Apply now »

Information Security & Compliance Manager

Because sound matters

Oticon Medical is a global company in implantable hearing solutions, dedicated to bringing the power of sound to people at every stage of life. For more than a decade, we have made bone anchored hearing systems more accessible by simplifying the treatment for physicians, audiologists, and patients alike.

We believe that patients and hearing care professionals should be able to choose the best possible solution at any time along the patient journey. We call it “Freedom of Choice” and it has always been paramount to Oticon Medical. This is the reason why our solutions are designed to be compatible whenever possible. As a result, an implant from Oticon Medical stands as a true testament to our unwavering lifelong support.

We work collaboratively with professionals to ensure that every solution we create is designed with our users’ needs in mind. We have a strong passion to provide innovative solutions and support that enhance quality of life and help people live life to the fullest – now and in the future.

Because we know how much sound matters.

Would you like to contribute to strengthening the security, resilience, and compliance of a healthcare information system?

At Oticon/ITSA Medical, we develop, manufacture, and market bone-anchored hearing systems within an international organization. The group has a presence in several countries, with its main offices located in France and Sweden. At our Vallauris site (Sophia Antipolis), in the south of France, we specialize in the production of active implantable Class III medical devices and manage the worldwide distribution of the company’s complete product portfolio. The site also hosts an R&D team and the French sales organization.

Although the position is based in France, its scope extends across all geographies where the group operates.

As part of the development and security enhancement of the organization’s information system, and in the context of a newly created position, we are looking for an Information Security & Compliance Manager  to define, deploy, manage, and continuously improve the technical, organizational, and human measures required to ensure the security, availability, integrity, and confidentiality of information, particularly personal health data.

The role will support full alignment of the information system with ISO/IEC 27001, GDPR requirements, and health data hosting standards, including HDS certification where applicable.

Reporting to senior management, your main responsibility will be to lead the global organization’s cybersecurity strategy, risk management framework, compliance roadmap, and continuous improvement of the Information Security Management System.

Main Tasks:

• Define, maintain, and deploy the Information Systems Security Policy and the ISO 27001-based Information Security Management System. • Ensure alignment with GDPR, ISO 27001, HDS, and healthcare data protection requirements.

• Lead cybersecurity risk management, including asset and risk mapping, EBIOS RM analysis, Statement of Applicability, and risk treatment plans. • Report regularly to senior management on cybersecurity risks, compliance status, key indicators, dashboards, and roadmap progress.

• Define and oversee secure architecture, infrastructure, identity and access management, monitoring tools, encryption, and certificate management. • Supervise backup, business continuity, disaster recovery, incident response, and cyber crisis exercises, including ransomware and data exfiltration scenarios.

• Prepare and support audits, penetration tests, vulnerability scans, remediation plans, and threat monitoring activities.

• Deploy cybersecurity awareness initiatives and manage security requirements for suppliers and subcontractors, including contracts and audits.

Work closely with the DPO, IT, medical leadership, operations, and key stakeholders.

Profile:

Required Skills:

• Master's degree (Bac+5) in Engineering, Cybersecurity, or Information Systems Security, or equivalent

• 5–10 years of experience as a CISO or in a similar information security leadership role

• Proven hands-on experience leading an ISO 27001 Information Security Management System (ISMS), including full end-to-end project management responsibility

• Strong command of relevant frameworks and standards: GDPR, ISO 27001, HDS, EBIOS RM

• Solid technical expertise: secure architecture, IAM management, SOC/SIEM, PKI, vulnerability management and cyber crisis management

• Strong soft skills: leadership, executive-level communication, and the ability to translate complex technical topics for senior management/Executive Committee (COMEX)

• Knowledge of AI, generative AI security risks, AI governance, and responsible AI principles, with the ability to support secure and compliant adoption of AI solutions.

Desired Skills:

• ISO 27001 Lead Implementer and/or Lead Auditor certification.

• CISSP, CISM, CEH, EBIOS RM, or equivalent cybersecurity certification.

• Experience in healthcare, medical technologies, regulated environments, or health data protection.

• Knowledge of HDS requirements and healthcare cybersecurity constraints.

• Experience coordinating suppliers, audits, security committees, or cyber crisis exercises. 

Apply now »