Pigment Logo

Pigment

Security Analyst (GRC Specialist)

Posted 3 Hours Ago
Be an Early Applicant
Hybrid
2 Locations
Senior level
Hybrid
2 Locations
Senior level
The Security Analyst (GRC Specialist) will lead governance, risk, and compliance initiatives, implement security policies, oversee vendor assessments, and manage compliance audits. The role requires collaboration with various teams, advocating for security best practices, and maintaining compliance with standards such as ISO 27001.
The summary above was generated by AI

Our Story So Far


Since our founding in 2019, Pigment has become one of the fastest-growing SaaS companies in the world today. Our product, a highly efficient Enterprise Performance Management (EPM) platform, is helping companies achieve their financial goals by quickly responding to dynamic factors in their respective markets including Tech, Retail, CPG & Financial Services. 


In less than 5 years, Pigment has grown to over 450 employees across offices in New York, Toronto, London & Paris and attracted a total of $393M in investment from some of the top Venture Capital firms globally.

We serve companies including Unilever, Deliveroo, Gong and Brex to name a few!


We are looking for a Governance, Risk and Compliance specialist, whose core focus will be to protect our customers' and compliance data.

Key Responsibilities

  • Strategic Leadership

  • Under the coordination of the CISO, participate in the definition of a multi-year, risk-driven security roadmap, design policies, processes and guidance documents driving its implementation

  • Implementing the security roadmap, either autonomously or with support from other engineering teams, either in a delivery or project management capacity, depending on the project’s technical requirements.

  • Establish and implement company-wide security policies and procedures covering internal IT, production platforms, facilities, and more.

  • Improve and maintain the risk analysis and its mitigation planDesign and implement a comprehensive reporting framework of security indicators

  • Operational Excellence

  • Drive implementation of the security roadmap, leading initiatives and coordinating with engineering teams or other relevant stakeholders (legal, HR, support, customer experience

  • Oversee vulnerability remediation, including triage, prioritization, and mitigation follow up.

  • Oversee vendor security assessments and ensure alignment with compliance requirements, deliver security approvals in the procurement process

  • Participate in the asset management program (contractors, accounts, datasets, etc.) 

  • Compliance Management

  • Lead certifications renewals for SOC 1, SOC 2, and contribute to acquisition of new certification (e.g., ISO 27001, ISO 27701)

  • Lead planning and execution of compliance audit programs conducted both internally and externally.

  • Maintain and enhance compliance programs, collaborating cross-functionally to ensure adherence.

  • Coordinate with the Sales and Legal teams to understand the legislative landscape and market requirements in terms of compliance.

  • Advocacy and Training

  • Design and implement security awareness training programs and champion best practices across teams (onboarding training, awareness training, phishing simulations, developer trainings)

Experience & Expertise

  • At least 5 years of experience on governance and compliance topics, either as Security Engineer, Security Project Manager, or compliance officer (of course, you can be way more experienced!)

  • Extensive knowledge and experience with the ISO27000 series standard: implementation experience in obtaining and maintaining is a plusSolid technical background in security engineering

  • Great team spirit with a problem-solving, can-do attitude.

  • Good dose of humility and the willingness to grow (no matter your seniority!).

  • Fluent in English (French is not mandatory!).

Environment

  • The scope of this role includes both the production environment and internal IT
  • Sites in Paris, London, Toronto and NYC 
  • MacOS, Windows, Linux
  • GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault
  • Okta, Oauth, JWT, C#, .NET Core, TypeScript, React
  •  Vanta (GRC), Riot (awareness), Google Workspace (office), Jumpcloud (MDM and SSO), Hibob (HRIS), Slack (IM), GitHub (VCS), CircleCI / ArgoCD (CI/CD) HackerOne (Bug Bounty program), Datadog (SIEM), 1Password (password manager)

Pigment is an equal opportunity employer. We believe diversity is a strength and fosters innovation. We are committed to enabling everyone to feel included and valued at the workplace. All qualified applicants will receive consideration for employment without regard to age, color, family, gender identity, marital status, national origin, physical or mental disability, sex (including pregnancy), sexual orientation, social origin, or any other characteristic protected by applicable laws. We may process your personal data in accordance with our HR Data Protection Notice.

Top Skills

.Net Core
C#
GCP
Jwt
Kubernetes
Oauth
Okta
Postgres
React
Singlestore
Terraform
Typescript
Vault

Similar Jobs

Be an Early Applicant
21 Hours Ago
Paris, Île-de-France, FRA
750 Employees
Mid level
750 Employees
Mid level
eCommerce • Information Technology • Retail • Software
The Business Value Consultant will support Sales teams by delivering impactful business cases and presentations to C-level prospects. The role involves building knowledge benchmarks, specializing in vertical industries, supporting internal stakeholders, and contributing to transversal projects. The consultant will work closely with various departments to create strong value propositions and impact high-value deals.
Be an Early Applicant
2 Days Ago
Paris, Île-de-France, FRA
5,000 Employees
Senior level
5,000 Employees
Senior level
Artificial Intelligence • Information Technology • Natural Language Processing • Software • Business Intelligence • Generative AI
The Senior Analyst, Technical Success Manager at Qualtrics will assist clients in optimizing their use of the Qualtrics platform, offering technical insights and recommendations to drive customer adoption and success. This role requires building strong relationships with clients, managing multiple projects, and providing strategic guidance throughout the customer lifecycle.
Be an Early Applicant
2 Days Ago
Paris, Île-de-France, FRA
Remote
Hybrid
4,700 Employees
Mid level
4,700 Employees
Mid level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
As a Sr Data Analyst at Dynatrace, you will analyze complex data sets to provide insights that improve client performance and user experiences. Your responsibilities include account management for multiple clients, conducting detailed data analysis, and collaborating with internal teams on Digital Experience Monitoring projects. You will help clients understand and optimize their digital performance using data.

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account