Head Of Cyber Governance Risk & Compliance
Job description
About the role
You will architect and own the end-to-end cyber governance, risk, and compliance strategy for Scaleway across all product lines and operational regions. You will define the security posture and resilience targets that align with our strategic business objectives and regulatory obligations. You will act as the central authority and trusted advisor on cyber risk for the executive committee and technology leadership. You will design and drive the implementation of a unified governance framework that integrates standards, policies, and controls. You will establish the mechanisms for continuous monitoring, measurement, and reporting of cyber risk to the board and senior stakeholders. You will ensure that our cyber risk management practices evolve in step with the threat landscape and emerging regulatory requirements. You will partner with business, product, and technology leaders to embed security and compliance into every initiative from conception to production. You will represent Scaleway as a responsible and reliable steward of customer trust and digital sovereignty.
Key facts
What you'll do
Develop and maintain a comprehensive cyber governance framework that defines risk appetite, tolerance, and escalation processes.
Own the enterprise risk register, drive its continuous update, and ensure that risk treatment plans are actioned and tracked to closure.
Champion the adoption of international and industry-standard frameworks such as ISO 27001, NIST, and GDPR to guide our security program maturity.
Design and implement a robust policy lifecycle, including creation, approval, publication, review, and retirement of security policies and standards.
Establish clear lines of accountability for cyber risk ownership across business units and technical teams, ensuring consistent application of controls.
Define and manage key risk indicators (KRIs) and key performance indicators (KPIs) to measure the effectiveness of the governance and risk management program.
Partner with legal, privacy, and regulatory teams to assess the impact of evolving laws such as the Digital Services Act, NIS2, and other relevant legislation.
Oversee third-party risk management, including due diligence, assessments, and ongoing monitoring of vendors and suppliers.
Lead the preparation of audit schedules, evidence collection, and remediation tracking for internal and external cybersecurity audits.
Drive the development and maintenance of incident response playbooks, ensuring alignment with business continuity and disaster recovery requirements.
Collaborate with product and engineering teams to embed security and compliance requirements into product roadmaps and delivery milestones.
Provide executive-level reporting on cyber risk posture, emerging threats, and program performance to the board and senior leadership.
Champion the use of automation and data analytics to improve the visibility, accuracy, and timeliness of risk and compliance reporting.
Act as a subject matter expert in cyber governance, risk, and compliance, providing mentorship and guidance to colleagues across the organization.
Requirements
You must hold a recognized information security certification relevant to governance and risk, such as Certified Information Systems Security Professional (CISSP).
You must demonstrate proven experience in developing, implementing, and operating enterprise cyber governance, risk, and compliance programs.
You must possess deep expertise in major security frameworks and standards, including ISO 27001, NIST Cybersecurity Framework, and related control frameworks.
You must have extensive knowledge of data protection regulations and privacy frameworks, particularly GDPR and sector-specific rules affecting digital services.
You must have a strong understanding of cyber risk management methodologies, risk assessment techniques, and treatment strategies.
You must have experience establishing and managing enterprise risk registers and defining risk appetite and tolerance statements.
You must have a track record of collaborating with executive leadership, audit, legal, and business stakeholders on governance matters.
You must have excellent analytical, problem-solving, and strategic thinking skills, with the ability to translate complex technical and regulatory concepts into clear guidance.
Nice to have
Experience in highly regulated industries or environments with significant digital transformation programs.
Knowledge of emerging technology risk areas related to cloud services, containerization, serverless computing, and artificial intelligence.
Familiarity with operational resilience standards and practices related to digital service continuity.
Practical notes
The position is based in Paris.
No specific working hours are stated in the source.
No travel requirements are stated in the source.
No visa sponsorship information is provided in the source.
No application deadline is mentioned in the source.