GRC Security Engineer
Ddome · France - Remote · 2026-06-29
À propos du poste
<p><strong>⭐ About the role :</strong></p> <p>&nbsp;</p> <p>At DataDome, security is a core part of the product and of how we operate as a company. We protect large enterprises against bots, fraud, and account abuse, which means strong security and compliance foundations are critical to the trust our customers place in us.</p> <p>As the company grows, so does the level of rigor expected around certifications, risk management, internal controls, third-party security, and audit readiness. We’re looking for a Senior GRC Security Engineer to help us scale that work in a way that is practical, effective, and grounded in how teams actually operate.</p> <p>This is a hands-on individual contributor role reporting to the Head of Security. The impact of the role comes from follow-through, sound judgment, and the ability to turn compliance requirements into security practices that hold up in the real world.</p> <p>You also will build and own a robust tooling and workflow engine to power and automate GRC activities at scale.</p> <p>&nbsp;</p> <p>👉 <strong>You will be more specifically in charge of things like...</strong></p> <p>&nbsp;</p> <h4><strong>Compliance programs</strong></h4> <ul> <li>Play a leading role in DataDome’s ISO 27001 program, driving day-to-day execution across control maturity, evidence collection, internal audits, and audit preparation.</li> <li>Help maintain DataDome’s SOC 2 Type II program over time, ensuring controls, evidence, and follow-up actions stay on track.</li> <li>Keep compliance work practical, reliable, and scalable as the company grows.</li> </ul> <h3>Risk management</h3> <ul> <li>Run the risk management process in practice, including risk assessments, workshops, the risk register, treatment plans, and follow-up.</li> <li>Work with both technical and business stakeholders to identify and assess risks in a structured and useful way.</li> <li>Help teams turn risk findings into clear, prioritized remediation actions.</li> </ul> <h3>Third-party risk and internal controls</h3> <ul> <li>Handle third-party security reviews for internal tools and vendors, including onboarding assessments, reassessments, and follow-up actions.</li> <li>Check that key controls are actually in place across tools and processes, spot gaps or weak configurations, and make sure remediation is tracked and moving with the right teams.</li> </ul> <h3>Awareness and business partnership</h3> <ul> <li>Lead the security awareness program, including training, phishing simulations, and effectiveness tracking.</li> <li>Act as a key security partner for Legal, HR, Finance, and Business Operations on topics such as people controls, data handling, and process design.</li> <li>Help Sales on security topics when needed, including writing clear, accurate, and high-quality answers to security questionnaires and supporting follow-up discussions during the sales cycle.</li> <li>Be comfortable representing security during audits, including explaining how controls work, answering auditor questions, and following up on findings.</li> </ul> <p>&nbsp;</p> <p>👤 <strong>It would be great if...</strong></p> <p>&nbsp;</p> <ul> <li>You have at least 7+ years Experience in a cybersecurity product company or internet-scale SaaS environment.</li> <li><em>You have demonstrated hands-on experience with ISO 27001 and understand what it takes to drive and maintain a certification program in the long run.</em></li> <li>You are comfortable going directly to teams, understanding how things work in practice, spotting gaps, and pushing for improvements that actually fit the way people work.</li> <li>You care about whether controls are real and effective, not just documented.</li> <li>You are comfortable running structured risk assessments and facilitating discussions with both technical and non-technical stakeholders.</li> <li>You communicate clearly and confidently, both in writing and in person, and you are comfortable working in French and English.</li> <li><em>You have the technical fluency to assess tools, systems, and processes with a critical eye, and to engage credibly with engineering teams on remediation efforts</em></li> <li>You look for practical ways to simplify and automate repetitive GRC work, including with AI when it adds real value.</li> </ul> <p>&nbsp;</p> <p><strong>Bonus Points</strong></p> <ul> <li>Experience with SOC 2 Type II and third-party risk management in a SaaS environment.</li> <li>Experience with Vanta or similar GRC automation platforms.</li> <li>Familiarity with AI governance topics or security implications of AI tooling.</li> </ul> <hr> <p><strong>What’s in it for you?</strong></p> <ul> <li><strong>Flex Life:</strong> While we offer remote, hybrid, &amp; in-office options each position specifies the level of flexibility. Our Parisian office is located next to the Opera Garnier. You will also receive a 500€ stipend to help you set up your ideal workspace if you work hybrid or remotely. <ul> <li>If you are full remote, the SNCF dicount card is paid for you to come to our office to visit us &amp; your team!</li> </ul> </li> <li><strong>Generous Health Benefits:</strong> We have partnered with Kenko for your healthcare…
Compétences demandées
- cybersecurity
Votre prochain poste est déjà ici.
Parcourez les offres en direct de milliers d'employeurs, gardez celles qui méritent un second regard et laissez JobBob surveiller le reste.