Security Governance Associate

contentsquare
Paris Area, France
On-site
Full-time
Posted 8 days ago
Security Trust

Job Description

Security Governance Associate

Contentsquare is looking for a Security Governance Associate to be a part of the Security Team. As part of the Security Team, you will be reporting directly to the Security Governance Specialist. Contentsquare’s Security Team sits within the global trust team  and is responsible for the oversight, guidance and business enablement of security aspects within Contentsquare and its acquired company products, teams and customers. 

You will work out of our Paris or Barcelona office. Contentsquare provides a SaaS service and commits to the highest security level for its customers. Contentsquare is ISO 27001,ISO 27701, ISO 27017 and ISO 27018 certified and deployed many security initiatives during the last year (SOC 2 Type 2 report, penetration testing, private bug bounty program, security awareness training for all employees, SIEM, etc.). 

Responsibilities

What you will do

As part of the Security Governance & Compliance Team, you will be responsible for:

  • Participating in maintaining our ISO 27001/27701/27017/27018 certifications, HIPAA and SOC 2 report. As well as any new framework we would go forward with.

  • Helping acquired companies integrate with Contentsquare’s security policies and practices

  • Taking part in internal, external, customer and certification security audits

  • Contributing to periodic risk management activities such as internal risk assessments and third party security reviews

  • Deploying/merging our security practices, policies and certification with recently acquired companies

  • Handling the security governance tasks (bi-annual management review, risk analysis, monthly KPI, security awareness, supplier risk review)

  • Collaborating with other departments to improve the security of business processes (onboarding, offboarding, access management, business continuity, SDLC, incident management, etc.)

  • Actively promoting security awareness through the use of structured campaigns and initiatives

  • Helping ensure internal security controls are understood and consistently followed

  • Responding to prospects/customers on security topics before and during the life of customer contracts

  • Reviewing security clauses in legal contracts

  • Arrange the schedule of internal and external security scans, penetration testing, code vulnerability testing, etc.

  • Continually monitor emerging threats, understanding when a concern becomes a priority, and finding creative ways to mitigate these while achieving business goals

  • Respond to security incidents if they occur, working to investigate and remediate the impact swiftly

  • As part of Third-Party Risk Management (TPRM), perform security assessments and risk analyses on vendors

What we are looking for

  • Genuine interest in various security, governance, risks and compliance topics

  • Keen interest in AI technologies and AI security, with a desire to stay ahead of industry trends.

  • Comfortable taking ownership of projects and showcasing key accomplishments

  • Excellent interpersonal skills and a service ethic

  • A track record of assisting business functions with technical internal and customer-facing requests that are prioritised appropriately

  • Ability to work quickly and independently in a fast-paced scale-up environment

  • Experience delivering risk assessments, security policies, processes and procedures, guidance, and training with empathy and understanding for a diverse remote team

  • Familiarity with internal/external security assessments and reviews, such as penetration testing, bug bounty programs, and internal vulnerability scans

  • A willingness to get stuff done in an enthusiastic, proactive, and resourceful manner that scales

  • Be passionate about information security!

  • Fluent in English (French is a plus!)

  • Requirements

    Specific requirements

  • Bachelor's and/or Master's degree in Information Systems Management or a related field.
  • Previous professional experience in Cybersecurity or Security GRC.
  • Strong project management skills.
  • Knowledge of ISO 27001, SOC 1, and SOC 2 frameworks is desirable.
  • Demonstrates rigor, autonomy, and a proactive mindset, with the ability to drive initiatives and bring forward new ideas.
  • Location: In our Paris (France) or Barcelona (Spain)

     

  • Ready to Apply?

    Take the next step in your career journey

    Apply Now

    Explore more

    Browse more jobs like this

    Work arrangement

    Disclaimer: Real Jobs From Anywhere is an independent platform dedicated to providing information about job openings. We are not affiliated with, nor do we represent, any company, agency, or agent mentioned in the job listings. Please refer to our Terms of Services for further details.