- Company Name
- Altares - Dun and Bradstreet
- Job Title
- Analyste Sécurité – GRC (H/F)
- Job Description
-
Job Title: Security Analyst – GRC
Role Summary: Support the Cybersecurity team by managing governance, risk, and compliance (GRC) activities to strengthen the organization’s security posture.
Expectations: Minimum 5 years of proven experience in a GRC or security analyst role, deep knowledge of ISO 27001, DORA, NIS2, EBIOS‑RM, and GDPR frameworks. Proficient with GRC tools such as CISO Assistant, TrustHQ, Tenable, and advanced Excel. Strong written and verbal communication in French and English (C1 level); Dutch language skills are an advantage. Demonstrated project management, collaboration across functions, and proactive process improvement.
Key Responsibilities: • Assist the Head of Security in steering the Cybersecurity service.
• Define, update, and enforce security and compliance policies aligned with ISO 27001.
• Own GRC processes: risk identification, mitigation planning, action tracking, and reporting.
• Coordinate internal and external audits, and manage client questionnaire responses.
• Maintain and update security data for systems and products.
• Lead security awareness campaigns, training, and communication initiatives.
• Monitor regulatory compliance and maintain supporting documentation.
• Engage stakeholders to ensure consistent security practices across the enterprise.
Required Skills: • 5 + years of GRC or security analyst experience.
• Expertise in ISO 27001, DORA, NIS2, EBIOS‑RM, GDPR, and related standards.
• Hands‑on experience with GRC platforms (CISO Assistant, TrustHQ, Tenable) and Excel.
• Strong governance, risk management, and compliance knowledge.
• Excellent written and oral communication; ability to translate technical concepts for non‑technical audiences.
• Fluency in French and English (C1); Dutch is a plus.
• Project management aptitude, organization, and attention to detail.
• Collaborative mindset, cross‑functional teamwork, and proactive improvement focus.
• Solid security fundamentals and continuous learning attitude.
Required Education & Certifications: • Bachelor’s degree in Computer Science, Information Security, or related field.
• Professional certifications in ISO 27001 Lead Implementer, CISM, CISSP, or equivalent are highly desirable.