Le poste
03THE ROLE
The Information Security Officer (ISO) partners closely with the Head of IT Security & Compliance to shape and execute Corintis’ information security program. The ISO plays a key role in Governance, Risk, and Compliance (GRC) management, developing and implementing security requirements and controls that align with business goals, customer expectations, and applicable compliance standards. This role is responsible for performing risk assessments, conducting gap analyses, and contributing to metrics and key performance indicators (KPIs) that measure the maturity and effectiveness of Corintis’ security posture. As a champion of proactive risk management and a strong security culture, the ISO ensures that information security best practices are integrated across all areas of the organization.
01Partner with the Head of IT Security & Compliance to define and execute Corintis’ information security program.
02Support the development and continuous improvement of the company’s security framework.
03Define and track Key Performance Indicators (KPIs) to evaluate the maturity and effectiveness of the security program.
04Prepare and present risk, compliance, and performance reports to senior leadership and relevant committees.
05Support ongoing compliance with key standards such as ISO 27001, SOC 2, and GDPR.
06Collaborate across functions—particularly with R&D, Customer Success, IT, and Operations.
07Continuously review, refine, and strengthen existing governance and security practices.
08Lead and perform regular risk assessments, compliance gap analyses, and internal audits to identify security weaknesses and recommend remediation.
09Support customer and third‑party due diligence activities.
10Maintain the corporate risk register, documenting identified risks, mitigation strategies, and resolution progress.
11Ensure executive visibility of key risks and risk trends through structured reporting and stakeholder communication.
12Monitor and evaluate the security compliance of business operations.
13Design and implement pragmatic, fit‑for‑purpose security controls.
14Oversee the operation and continuous improvement of Corintis’ Information Security Management System (ISMS).
15Track relevant standards and evolving customer, industry, and regulatory requirements.
16Partner with legal, privacy, and compliance teams to manage contractual and regulatory aspects of information security.
17Serve as a visible advocate for information security across the organization, fostering a culture of accountability and awareness.
18Contribute to the company’s ongoing security awareness initiatives, including training sessions and targeted communications.
19Promote a risk‑conscious mindset across all departments to ensure security principles are applied consistently throughout the business.
20Support the incident response process, coordinating with internal and external stakeholders.
21Participate in post‑incident reviews to identify lessons learned and propose continuous improvements to processes and controls.
22Provide leadership with timely reports on incident trends, risk metrics, and recommendations to enhance organizational resilience.