Security Lead

Posted 2 Days Ago
Be an Early Applicant
Paris, Île-de-France, FRA
Hybrid
Senior level
Healthtech • Insurance
The Role
Lead and grow Alan's security team, define AI security posture and governance, manage ISMS and ISO 27001 certification, navigate multi-country health regulations, run risk cartography and vendor assessments, and align security with Product, Engineering, Legal, DPO, and Risk.
Summary Generated by Built In
Health can’t wait.

Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t.

Alan exists to end the wait.

Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way.

So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience.

We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR.

Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond.

The team and your missions

You will lead Alan's Security team, a highly technical group operating across 10+ countries in a regulated health insurance environment. As Security Lead, your missions span four core areas:

  • Lead and grow the security team: Coach, structure, and elevate a team of security experts. Set clear priorities, define ownership, and create conditions for genuine professional growth.

  • Own security in the AI era: Define Alan's posture on AI-driven threats and opportunities. Build frameworks that let product and engineering teams ship AI-powered features safely and at speed.

  • Scale security across 10+ countries: Own the ISMS and certification programme (ISO 27001), navigate a complex multi-regulatory environment (DORA, HDS, RGPD, NIS2, PGSSI-S), and ensure Alan's security programme keeps pace with its geographic expansion.

  • Build and evolve Alan's security strategy: Position security as a long-term business asset and trust-builder for members, regulators, and partners. Align Legal, DPO, Risk, Engineering, and Product on security requirements, and build a security culture that empowers rather than restricts.

     
The challenge

Alan is a fast-growing health insurer operating in a uniquely complex environment. The challenges you will navigate include:

  • A shifting threat landscape: AI is reshaping both attack vectors and defensive possibilities. You will need a clear point of view on LLM security, agent risks, and AI governance, and the ability to translate that into concrete, actionable priorities.

  • Multi-country regulatory complexity: Operating across 10+ countries means managing a dense, evolving regulatory stack (DORA, HDS, RGPD, NIS2, PGSSI-S) while keeping the business moving. You will need to translate regulatory requirements into technical controls without creating bottlenecks.

  • Health sector specifics: Alan handles sensitive health data at scale. This comes with sector-specific requirements (ANS framework, CERT Santé, HDS) that demand both technical precision and operational rigor.

  • Influencing at scale without direct authority: Security touches every function. Your ability to align Legal, DPO, Risk, Engineering, Product, and Operations, and make them come to you early, will be as important as your technical depth.

  • Running security as a living programme, not a compliance exercise: The goal is not to pass audits. It is to build a programme that feeds real decisions, scales with the company, and earns genuine trust.

Who we are looking for
  • Proven experience leading a security (or security-adjacent) team, with concrete examples of people development and growth

  • At least one full ISO 27001 certification or recertification cycle led end-to-end

  • Solid understanding of the regulatory stack relevant to Alan's context: DORA, HDS, RGPD, NIS2, PGSSI-S

  • Experience running security risk cartography, ideally with EBIOS RM- Experience conducting vendor security assessments and defining contractual security requirements

  • Clear understanding of AI security: LLM threats, agent risks, AI governance frameworks (OWASP LLM Top 10, MITRE ATLAS, EU AI Act)

  • Full professional fluency in English required; French is a plus

  • Bonus: experience in a regulated health sector environment (ANS framework, CERT Santé, HDS)

     

This position targets level F+ on our level grid.

 
How we work

Location: You must be legally eligible to work from France. We offer remote work flexibility, but we value in-person collaboration

 
🎯 Important note: we hire people, not roles.

If you're excited about this opportunity but don't check every box, we'd love to hear from you. Everyone, no matter how underrepresented, should feel free to apply, as it can only bring learnings or success.

If you identify yourself as a woman: Did you know that research shows women often apply only when meeting 100% of requirements?

Remember, this is just a guide, not a checklist. We'll be thrilled to receive your application!

 

🔖 Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info.

 
You want to know more about Alan?

🙌 Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high-quality time with co-workers.

🤘A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of cultural values that guide our approach to work

Skills Required

  • Proven experience leading a security (or security-adjacent) team with people development examples
  • At least one full ISO 27001 certification or recertification cycle led end-to-end
  • Ownership and operation of an ISMS
  • Solid understanding of DORA, HDS, RGPD, NIS2, PGSSI-S
  • Experience running security risk cartography
  • Experience with EBIOS RM
  • Experience conducting vendor security assessments and defining contractual security requirements
  • Clear understanding of AI security: LLM threats, agent risks, AI governance frameworks (OWASP LLM Top 10, MITRE ATLAS, EU AI Act)
  • Full professional fluency in English
  • French language skills
  • Experience in regulated health sector (ANS framework, CERT Sante, HDS)
  • Legal eligibility to work from France
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Paris
1,113 Employees
Year Founded: 2016

What We Do

Alan is your one stop health partner. We give everyone access to a healthy & productive life, empowering the body and the mind. Our services include the most intuitive health insurance offering, our Alan Clinic to navigate the healthcare system and Alan Mind, our mental well-being offer among other things! We cover more than 400.000 members and are partners of 20.000 companies for the health of their employees. With Alan, people are healthier, happier and more productive. We are the first new independent insurance licensed in France since 1986 by the French Prudential Supervisory Authority (ACPR). We operate in 🇫🇷, 🇧🇪 and 🇪🇸. Alan has raised more than €490 million

Similar Jobs

Proton Logo Proton

Product Security Lead

Information Technology • Software • Cybersecurity
In-Office
4 Locations
657 Employees

Braze Logo Braze

Account Executive

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
Paris, Île-de-France, FRA
2000 Employees

SailPoint Logo SailPoint

Sales Executive

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
France
2461 Employees
68K-102K Annually

Zscaler Logo Zscaler

Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
Ville-Lumière, Paris, Île-de-France, FRA
8697 Employees
81K-115K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account