Jobs and Careers
SC

Information Security Risk & Compliance Manager (Flex)

Scaleway
Francefull_timeVerifiedPosted 24 Aug 2023

About the role

Our mission 🚀
Founded in 1999, Scaleway, the cloud of choice, helps developers and businesses to build, deploy and scale applications to any infrastructure. Located in Paris, Amsterdam and Warsaw, Scaleway’s complete cloud ecosystem is used by 25,000+ businesses, including European startups, who choose Scaleway for its multi-AZ redundancy, smooth developer experience, carbon-neutral data centers and native tools for managing multi-cloud architectures. With fully managed offerings for bare metal, containerization and serverless architectures, Scaleway brings choice to the world of cloud computing, offering customers the ability to choose where their customer’s data resides, to choose what architecture works best for their business, and to choose a more responsible way to scale.
Our journey 💡
We want all our actions and decisions to bring us closer to achieving our vision: building and scaling technologies that make sense to us, to our customers and their end users. Scaleway is the challenger nobody’s expecting.As our business scales, the customers and developers we serve are increasingly diverse and global. Giving them an unbeatable experience is central to our business strategy and value proposition. To better understand them, we've discovered that the best way to deliver the highest value and performance is by incorporating a well-rounded team that leverages diverse perspectives,  knowledge, skills, and cross-cultural understanding. 
Our values 💜
Singularity: We do it our own way. Community: One company, one cultureAdventure: Level up if you dare, never stop innovating. Leadership: Be the leader you want to follow.Excellence: We want to be customers' first choice as a cloud provider.Rock Solid: You can always count on us! 
About the job
The Information Security Risk & Compliance Manager is a member of the team who is responsible for developing and managing Scaleway’s compliance with various standards. As a key component of the PDCA cycle, the “Information Security Risk & Compliance” (ISRC) team is responsible for auditing internal teams, making process discoveries, managing internal and external audits, and ensuring that necessary organizational or technical requirements are implemented based on the identified gaps or improvement needs.In addition to this main responsibility, the ISRC Team is responsible for actively contributing to cybersecurity-related standards and policies. Reporting to the CIO, you will play a pivotal role in risk analysis and active project management to successfully handle the compliance roadmap (ISO 27001, SecNumCloud, HDS) for our Public Cloud offerings (IaaS/PaaS/IA/Bare Metal) rolled out across Europe.

Preferred Qualifications

  • Experience with recognized Information Compliance standards (ISO 27001, ISO 27005, SecNumCloud, HDS…)
  • Experience with Public Cloud and Hosting Technologies, as well as IT Service Provisioning
  • Ability to lead and integrate large teams of Engineers
  • Knowledge of at least one of the following certifications: PCI-DSS, HDS, ISO 27001, or SOC2
  • Understanding of topics related to technical architectures and cloud technologies (APIs, databases, microservices), as well as desktop environments
  • Excellent oral and written communication skills in both French and English, including the ability to summarize effectively.

Responsibilities

  • Based on Scaleway’s strategy and legal requirements, manage compliance with cybersecurity-related standards, legal and regulatory frameworks and conduct independent reviews to assess it.
  • Contribute to the development of Scaleway’s cybersecurity strategy and policy.
  • Supervise the application and improvement of the Information Security Management System (ISMS) of Scaleway
  • Plan, establish, implement, and maintain audit programs required to obtain and maintain cybersecurity-related certifications
  • Manage Scaleway’s cybersecurity-related risks aligned with the business strategy.
  • Ensure that cybersecurity-related risks remain at an acceptable level for Scaleway by proposing the most appropriate risk treatment options
  • Obtain new certifications (ISO 27001, SecNumCloud) and extend the scope of existing ones
Location
This position can be either: based in our offices in Paris or Lille (France)
Recruitment Process 
Screening call - 30 mins with the recruiter Manager Interview - 45 minsTechnical InterviewsTeam InterviewHR Interview - 45 minsOffer sent - 48 hours
On average our process lasts 2-3 weeks and offers usually follow within 48 hours 🤞
Important note: if you don't see yourself ticking all the boxes don't hesitate to apply anyway. Don't limit yourself to a job description, you never know! 
To learn more about us 🌐Scaleway website  | Scale