Security Governance Associate
See all open roles at clicktale →
Likely real
- 40 open roles at this company in 30 days (mass-hiring blitz)
- no salary disclosed (correlates with ghost postings)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
What you will do
As part of the Security Governance & Compliance Team, you will be responsible for:
Participating in maintaining our ISO 27001/27701/27017/27018 certifications, HIPAA and SOC 2 report. As well as any new framework we would go forward with.
Helping acquired companies integrate with Contentsquare’s security policies and practices
Taking part in internal, external, customer and certification security audits
Contributing to periodic risk management activities such as internal risk assessments and third party security reviews
Deploying/merging our security practices, policies and certification with recently acquired companies
Handling the security governance tasks (bi-annual management review, risk analysis, monthly KPI, security awareness, supplier risk review)
Collaborating with other departments to improve the security of business processes (onboarding, offboarding, access management, business continuity, SDLC, incident management, etc.)
Actively promoting security awareness through the use of structured campaigns and initiatives
Helping ensure internal security controls are understood and consistently followed
Responding to prospects/customers on security topics before and during the life of customer contracts
Reviewing security clauses in legal contracts
Arrange the schedule of internal and external security scans, penetration testing, code vulnerability testing, etc.
Continually monitor emerging threats, understanding when a concern becomes a priority, and finding creative ways to mitigate these while achieving business goals
Respond to security incidents if they occur, working to investigate and remediate the impact swiftly
As part of Third-Party Risk Management (TPRM), perform security assessments and risk analyses on vendors
What we are looking for
Genuine interest in various security, governance, risks and compliance topics
Keen interest in AI technologies and AI security, with a desire to stay ahead of industry trends.
Comfortable taking ownership of projects and showcasing key accomplishments
Excellent interpersonal skills and a service ethic
A track record of assisting business functions with technical internal and customer-facing requests that are prioritised appropriately
Ability to work quickly and independently in a fast-paced scale-up environment
Experience delivering risk assessments, security policies, processes and procedures, guidance, and training with empathy and understanding for a diverse remote team
Familiarity with internal/external security assessments and reviews, such as penetration testing, bug bounty programs, and internal vulnerability scans
A willingness to get stuff done in an enthusiastic, proactive, and resourceful manner that scales
Be passionate about information security!
Fluent in English (French is a plus!)
Specific requirements
Bachelor's and/or Master's degree in Information Systems Management or a related field.
Previous professional experience in Cybersecurity or Security GRC.
Strong project management skills.
Knowledge of ISO 27001, SOC 1, and SOC 2 frameworks is desirable.
Demonstrates rigor, autonomy, and a proactive mindset, with the ability to drive initiatives and bring forward new ideas.
Location: In our Paris (France) or Barcelona (Spain)
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot