PB✓
PBridge

Full-time jobsFrance

Security Governance / GRC lead

Alan · Paris, France; Bordeaux, France; Lyon, France; Marseille, France; Biarritz, France; Nantes, France; Annecy, France · Full-time

About this role

HEALTH CAN’T WAIT.

Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t.

Alan exists to end the wait.

Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way.

So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience.

We are on an incredible journey to build a global leading company, with a unique culture https://alan.com/en/careers. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR.

Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond.

Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the broader Risk function — this is a collaborative role, not a siloed one.

🛡️ YOUR MISSION — GOVERNANCE, RISK & COMPLIANCE

Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System — scope definition, Statement of Applicability, internal audit programme, and management review. You've led at least one full certification or recertification cycle and know what breaks down in the months between audits.

Be the security expert in the room on regulatory and privacy matters — not the owner. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme holds up when the regulatory team negotiates with the ACPR or ANS.

Run risk as a living programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM and ensure it feeds into — and is informed by — the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table. You know when a security risk is actually a business risk in disguise.

Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and track coverage — but the controls

Tired of applying one by one?

Our Career Success Team finds roles in France that fit you, tailors your CV to each, and submits the applications — tracked end to end. You just show up to interviews.

We apply, you interview →