- Company Name
- SYNETIS
- Job Title
- Consultant Cybersécurité GRC H/F
- Job Description
-
Job title: Cybersecurity GRC Consultant (M/F)
Role Summary: Deliver end‑to‑end cybersecurity, resilience, and regulatory compliance services for large accounts, mid‑market and SMB clients. Lead governance, risk and compliance (GRC) initiatives, design and implement action plans, and support clients in achieving regulatory and industry standards.
Expectations: Produce high‑quality deliverables (risk assessments, maturity diagnostics, control plans), guide clients through implementation, maintain client relationships, and contribute to the growth of the GRC offering. Demonstrate pro‑active consulting, strategic vision, and measurable impact on clients’ security posture.
Key Responsibilities:
- Conduct risk analyses using Ebios RM, ISO 27005, FAIR, and financial quantification.
- Develop and execute GRC roadmaps: governance charts, internal audit plans, KPI dashboards, and committee procedures.
- Lead regulatory alignment: ISO 27001‑related documentation, NIS2, DORA, LPA, GIA, LPM, SWIFT, IA Act, RGPD.
- Support cyber risk management across SI acquisition, on‑premise, cloud, and multi‑cloud projects.
- Implement third‑party risk management (TPRM).
- Plan and run business continuity and disaster recovery (BIA, PCA, PRA, crisis exercise).
- Deliver training, awareness, and cultural programs.
- Co‑create and refine the GRC service portfolio (AI, multi‑cloud, NIS2).
Required Skills:
- Minimum 3 years in consulting focused on governance frameworks, change management, and regulatory compliance for critical information systems.
- Deep knowledge of ISO 27001, ISO 27005, NIS2, DORA, LPM, SWIFT, and related standards.
- Proficiency in risk assessment methodologies (Ebios RM, FAIR, ISO 27005).
- Strong project management, stakeholder communication, and client‑facing skills.
- Bilingual ability; English fluently written and spoken.
- Pro‑active, strategic consulting mindset.
Required Education & Certifications:
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field.
- Professional certifications preferred: CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, CISSP, or equivalent.
- Advanced knowledge of regulatory frameworks (NIS2, DORA, GIA, LPM) and risk tools.