Platform and Product Security Officer (F/H)
Role details
Job location
Tech stack
Job description
Mirakl is seeking a Compliance Security Officer to manage our compliance program. As a key member of our security team, in the GRC (Governance Risk & Compliance) pillar, you will be responsible for ensuring our adherence to security standards and regulations, including SOC2, ISO 27001, and ISO 27018, with the opportunity to expand to new standards.
The job is directly attached to the Chief Security & IT Officer with a wide autonomy. It will lead the candidate to interact with key functions at Mirakl, including C levels, Engineering & platform teams, data science & AI teams, and of course legal/compliance officers. It may involve supporting the sales cycles and prospects-facing activities.
Your responsibilities will include:
- Supporting the CISO in defining and managing the information systems security and compliance program.
- Maintaining and evolving documentation related to information security
- Implementing internal & external security audits.
- Contributing to the maintenance or implementation of compliance with security standards and applicable regulations, in coordination with the compliance officer.
- Leading certification audits (ISO 27001 / SOC 2)
- Piloting the ISMS (Information Security Management System) certified ISO 27001.
- Defining and managing the audit and control plan (internal and external).
- Maintaining the cybersecurity documentation repositories.
- Participating in risk analysis and implementation of risk treatment plans.
- Staying up to date on the IT security market, vulnerabilities, threats, and technologies.
Requirements
- Bac +5 - Master's degree
- Experienced with at least 3 years' experience in the field of GRC security.
- Experience in a consulting firm or equivalent role, or in a technology company is a plus.
- Professional English.
- Proactive, autonomous.
- Ability to work in a extended team.
- Integrity and ethics as core value.
- Sense of pedagogy and listening.
- Good oral and written communication.
- Rigor, organization, analytical skills and problem-solving.
Bonus (not required):
- Experience with web application and cloud (SaaS) security.
- Holds one or more professional security certifications (CISM, CISSP, ISO, etc.)