
Ivalua · France
Manager Sécurité Applicative Senior (H/F) (Massy - France) Créée en 2000, Ivalua est un leader mondial dans l’édition de solutions cloud de gestion des achat...
Manager Sécurité Applicative Senior (H/F)
(Massy - France)
Créée en 2000, Ivalua est un leader mondial dans l’édition de solutions cloud de gestion des achats.
Chez Ivalua, nous sommes une communauté mondiale d'experts convaincus que la transformation numérique rend les chaînes
d'approvisionnement plus durables et résilientes, tout en améliorant la collaboration avec les fournisseurs. Nous y parvenons
grâce à notre plateforme cloud de gestion des dépenses, qui permet à des centaines de grandes marques de gérer leurs dépenses et
leurs fournisseur tout en optimisant leur rentabilité, leur performance ESG (Environnement, Sociale et Gouvernance), de réduire
les risques et d’améliorer leur productivité. Animés par nos passions et nourris par nos ambitions communes, nous nous donnons les
moyens de relever les défis et de créer des expériences impactantes pour nos clients et notre écosystème partenaire, tout en
donnant du sens à nos équipes.
Découvrez en plus sur www.ivalua.com. Suivez-nous sur LinkedIn
CONTEXTE : Vous ferez partie de l'équipe InfoSec avec pour mission de construire, maintenir et améliorer continuellement la
sécurité de notre application, offrant ainsi l'assurance de protection et de sécurité à nos clients. Notre équipe est
opérationnelle, avec un fort esprit de résolution de problèmes, capable de penser de manière holistique à la mise en œuvre et de
fournir des solutions pour relever les défis à long terme de nos clients. .
RÔLE : En tant que Senior Manager AppSec, vous consacrerez une part majeure de votre rôle au pilotage, à la stratégie et à la
gestion du programme de sécurité applicative, tout en restant le pilier technique et le soutien de l'équipe opérationnelle. Votre
mission sera de repenser, structurer et diriger notre programme AppSec à l'échelle mondiale.
Nous recherchons un(e) Senior Manager AppSec stratégique et technique pour orchestrer la sécurité de notre application SaaS ainsi
que de l'écosystème internet-facing d'Ivalua. Ce rôle hybride nécessite une forte collaboration avec la R&D (Solution Owners,
Framework Architects, Dev Leads) afin d'intégrer la sécurité dès la genèse de chaque nouveau produit.
Vous serez garant(e) de la priorisation des tâches face aux défis de bande passante, de la gestion des escalades clients complexes
et de l'automatisation des processus de détection en tirant parti des technologies de pointe.
transparente dans les processus de la R&D pour tout nouveau développement de produit
profondeur technique sur les sujets complexes
sécurité et fluidifier le cycle de vie du développement logiciel
optimisant l'usage de l'IA pour la détection et la remédiation
de correction
requêtes, identifier rapidement les points clés et vulgariser les concepts techniques de sécurité auprès des parties prenantes
Si vous avez une solide expérience en sécurité applicative, un leadership naturel et une vision stratégique de la DevSecOps, ce
rôle est fait pour vous.
directement avec des équipes de développeurs
processus de défense
rigueur méthodologique malgré les contraintes de temps
proposer des solutions holistiques durables
Si votre candidature correspond aux compétences souhaitées pour ce rôle, notre équipe de recrutement vous contactera pour
planifier un premier échange téléphonique. Faites un pas de plus vers la réalisation de vos objectifs - postulez dès aujourd'hui
!
Un recruteur dédié vous guidera à chaque étape du processus de recrutement. Nous sommes là pour vous accompagner!
Notre processus de recrutement est conçu pour évaluer vos compétences à travers une série d'entretiens personnalisés avec nos
équipes. Les entretiens se dérouleront virtuellement et en personne dans nos locaux.
passionnées par leur travail et guidées par une même vision,
valorisée,
team building),
Portés par nos différences - Votre énergie est notre force !
Unis par nos valeurs, nous célébrons la diversité et l’équité dans toute leur étendue pour construire un environnement de travail
inclusif. Pour aider nos clients à rendre leurs chaînes d’approvisionnement plus efficaces, durables et résilientes, nous comptons
sur nos équipes internationales aux parcours, compétences et perspectives divers et variés. Nous croyons en l’égalité des
opportunités et en la diversité comme moteurs d’innovation, favorisant un esprit d’inclusivité, un environnement de travail
productif et agréable, et en offrant des perspectives de carrière épanouissantes pour tous les Ivaluans.
Explorez la culture Ivalua - visionnez cette vidéo pour en savoir plus !
Senior Security Analyst - GRC (Massy - France) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. Learn more at www.ivalua.com. Follow us on LinkedIn THE OPPORTUNITY CONTEXT: You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity. ROLE: We are looking for a Senior Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives. WHAT YOU WILL DO WITH US * Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53 * Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams. * Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations. * Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them. * Lead or support internal and third party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring. * Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness. * Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc. YOUR PROFILE If you have the below experience and strengths this role could be for you: Skills and Experience: * At least 4 years of experience as Security Analyst GRC * Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR) * Direct experience managing audits, self-assessments, or risk assessments against one or more InfoSec frameworks listed above * Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis) * Familiarity with continuous compliance and monitoring platforms * Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams * Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments) * Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800-39) * Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired * Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus Soft Skills: * Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts * Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators. * Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast-paced environment * High degree of initiative, self-motivation, and ability to work independently with limited supervision WHAT HAPPENS NEXT If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today! Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you! Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role. Interviews will be conducted virtually via video or on-site with face-to-face meetings. LIFE AT IVALUA * Hybrid working model (3 days in the office per week) * We're a team dedicated to pushing the boundaries of product innovation and technology * Sustainable Growth, Privately Held * A stable and cash-flow positive Company since 10 years * Snacks and weekly lunches in the office * Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity * Unlock and unleash your full professional potential with our exceptional training and career development program * Join a dynamic and international team of top-notch professionals who are experts in their respective fields * Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work * Experience a truly diverse and inclusive work environment where your unique contributions are highly valued * Regular social events, competitive outings, team running events, and musical activities * Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua): Powered by People - Powered by You! United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/ Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us. #LI-MV1 #LI-HYBRID
About Mirakl: Founded in 2012, Mirakl has been at the forefront of marketplace innovation, empowering every business to compete in the platform economy. Today, Mirakl’s operating system combines an enterprise marketplace solution (Mirakl Platform) that enables retailers and B2B organizations to launch, scale, and operate marketplaces and dropship, AI-powered multichannel selling (Mirakl Connect), retail media (Mirakl Ads) and an agentic commerce infrastructure (Mirakl Nexus). With dual headquarters in Boston and Paris, Mirakl helps a global ecosystem of 450+ marketplaces (B2C and B2B) and a network of over 100k third-party marketplace sellers. Brands like Macy’s, Decathlon, Carrefour, Asos, and Airbus Helicopters use Mirakl to grow their businesses in new and remarkable ways. For more information, visit www.mirakl.com. Mirakl in Numbers: * 🗓️ Founded in 2012 | Member of French Tech Next40 * 👥 750+ employees in 9 offices worldwide: Paris, Barcelona, Bordeaux, Boston, London, Munich, New York, Sydney, Tokyo Our Values: Working at Mirakl means accelerating your career alongside ambitious, passionate, and supportive colleagues. We're proud of the diversity of backgrounds, perspectives, and experiences that make our teams unique. Our 5 values guide how we collaborate: * 💡 Work Hard Together: Teamwork and collaboration are the foundation of our success * 🏆 Get Things Done: We prioritize action and efficiency for impactful results * 🚀 Go Above & Beyond: We tackle challenges proactively and always aim for excellence * 🎓 Succeed Through Expertise: Knowledge sharing and continuous learning are core to our culture * 🤝 Satisfy & Empower Clients: We're committed to our clients' success THE TEAM YOU'LL JOIN You'll be part of our Security team within the Platform, Data & AI Security pillar, led by Maxime Lahaye, Senior Security Officer, based in Paris. AI is fundamentally transforming how we work, and you'll join a team at the forefront of this evolution. This is your opportunity to build the GRC infrastructure of tomorrow, where automation, scripting, and security converge to enable Mirakl's next phase of growth. This is a permanent position (CDI) based in Paris or Bordeaux, with 4 days on-site per week. YOUR IMPACT 1 · COMPLIANCE & CERTIFICATIONS — AUTOMATION-FIRST * Contribute to maintaining Mirakl's ISO 27001, ISO 27018 and SOC 2 certifications, leveraging automated GRC platforms to enable continuous compliance monitoring * Automate evidence collection, control monitoring and documentation workflows using modern GRC tooling, AI-powered agents and scripting (Python, N8N) * Help manage and evolve the ISMS (Information Security Management System), ensuring it reflects both regulatory requirements and Mirakl's evolving AI-driven operations 2 · AI GOVERNANCE * Co-design and evolve Mirakl's AI usage governance framework: acceptable use policies, data classification for AI inputs, shadow AI detection and AI vendor risk assessment * Maintain a live inventory of AI tools used across the company and contribute to the risk-based process for evaluating and onboarding new tools * Monitor the AI governance regulatory landscape and help adapt Mirakl's framework proactively 3 · SECURITY BY DESIGN ACROSS ALL COMPANY PROJECTS * Partner with Product and Engineering teams early in project lifecycles to embed security and compliance requirements from the start * Participate in risk reviews across product and platform initiatives, with specific attention to AI-related threat vectors (prompt injection, data leakage in LLMs, access control for models) WHAT YOU'LL BRING TO THE ROLE Experience: * Master's degree (Bac+5) * Minimum 3 years of experience in cybersecurity * You participated in ISO 27001 audit as a security contributor at least * Proven experience in scripting and automation (Python, N8N or equivalent) * Experience in a consulting firm or technology company is a plus * Strong understanding of compliance frameworks and security standards Skills: * Strong technical profile with hands-on experience developing scripts and automating processes * Proactive and autonomous, with strong organizational and problem-solving abilities * Excellent communication skills to engage both technical and non-technical stakeholders * Integrity and ethics as core values * Ability to work collaboratively in cross-functional teams * Experience with web application and cloud (SaaS) security is a plus TOOLS USED * Python * N8N * Drata * AWS, GCP * Office Suite / Google Workspace LANGUAGES * Fluent in French and conversational English OUR HIRING PROCESS 1. 30-40 minute call with a Talent Acquisition Specialist 2. 1-hour technical interview with the hiring manager 3. Two 45-minute values interviews using the STAR methodology The STAR method and structured interviews will hold no secrets for you. We welcome collaborators with their diverse perspectives and experiences to power us forward. These often far exceed conventional job requirements and help us create a culture of continuous learning. If you’re ready to join a global leader powering digital transformation for 450+ of the world’s most innovative retailers and B2B organizations. As part of our recruitment process, Mirakl processes your personal data to review and manage your application and, where appropriate, to consider your profile for future opportunities. You can exercise your data protection rights at any time, and as further detailed in our policies. For more information about how we process your personal data and your rights, please consult our Recruitment Privacy Notice, here in English and here in French. We may use Artificial Intelligence (AI) solutions to help streamline our hiring process, including screening applications, analyzing resumes, and assessing responses. While AI helps us work efficiently, all final hiring decisions are made by humans. For more information, visit our AI Guidelines for Candidates and Interviews.
ISO New England is seeking an experienced Cyber Security Analyst to support and enhance enterprise cloud, infrastructure, AI, and DevSecOps security initiatives. This role is responsible for proactively identifying vulnerabilities, compliance gaps, misconfigurations, and security risks across enterprise systems, cloud platforms, AI/ML environments, CI/CD pipelines, and regulated CIP environments. The ideal candidate will have strong experience in cloud security, vulnerability management, DevSecOps, AI security, and security compliance, with the ability to collaborate across technical teams to implement and maintain enterprise security standards. What we offer you: * A stable, mission-driven workplace where your impact truly matters * A highly engaged work environment that values inclusion, collaboration, and employee safety and wellbeing * Competitive compensation with a base salary + performance bonus * Robust benefits package, including: * Enhanced 401(k) and financial planning support * Tuition reimbursement and professional development * Wellness programs, including an onsite gym * Flexible work hours * Employee Business Networks * Free coffee at our onsite café * Hybrid work environment (3 days/week onsite) * Distance-based relocation assistance available * 5/6 person paid on-call rotation How you will make an Impact * Conduct cloud security assessments across AWS and Azure environments, including CSPM, CIEM, IAM, and container security reviews. * Integrate and support security controls within CI/CD pipelines and DevSecOps environments. * Assess and secure AI/ML systems, generative AI applications, and AI-enabled business solutions throughout their lifecycle. * Evaluate risks associated with AI model usage, training data, third-party AI services, and Large Language Model (LLM) integrations. * Implement AI governance controls to protect sensitive data and prevent unauthorized disclosure through AI platforms. * Develop security guardrails for AI adoption, including data classification, access controls, prompt security, and responsible AI usage. * Perform AI threat modeling to identify risks such as prompt injection, data poisoning, model manipulation, model theft, and insecure AI integrations. * Perform vulnerability assessments, configuration reviews, and remediation tracking across enterprise and CIP systems. * Review and validate baseline configurations, logging requirements, and compliance controls. * Evaluate network topology and infrastructure changes to determine CIP impact and SOC visibility requirements. * Partner with application development, cloud platform engineering, infrastructure, enterprise architecture, IAM, network, SOC, and business teams to integrate security into system design, projects, and operational processes. * Support phishing simulations, security awareness initiatives, AI security awareness training, and audit evidence collection. * Provide security recommendations and risk mitigation strategies for cloud, AI, and enterprise environments. * Support and maintain enterprise security platforms including CNAPP, EDR, vulnerability management, SIEM, DSPM, and cloud security monitoring tools. * Monitor evolving AI security risks, industry standards, and regulatory requirements. What we are looking for * Experience in cybersecurity, cloud security, security engineering, or AI security roles. * Experience with AWS and/or Azure cloud platforms. * Experience with container orchestration technologies including Amazon ECS and Amazon EKS. * Experience implementing security controls within CI/CD and DevSecOps environments. * Knowledge of AI security concepts, including securing generative AI applications, LLMs, AI governance, and AI risk management. * Familiarity with AI threats such as prompt injection, data leakage, model poisoning, model theft, and insecure AI APIs. * Knowledge of vulnerability management, cloud security, IAM, CSPM, and configuration management practices. * Experience with security monitoring and logging platforms. * Familiarity with Terraform, infrastructure-as-code, and policy governance frameworks such as OPA. * Understanding of data governance, data protection, and responsible AI principles. * Strong analytical, troubleshooting, communication, and collaboration skills. * Self-starter with the ability to work independently in a fast-paced environment. Desired not required * Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field. * Advanced degree such as a Master’s in Cybersecurity Management, Information Assurance, Artificial Intelligence, or related fields. * Industry cybersecurity, cloud security, and AI security certifications preferred, including: * ISC2 Certified Information Systems Security Professional (CISSP) * ISACA Certified Information Security Manager (CISM) * Amazon Web Services Certified Security – Specialty * Microsoft Azure Security Engineer Associate (AZ-500) * ISC2 Certified in AI Security (when available) * OWASP AI Security and LLM Security knowledge/training This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.). The expected salary range for this position is $127,000 - $150,000 per year. This role is also eligible for an annual performance bonus, comprehensive health insurance (medical, dental and vision), flexible spending and health savings accounts, a 401(k) plan with generous employer contributions and a student debt benefit, life and AD&D insurance, disability insurance, critical illness and hospital indemnity benefits, paid time off, paid leave, a wellness program, an employee assistance program and other great company perks. #LI-HYBRID