Cyber Security Engineer - Remote (Bilbao)

Cyber Security Engineer - Remote (Bilbao)

25 ago
|
Alan
|
Bilbao

25 ago

Alan

Bilbao

Health can't wait. But that’s exactly how healthcare works today. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way.
So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience.
We are on an incredible journey to build a general leading company, with a unique culture. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the broader Risk function. It's a highly collaborative role.
You are the accountable owner of the Information Security Management System: scope definition, Statement of Applicability, internal audit programme, and management review. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme is solid when the regulatory team negotiates with the ACPR or ANS.
You lead security risk cartography using EBIOS RM and ensure it feeds into, and is informed by,



the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table. You work closely with Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging) are designed with security requirements built in from the start. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive health data in day-to-day operations. You're a useful partner to Legal when the question is "what does this regulation actually require us to do technically?"
You classify and elevate ICT incidents internally, own BCP and DRP governance, and provide the security substance for DORA incident reports.
You'll work closely with Legal, DPO, Internal Audit, and the broader Risk function, and partner day‑to‑day with Infrastructure, Platform, Engineering, Product, and Operations. Direct Impact : You own the trust foundation that lets Alan handle health data for 1M+ members and operate in highly regulated markets. Complex Problems : 4 regulators across 4 countries, sensitive health data, and a regulatory landscape that keeps shifting (DORA, NIS2, AI Act), all to be modeled into a single, coherent control system.
You script evidence collection, automate control testing,



and connect GRC tooling to engineering pipelines. You've used Python or similar to reduce the manual work of an audit cycle, and you actively look for the next process to streamline.
You can administer platforms like CISO Assistant, ServiceNow GRC, or Archer, designing workflows, building dashboards, and making them genuinely useful for the teams that feed them data.
Speak cloud governance fluently. You understand shared responsibility in HDS-qualified environments, know what CSPM tools surface and what they miss, and can reason about policy-as-code (OPA, SCP) without needing an engineer to translate.
Read architecture well enough to challenge it. You can review a proposed architecture, identify control gaps in identity, network segmentation, encryption, or logging, and push back credibly with engineers even though you're not one.
Interpret vulnerability data and drive prioritisation. You know the difference between a finding that requires an emergency board call and one that belongs in a quarterly report.
You align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers or adversarial dynamics. You know where every commitment is, who owns it, and when it's due. You think in principles when frameworks shift. Remote work: We offer remote work flexibility, but we value in‑person collaboration.
Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info.
Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high‑quality time with co‑workers.
We have a set of cultural values that guide our approach to work.
#

📌 Cyber Security Engineer - Remote (Bilbao)
🏢 Alan
📍 Bilbao

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cyber security engineer - remote (bilbao) / bilbao

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cyber security engineer - remote (bilbao) / bilbao