Talent.com
Didomi
Information Security AnalystDidomi • Paris,France
Information Security Analyst

Information Security Analyst

Didomi • Paris,France
Il y a 26 jours
Type de contrat
  • Temps plein
Description de poste

We are looking for an Information Security Analyst to join our Security & IT team and become the operational backbone of our ISO 27001 program. You will support the day-to-day work that keeps Didomi audit-ready year-round and run recurring security activities across the company.

This role is roughly 80% recurring compliance work: evidence collection, audit preparation, access reviews, vendor reviews, and security questionnaire responses. Leverage is the whole game. We want someone who reaches for automation and AI tooling as a default and who actively pushes back on process that no longer earns its keep, rather than someone who accepts that compliance work has to be slow or manual.

This role reports to the Security Manager.

The responsibilities are as follows:

ISO 27001 program and audit readiness

  • Help maintain and improve our ISO 27001 management system, ensuring controls remain effective, documented, and continuously evidenced.
  • Contribute to internal audits, surveillance audits, and recertification cycles, including the upcoming unified audit covering Didomi and recently acquired business units.
  • Track corrective actions, nonconformities, and continuous improvement initiatives, supporting the security team in driving them to closure.

Security operations and recurring activities

  • Carry out recurring activities on the security calendar in support of the security team, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles.
  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources, then work with the Security Manager to define remediation priorities and follow them through to closure.
  • Run periodic access reviews across critical systems (Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications), surfacing findings to the Security Manager and helping ensure they are remediated.

Cross-functional security support

  • Contribute to the security team's reviews of new tools, vendors, and SaaS applications for security and compliance risks before adoption.
  • Help the security team assess and harden internal workflows, with a particular focus on identity, access management, MFA, SSO, and data handling.
  • Support the security team on security questionnaires, RFPs, and customer due diligence requests.
  • Support the security team on broader initiatives such as AI governance, SaaS governance, and integration of acquired entities into the ISO scope.

Preferred skills & experience

  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally within a SaaS or technology company.
  • Solid working knowledge of ISO 27001, including Annex A controls, the audit process, and how to operationalize the standard rather than treat it as paperwork.
  • Hands-on experience with vulnerability management tools and access governance processes.
  • Hands-on experience with Vanta, including running ISO 27001 (or comparable) audits end-to-end on the platform.
  • Hands-on experience with the AWS security suite, in particular GuardDuty and Inspector, including triaging findings and proposing remediation priorities.
  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work. You should be able to walk us through concrete examples of what you have built or automated.
  • A strong bias toward removing process. You actively challenge controls, paperwork, and workflows that no longer earn their keep, and you propose lighter alternatives.
  • Strong written communication in English. You can explain security topics clearly to engineers, executives, and customers alike.
  • A pragmatic mindset: you favor controls that work in practice over controls that only look good on paper.

Nice to have

  • Experience supporting HIPAA or HITRUST programs, and comfort mapping requirements across frameworks.
  • Familiarity with cloud environments (AWS in particular) and with common SaaS administration (Google Workspace, Slack, identity providers).
  • Exposure to security questionnaire platforms and trust center tooling.

Tools you’ll work with on a regular basis

  • Compliance and GRC: Vanta
  • Cloud and security monitoring: AWS, AWS GuardDuty, AWS Inspector, AWS Security Hub
  • Identity and access: Google Workspace, SSO and MFA providers
  • Endpoint and device management: JAMF
  • Code and engineering: GitLab, GitHub
  • Collaboration and documentation: Slack, Notion, Google Workspace
  • SaaS governance and vendor review: internal review workflows and questionnaire tooling

Recruitment process

  • HR Screen with our Talent Acquisition Expert (~15 min, video) | Motivation, fit, logistics, salary
  • Hiring Manager Interview with our Security & IT Manager (~45 min, video) | ISO 27001 depth, mindset, ownership style
  • Case Study Presentation with our Security & IT Manager & CTO (~60 min, video)
  • Final Interview with our CTO (optional) (~30 min, video) | Strategic alignment
€48,000 - €60,000 a yearWe may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Créer une alerte emploi pour cette recherche

Information Security Analyst • Paris,France

Offres similaires

Analyste Soc - Spécialiste Dans La Cybersécurité H/F - €35.000 - €47.000 Par An

Kicklox - Plateforme de matching entre talents tech & porteurs de projetsMontrouge, France, FR
Temps plein

L'analyste SOC surveille et administre les solutions de sécurité, détecte et analyse les incidents. Voir plus

 • Offre sponsorisée

Information Security Officer

GoyardGentilly, France, FR
Temps plein

Join to apply for the Information Security Officer role at Goyard A house of artisanal tradition, Goyard is a French leather goods manufacturer, trunk maker and luggage maker, which has always be... Voir plus

 • Offre sponsorisée • Nouvelle offre

Ai Security Lead For Secure Ai Deployments

HermèsAubervilliers, France, FR
Temps plein

Dans un contexte de très forte croissance, la maison Hermès place la cybersécurité au cœur de ses préoccupations depuis de nombreuses années.Au sein du pôle Data, Technologies & Innovation, la ... Voir plus

 • Offre sponsorisée • Nouvelle offre

Senior Security Assurance Solutions Architect, Aws Security Assurance Services

Amazon Web ServicesGentilly, France, FR
Temps plein

DescriptionThe Security Assurance Services (SAS) team, a part of Amazon Web Services, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both interna... Voir plus

 • Offre sponsorisée • Nouvelle offre

Azure Sysops Engineer — Cloud Infra, Iam & Security

Dassault SystèmesGentilly, France, FR
Temps plein

Chez Devoteam M Cloud, le Cloud Microsoft fait partie de notre ADN.On accompagne chaque jour des centaines de clients — des PME les plus agiles aux grands groupes les plus exigeants — dans leur tra... Voir plus

 • Offre sponsorisée • Nouvelle offre

Application Security Analyst - $38 - $60 An Hour - Remote

AlignerrParis, France, FR
Temps plein

The Application Security Analyst will analyze security scenarios, classify vulnerabilities, and evaluate secure coding practices for AI systems. Voir plus

 • Offre sponsorisée

Cybersecurity Analyst Hf - €45.000 - €55.000 A Year

Approach People RecruitmentParis, France, FR
Temps plein

The Cybersecurity Analyst will monitor and analyze security events, manage incidents, and improve security processes.Requires experience with security tools and standards. Voir plus

 • Offre sponsorisée

Expert Kubernetes Security - Hardening & Incidents

GazelTechGentilly, France, FR
Temps plein

Overview Expert en sécurité Kubernetes à Paris.Responsibilities Hardening des clusters Kubernetes Implémenter les contrôles de sécurité (RBAC, Network Policies) Déployer des outils de sécurité (Fal... Voir plus

 • Offre sponsorisée • Nouvelle offre

Genai Security Engineer

Capital Fund Management (CFM)Montrouge, France, FR
Temps plein

Are you passionate about application security and ready to serve as a subject matter expert in AI security? In this role, you’ll be instrumental in protecting our low-latency processing systems and... Voir plus

 • Offre sponsorisée • Nouvelle offre

Alternant(E) - Chargé(E) D'Études (H/F) - Sécurité De L'Information

Agpm KlesiaGentilly, France, FR
Temps plein

Intitulé du poste Alternant(e) - Chargé(e) d'études (H/F) - Sécurité de l'informationDescription de la missionAu sein de l'activité Grand Public de SFR et dans le cadre de la mise en œu... Voir plus

 • Offre sponsorisée • Nouvelle offre

Cybersecurity Architect

Airbus Defence and SpaceMontrouge, France, FR
Temps plein

Airbus Defence and Space SAS seeks a Cyber Security Architect to oversee secure architecture across Airbus projects, ensuring cybersecurity and regulatory compliance for new systems.You will conduc... Voir plus

 • Offre sponsorisée • Nouvelle offre

Devsecops Security Consultant: Implementations & Travel

AkamaiGentilly, France, FR
Temps plein

Join our highly-skilled Security Professional Services team.We provide managed services and proactive and reactive support to our global customers, integrating and maintaining Akamai solutions.Resp... Voir plus

 • Offre sponsorisée • Nouvelle offre

Iot Product Security & Compliance Lead

HagerGentilly, France, FR
Temps plein

Hager SE à Obernai recherche un Product Cybersecurity Manager pour assurer la conformité des produits connectés aux exigences de cybersécurité.Le rôle inclut la veille réglementaire, la définition ... Voir plus

 • Offre sponsorisée • Nouvelle offre

Architecte Sécurité Applicative Senior H/F -

SERMA Safety and SecurityGentilly, France, FR
Temps plein

Architecte sécurité applicative Senior H/F - (KSC/PSC/012026)Serma Safety & Securityest l’entité spécialisée dans la cyber sécurité du groupe SERMA qui est un acteur indépendant français dans l... Voir plus

 • Offre sponsorisée • Nouvelle offre

Cloud Security Engineer Senior F/H

Devoteam | Cyber TrustLevallois-Perret, France, FR
Temps plein

Présentation de l’entrepriseDevoteam est une entreprise de conseil en technologies, cloud, cyber, IA et développement durable.Avec plus de 11 000 collaborateurs dans plus de 25 pays, nous guidons n... Voir plus

 • Offre sponsorisée

Cyber Sec Analyst Sr Adv - $139,984 - $233,771.2 A Year

GciParis, France, FR
Temps plein

Experienced Cyber Security Analyst to ensure organization's information systems and networks are secure, analyzing cyber defense data, mitigating threats, and developing risk assessment techniq... Voir plus

 • Offre sponsorisée

Remote Cybersecurity Analyst & Ai Trainer — Shape Security - Up To $58 An Hour - Part Time - Remote

Shape SecurityParis, France, FR
Temps partiel

Freelance Cybersecurity Analyst needed to analyze security alerts and reports, with SOC and Microsoft Defender experience. Voir plus

 • Offre sponsorisée

Architecte Sécurité Aws & Cloud Devsecops

DevoteamGentilly, France, FR
Temps plein

Be among the first 25 applicantsGet AI-powered advice on this job and more exclusive features.Devoteam est une entreprise de conseil en technologies, cloud, cyber, IA et développement durable.Avec ... Voir plus

 • Offre sponsorisée • Nouvelle offre

Ai Security Engineer: Cloud & App Defense

Capital Fund ManagementGentilly, France, FR
Temps plein

Capital Fund Management (CFM) is looking for an AI Security Expert in Paris.You will protect our low-latency processing systems and work closely with multiple teams to embed security into our proce... Voir plus

 • Offre sponsorisée • Nouvelle offre

Application Security Research Engineer

CommITGentilly, France, FR
Temps plein

Application Security Research Engineer– Company is seeking an Application Security Research Engineer.In this role, you will lead a team of researchers and ethical hackers focused on offensive secur... Voir plus