Cybersecurity GRC Manager
An organization is looking for an experienced Cybersecurity GRC Manager to support them in strengthening their information security governance, risk management, and compliance approach. The consultant will join the cybersecurity team and work closely with the CISO, internal teams, external partners, and business stakeholders. The mission focuses on ISO 27001:2022, NIS2 compliance, risk management, audit preparation, and the continuous improvement of the Information Security Management System.
This role is ideal for a pragmatic GRC professional who combines strong documentation skills, security governance expertise, and the ability to work in a multi-stakeholder environment.
What you will do.
- Drafting and maintaining ISMS documentation, including security policies, operational procedures, and risk treatment plans.
- Supporting ISO 27001 certification activities, from gap analysis to audit preparation.
- Preparing internal and external audits and following up on non-conformities.
- Supporting NIS2 compliance initiatives for essential and important entities.
- Maintaining risk registers, control follow-up, and action plans.
- Using and administering a GRC tool such as CISO Assistant, OneTrust, ServiceNow GRC, Archer, or equivalent.
- Facilitating workshops with IT, business, and security stakeholders.
- Translating regulatory and security requirements into practical, actionable controls.
- Producing clear reports and dashboards for management and governance bodies.
- Supporting the CISO in structuring security governance across multiple stakeholders.
What they ask
- 3 to 5+ years of experience in GRC, information security compliance, or IT risk management.
- Strong knowledge of ISO 27001:2022, including ISMS lifecycle, Annex A controls, and audit requirements.
- Experience with NIS2 compliance or regulatory security frameworks.
- Experience in risk analysis methodologies such as ISO 27005, EBIOS RM, or equivalent.
- Ability to draft high-quality documentation in French: policies, procedures, risk treatment plans, audit reports.
- Understanding of GDPR and its connection with information security governance.
- Good understanding of IT infrastructure and cybersecurity concepts.
- Strong communication skills with technical teams, management, and business stakeholders.
- Ability to work autonomously and drive concrete deliverables.
Nice-to-have.
- Experience preparing or supporting ISO 27001 certification is highly valued.
- Experience with GRC tools such as CISO Assistant, OneTrust, ServiceNow GRC, or Archer is a plus.
- ISO 27001 Lead Implementer or Lead Auditor certification.
- Experience in MSP, consulting, or multi-client environments.
- Experience in regulated sectors such as public sector, energy, water, healthcare, finance, or critical infrastructure.
- Knowledge of CIS Controls, IEC 62443, ANSSI guidelines, or OT/IT environments.
- Technical English.
Profile
- You have at least 3 years of professional experience in IT.
- You are at least fluent in French, English is a plus.
- You are eager to learn, motivated, and curious.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.