France (Formerly Vade)
- Job Title
- GRC Specialist
- Job Description
-
**Job Title:** GRC Specialist
**Role Summary:**
Lead end‑to‑end security initiatives, integrating risk management, compliance, and technical controls across IT projects and products. Drive security governance, conduct technical audits, manage vulnerability and penetration testing, enhance security operations, and provide training and communication to embed a secure culture within the organization.
**Expectations:**
- Deliver security solutions that meet ISO 27001, NIST CSF, CIS Controls, OWASP, and GDPR requirements.
- Own security project lifecycles: scope definition, risk analysis, design reviews, threat modeling, testing, implementation, and validation.
- Translate audit findings and regulatory mandates into prioritized, actionable remediation plans.
- Maintain clear communication with technical teams and senior leadership through documentation and presentations.
- Operate proactively, autonomously, and solution‑oriented, ensuring compliance and operational excellence.
**Key Responsibilities:**
- Own security projects from strategy to delivery, managing timelines, budgets, and risk.
- Conduct technical security audits (networks, endpoints, applications, cloud) and lead vulnerability scanning and penetration testing.
- Develop and execute remediation plans, tracking closure of identified issues.
- Collaborate with SOC to improve incident detection (SIEM, use‑cases, playbooks) and response processes.
- Implement hardening, access governance, logging, and patch management across environments.
- Support ISO 27001 certification lifecycle: policy development, internal audits, evidence collection.
- Advise on GDPR compliance: privacy‑by‑design, data protection impact assessments, incident handling.
- Deliver training and awareness programs to embed secure by default culture.
- Document security controls, procedures, and audit reports in English (and French or German as required).
**Required Skills:**
- Security architecture, risk analysis, and controls implementation.
- Proficiency with audit tools and the ability to convert findings into engineering actions.
- Experience with vulnerability management (Qualys, Nessus), SIEM/SOAR (Sentinel, Splunk), EDR/XDR, and container/Kubernetes security.
- Knowledge of ISO 27001, NIST CSF, CIS Controls, OWASP, and GDPR frameworks.
- Strong written and verbal communication; ability to explain complex topics to both technical and non‑technical audiences.
- Fluent in English; proficiency in French or German mandatory; additional languages a plus.
- Proactive, independent, and solution‑focused mindset.
**Required Education & Certifications:**
- Master’s degree or engineering school in Computer Science, Information Security, or Cybersecurity.
- Minimum 3 years of experience in security, audit, or GRC roles.
- Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, OSCP, PMP/Prince2, and familiarity with NIST and CIS frameworks.