AdTechTalent
Other7 days agoHybrid

Equativ

Senior GRC / ISO 27001 Program Lead [Freelance]

ISO 27001ISMScybersecurityGRCrisk analysisEBIOS RMISO 27005AI riskAI securitySOC 2NIST CSFTCF v2.2cloud securitypenetration testingsecurity auditsecurity awarenessgenerative AIAI toolsFrenchEnglish

Key details

Salary

Not specified

Employment type

Contract

Seniority

Senior

Years experience

10+

Location

Paris, Île-de-France, France

Full job description

Senior cybersecurity role responsible for leading the ISO 27001 certification program within 12 months. Tasks include defining the certification roadmap, building and operating the ISMS, managing the full audit cycle, conducting risk assessments including AI agent risks, implementing controls and audits, managing penetration tests, and collaborating cross-functionally with departments such as Legal, R&D, Finance, HR, and Ops. Requires 8-12 years experience in cybersecurity/GRC with significant ISO 27001 leadership, mastery of ISO 27001/27002, risk methodologies (EBIOS RM or ISO 27005), AI risk frameworks, and cloud security knowledge. Strong communication, leadership, and teamwork skills are essential. Fluent French and English required. On-site in Paris.

What you'll do

  • Define and own the ISO 27001 certification roadmap including milestones, deliverables, dependencies, workload plan
  • Build and operate the Information Security Management System (ISMS): policies, procedures, Statement of Applicability, risk treatment plan
  • Manage the full audit cycle: internal pre-audit, final certification audit, annual surveillance and renewal audits
  • Select and manage the certification body
  • Regular reporting to VP IT & Security and Executive Committee
  • Conduct and maintain risk assessments on critical assets using recognized methodologies
  • Analyze risks related to AI agents deployed within the company and define mitigation measures
  • Define, track and challenge remediation plans with technical and business teams
  • Implement permanent controls and ISMS internal audit program
  • Run recurring operational tasks in collaboration with application and system owners
  • Manage penetration tests and exploitation of their results
  • Lead management reviews and continuous improvement loops
  • Translate security topics for non-technical audiences
  • Design and roll out security awareness and training plans
  • Own responses to security questionnaires within RFPs and be primary contact for third-party audits
  • Collaborate closely with Legal, DPO, R&D, Product, Finance, HR, Ops and Cloud teams
  • Use generative AI tools daily to accelerate documentation, gap analysis, controls mapping, customer questionnaire handling and reporting
  • Promote AI usage best practices within security perimeter

Requirements

  • Minimum 8 to 12 years in cybersecurity / GRC
  • Significant experience leading an ISO 27001 certification end-to-end
  • Experience in international environments, ideally SaaS, AdTech, media or data-driven companies
  • In-depth mastery of ISO 27001 / 27002 and the ISMS
  • Operational mastery of at least one risk analysis methodology (EBIOS RM or ISO 27005)
  • Ability to conduct risk analysis on AI agents deployed internally (frameworks such as ISO/IEC 42001, NIST AI RMF, OWASP Top 10 for LLM, AI Act)
  • Solid knowledge of complementary frameworks (SOC 2, NIST CSF); knowledge of TCF v2.2 (AdTech) is a plus
  • Cross-functional understanding of Cloud security
  • Outstanding communication skills
  • Cross-functional teamwork
  • Cross-functional leadership, political acumen
  • Pragmatic, business and delivery-oriented mindset
  • Fluent in French and English, both written and spoken

Tech stack

ISO 27001ISO 27002EBIOS RMISO 27005ISO/IEC 42001NIST AI RMFOWASP Top 10 for LLMAI ActSOC 2NIST CSFTCF v2.2Cloud securitygenerative AI tools

Apply now

This MVP uses a placeholder application flow. In production, this section can connect to an external apply URL or a native application form.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.

TripleLift

Accountant

Detroit, Michigan, United States; New York, New York, United States19 days ago

$75K – $95K

accountingpayrollcompensation