368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$56k – $70k per year
Location
Remote (France)
Seniority
Middle · 3+ years exp
Overview
Company
Impact
Profile match
Didomi is a leading provider of consent and preference management solutions for businesses around the world. Specializing in compliance with privacy regulations like GDPR and CPRA, Didomi helps organizations gather, manage, and streamline user consent across various digital platforms, including web, mobile, and connected TV. With products such as Consent Management Platforms (CMP) and Privacy Request tools, Didomi enables companies to build trust with their users through transparent data practices, while optimizing marketing performance and ensuring legal compliance.

We are looking for an Information Security Analyst to join our Security & IT team and become the operational backbone of our ISO 27001 program. You will support the day-to-day work that keeps Didomi audit-ready year-round and run recurring security activities across the company.

This role is roughly 80% recurring compliance work: evidence collection, audit preparation, access reviews, vendor reviews, and security questionnaire responses. Leverage is the whole game. We want someone who reaches for automation and AI tooling as a default and who actively pushes back on process that no longer earns its keep, rather than someone who accepts that compliance work has to be slow or manual.

This role reports to the Security Manager.

The responsibilities are as follows:

ISO 27001 program and audit readiness

  • Help maintain and improve our ISO 27001 management system, ensuring controls remain effective, documented, and continuously evidenced.
  • Contribute to internal audits, surveillance audits, and recertification cycles, including the upcoming unified audit covering Didomi and recently acquired business units.
  • Track corrective actions, nonconformities, and continuous improvement initiatives, supporting the security team in driving them to closure.

Security operations and recurring activities

  • Carry out recurring activities on the security calendar in support of the security team, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles.
  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources, then work with the Security Manager to define remediation priorities and follow them through to closure.
  • Run periodic access reviews across critical systems (Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications), surfacing findings to the Security Manager and helping ensure they are remediated.

Cross-functional security support

  • Contribute to the security team's reviews of new tools, vendors, and SaaS applications for security and compliance risks before adoption.
  • Help the security team assess and harden internal workflows, with a particular focus on identity, access management, MFA, SSO, and data handling.
  • Support the security team on security questionnaires, RFPs, and customer due diligence requests.
  • Support the security team on broader initiatives such as AI governance, SaaS governance, and integration of acquired entities into the ISO scope.

Preferred skills & experience

  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally within a SaaS or technology company.
  • Solid working knowledge of ISO 27001, including Annex A controls, the audit process, and how to operationalize the standard rather than treat it as paperwork.
  • Hands-on experience with vulnerability management tools and access governance processes.
  • Hands-on experience with Vanta, including running ISO 27001 (or comparable) audits end-to-end on the platform.
  • Hands-on experience with the AWS security suite, in particular GuardDuty and Inspector, including triaging findings and proposing remediation priorities.
  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work. You should be able to walk us through concrete examples of what you have built or automated.
  • A strong bias toward removing process. You actively challenge controls, paperwork, and workflows that no longer earn their keep, and you propose lighter alternatives.
  • Strong written communication in English. You can explain security topics clearly to engineers, executives, and customers alike.
  • A pragmatic mindset: you favor controls that work in practice over controls that only look good on paper.

Nice to have

  • Experience supporting HIPAA or HITRUST programs, and comfort mapping requirements across frameworks.
  • Familiarity with cloud environments (AWS in particular) and with common SaaS administration (Google Workspace, Slack, identity providers).
  • Exposure to security questionnaire platforms and trust center tooling.

Tools you’ll work with on a regular basis

  • Compliance and GRC: Vanta
  • Cloud and security monitoring: AWS, AWS GuardDuty, AWS Inspector, AWS Security Hub
  • Identity and access: Google Workspace, SSO and MFA providers
  • Endpoint and device management: JAMF
  • Code and engineering: GitLab, GitHub
  • Collaboration and documentation: Slack, Notion, Google Workspace
  • SaaS governance and vendor review: internal review workflows and questionnaire tooling

Recruitment process

    • HR Screen with our Talent Acquisition Expert (~15 min, video) | Motivation, fit, logistics, salary
    • Hiring Manager Interview with our Security & IT Manager (~45 min, video) | ISO 27001 depth, mindset, ownership style
    • Case Study Presentation with our Security & IT Manager & CTO (~60 min, video)
    • Final Interview with our CTO (optional) (~30 min, video) | Strategic alignment
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Paris
Cloud Engineer (AWS) 5 hours ago
In office • Full-Time • 5+ years exp • Bachelor's Degree • Dalian
Python
DevOps
AWS
CI/CD
CloudFormation
Docker
FinOps
GitHub Actions
Kubernetes
Terraform
GitHub
Apply
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$105k – $252k per year • Remote • Full-Time • 18+ years exp • Bachelor's Degree
Python
Java
Java
Gradle
DevOps
Ansible
AWS
CI/CD
CloudFormation
Configuration Management
Docker
GitHub Actions
GitLab CI
Helm
Jenkins
Kubernetes
Platform Engineering
Terraform
GitHub
GitLab
Cybersecurity
Sonatype Nexus IQ
Management
Confluence
Jira
Apply
Remote/Hybrid • Full-Time • 4+ years exp • Hong Kong
Node JS
JavaScript
Node JS
Nest.JS
Databases
Apache Kafka
Frontend
Vue.js
DevOps
AWS
Docker
Terraform
Amazon ECS
IoT
MQTT
Apply
$68k – $85k per year • In office • Full-Time • Master's Degree • San Jose
Python
AI/ML
AI Agents
DevOps
Amazon EC2
AWS
AWS Lambda
Bitbucket
CI/CD
CloudFormation
Docker
Git
Kubernetes
Terraform
Amazon S3
IAM
HPC
Cybersecurity
Least Privilege
Apply
In office • Full-Time • PhD • Paris
Node JS
JavaScript
Node JS
Commander.js
Apply
$45k – $115k per year (Estimated) • In office • Full-Time • 3+ years exp • Paris
Apply
$35k – $87k per year (Estimated) • In office • Full-Time • 3+ years exp • Paris
Analytics
Power BI
Apply
$51k – $92k per year (Estimated) • Remote/Hybrid • Internship • 5+ years exp • Paris
Apply
$63k – $119k per year (Estimated) • Remote • Full-Time • 6+ years exp • PhD • Paris
Node JS
JavaScript
Node JS
Commander.js
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.