Information Security & Compliance Manager
Would you like to contribute to strengthening the security, resilience, and compliance of a healthcare information system?
At Oticon/ITSA Medical, we develop, manufacture, and market bone-anchored hearing systems within an international organization. The group has a presence in several countries, with its main offices located in France and Sweden. At our Vallauris site (Sophia Antipolis), in the south of France, we specialize in the production of active implantable Class III medical devices and manage the worldwide distribution of the company’s complete product portfolio. The site also hosts an R&D team and the French sales organization.
Although the position is based in France, its scope extends across all geographies where the group operates.
As part of the development and security enhancement of the organization’s information system, and in the context of a newly created position, we are looking for an Information Security & Compliance Manager to define, deploy, manage, and continuously improve the technical, organizational, and human measures required to ensure the security, availability, integrity, and confidentiality of information, particularly personal health data.
The role will support full alignment of the information system with ISO/IEC 27001, GDPR requirements, and health data hosting standards, including HDS certification where applicable.
Reporting to senior management, your main responsibility will be to lead the global organization’s cybersecurity strategy, risk management framework, compliance roadmap, and continuous improvement of the Information Security Management System.
Main Tasks:
• Define, maintain, and deploy the Information Systems Security Policy and the ISO 27001-based Information Security Management System. • Ensure alignment with GDPR, ISO 27001, HDS, and healthcare data protection requirements.
• Lead cybersecurity risk management, including asset and risk mapping, EBIOS RM analysis, Statement of Applicability, and risk treatment plans. • Report regularly to senior management on cybersecurity risks, compliance status, key indicators, dashboards, and roadmap progress.
• Define and oversee secure architecture, infrastructure, identity and access management, monitoring tools, encryption, and certificate management. • Supervise backup, business continuity, disaster recovery, incident response, and cyber crisis exercises, including ransomware and data exfiltration scenarios.
• Prepare and support audits, penetration tests, vulnerability scans, remediation plans, and threat monitoring activities.
• Deploy cybersecurity awareness initiatives and manage security requirements for suppliers and subcontractors, including contracts and audits.
Work closely with the DPO, IT, medical leadership, operations, and key stakeholders.
Profile:
Required Skills:
• Master's degree (Bac+5) in Engineering, Cybersecurity, or Information Systems Security, or equivalent
• 5–10 years of experience as a CISO or in a similar information security leadership role
• Proven hands-on experience leading an ISO 27001 Information Security Management System (ISMS), including full end-to-end project management responsibility
• Strong command of relevant frameworks and standards: GDPR, ISO 27001, HDS, EBIOS RM
• Solid technical expertise: secure architecture, IAM management, SOC/SIEM, PKI, vulnerability management and cyber crisis management
• Strong soft skills: leadership, executive-level communication, and the ability to translate complex technical topics for senior management/Executive Committee (COMEX)
• Knowledge of AI, generative AI security risks, AI governance, and responsible AI principles, with the ability to support secure and compliant adoption of AI solutions.
Desired Skills:
• ISO 27001 Lead Implementer and/or Lead Auditor certification.
• CISSP, CISM, CEH, EBIOS RM, or equivalent cybersecurity certification.
• Experience in healthcare, medical technologies, regulated environments, or health data protection.
• Knowledge of HDS requirements and healthcare cybersecurity constraints.
• Experience coordinating suppliers, audits, security committees, or cyber crisis exercises.