Security Analyst (GRC Specialist)
London or Paris
Pigment
Pigment is a planning platform built for agility and scale. It provides organizations around the world with the tools they need build and adapt strategic plans.
Our Story So Far
Since our founding in 2019, Pigment has become one of the fastest-growing SaaS companies in the world today. Our product, a highly efficient Enterprise Performance Management (EPM) platform, is helping companies achieve their financial goals by quickly responding to dynamic factors in their respective markets including Tech, Retail, CPG & Financial Services.
In less than 5 years, Pigment has grown to over 450 employees across offices in New York, Toronto, London & Paris and attracted a total of $393M in investment from some of the top Venture Capital firms globally.We serve companies including Unilever, Deliveroo, Gong and Brex to name a few!
We are looking for a Governance, Risk and Compliance specialist, whose core focus will be to protect our customers' and compliance data.
Since our founding in 2019, Pigment has become one of the fastest-growing SaaS companies in the world today. Our product, a highly efficient Enterprise Performance Management (EPM) platform, is helping companies achieve their financial goals by quickly responding to dynamic factors in their respective markets including Tech, Retail, CPG & Financial Services.
In less than 5 years, Pigment has grown to over 450 employees across offices in New York, Toronto, London & Paris and attracted a total of $393M in investment from some of the top Venture Capital firms globally.We serve companies including Unilever, Deliveroo, Gong and Brex to name a few!
We are looking for a Governance, Risk and Compliance specialist, whose core focus will be to protect our customers' and compliance data.
Key Responsibilities
- Strategic Leadership
- Under the coordination of the CISO, participate in the definition of a multi-year, risk-driven security roadmap, design policies, processes and guidance documents driving its implementation
- Implementing the security roadmap, either autonomously or with support from other engineering teams, either in a delivery or project management capacity, depending on the project’s technical requirements.
- Establish and implement company-wide security policies and procedures covering internal IT, production platforms, facilities, and more.
- Improve and maintain the risk analysis and its mitigation planDesign and implement a comprehensive reporting framework of security indicators
- Operational Excellence
- Drive implementation of the security roadmap, leading initiatives and coordinating with engineering teams or other relevant stakeholders (legal, HR, support, customer experience
- Oversee vulnerability remediation, including triage, prioritization, and mitigation follow up.
- Oversee vendor security assessments and ensure alignment with compliance requirements, deliver security approvals in the procurement process
- Participate in the asset management program (contractors, accounts, datasets, etc.)
- Compliance Management
- Lead certifications renewals for SOC 1, SOC 2, and contribute to acquisition of new certification (e.g., ISO 27001, ISO 27701)
- Lead planning and execution of compliance audit programs conducted both internally and externally.
- Maintain and enhance compliance programs, collaborating cross-functionally to ensure adherence.
- Coordinate with the Sales and Legal teams to understand the legislative landscape and market requirements in terms of compliance.
- Advocacy and Training
- Design and implement security awareness training programs and champion best practices across teams (onboarding training, awareness training, phishing simulations, developer trainings)
Experience & Expertise
- At least 5 years of experience on governance and compliance topics, either as Security Engineer, Security Project Manager, or compliance officer (of course, you can be way more experienced!)
- Extensive knowledge and experience with the ISO27000 series standard: implementation experience in obtaining and maintaining is a plusSolid technical background in security engineering
- Great team spirit with a problem-solving, can-do attitude.
- Good dose of humility and the willingness to grow (no matter your seniority!).
- Fluent in English (French is not mandatory!).
Environment
- The scope of this role includes both the production environment and internal IT
- Sites in Paris, London, Toronto and NYC
- MacOS, Windows, Linux
- GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault
- Okta, Oauth, JWT, C#, .NET Core, TypeScript, React
- Vanta (GRC), Riot (awareness), Google Workspace (office), Jumpcloud (MDM and SSO), Hibob (HRIS), Slack (IM), GitHub (VCS), CircleCI / ArgoCD (CI/CD) HackerOne (Bug Bounty program), Datadog (SIEM), 1Password (password manager)
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
11
4
0
Categories:
Analyst Jobs
Compliance Jobs
Tags: C CI/CD CircleCI CISO Compliance GCP GitHub Governance ISO 27000 ISO 27001 Kubernetes Linux MacOS Okta PostgreSQL Risk analysis SaaS Security assessment SIEM SOC SOC 1 SOC 2 SSO Terraform TypeScript Windows
Region:
Europe
Countries:
France
United Kingdom
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Security Analyst jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsSenior Network Security Engineer jobsInformation Security Specialist jobsSenior Cybersecurity Engineer jobsSecurity Consultant jobsSenior Penetration Tester jobsIT Security Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Cyber Security Engineer jobsCyber Security Specialist jobsChief Information Security Officer jobsStaff Security Engineer jobsIT Security Analyst jobsInformation System Security Officer (ISSO) jobsPrincipal Security Engineer jobsCloud Security Architect jobsCyber Security Architect jobsSystems Engineer jobsSecurity Operations Analyst jobsSenior Product Security Engineer jobsSenior Information Security Engineer jobs
CI/CD jobsSaaS jobsMalware jobsForensics jobsEncryption jobsEDR jobsIDS jobsSplunk jobsTop Secret jobsIPS jobsRMF jobsSDLC jobsSQL jobsIntrusion detection jobsBash jobsCompTIA jobsThreat detection jobsDoDD 8570 jobsOWASP jobsITIL jobsFinance jobsDocker jobsActive Directory jobsTCP/IP jobsCRISC jobs
IT infrastructure jobsGIAC jobsVPN jobsHIPAA jobsUNIX jobsBanking jobsTerraform jobsClearance Required jobsSANS jobsJavaScript jobsDNS jobsPolygraph jobsSOX jobsCISO jobsOSCP jobsAnsible jobsCCSP jobsMITRE ATT&CK jobsSOC 2 jobsJira jobsGCIH jobsData Analytics jobsCryptography jobsCyber defense jobsSOAR jobs