Les missions du poste
We're hiring a Security GRC Engineer to help us build governance, risk, and compliance in a way that actually works in a modern tech organization: pragmatic, automation-friendly, and aligned with agile delivery.
This is not a paperwork job. You'll partner closely with engineering, product, workplace, auditors and security to turn risk management and compliance into clear, usable guardrails and you'll challenge processes that create friction without improving security.
What you'll do
- Risk management that drives decisions
Run lightweight, continuous risk assessment and threat modelings with teams (not once-a-year rituals).
Translate risk into clear options: impact, likelihood, tradeoffs, and recommended actions.
Track remediation plans and provide visibility through simple reporting.
- Build practical governance
Maintain and improve security policies/standards so they're short, actionable, and adopted.
Create control objectives that fit real engineering workflows (CI/CD, cloud, SaaS, identity).
- Compliance, without the theater
Support audits and evidence collection with a focus on efficiency and reusability.
Help align our program with recognized frameworks (e.g., NIST ) in a pragmatic way.
Develop compliance-as-code habits where possible (automated checks, continuous evidence).
- Third-party risk (vendors, partners)
Drive assessments, follow-ups, and risk treatment with procurement and stakeholders.
Push for scalable vendor processes (tiering, standard questionnaires, measurable requirements).
- Security enablement
Create playbooks, templates, and self-service material that teams can use without heavy guidance.
Coach teams to understand risk and make better security choices early in delivery.
Le profil recherché
Experience in GRC / risk / compliance in a tech environment (security, cloud, SaaS, engineering orgs).
Strong understanding of security fundamentals: identity, access, logging, incident response, cloud shared responsibility, secure SDLC (at a practical level).
- Ability to write simple, clear policies/standards and translate requirements into engineering-friendly controls.
- Comfort with ambiguity and agility: you can iterate, prioritize, and deliver incremental improvements.
- Excellent stakeholder skills: you can influence without authority, challenge respectfully, and get things done.
Bonus points
- Experience aligning programs to frameworks (NIST CSF, ISO 27001, SOC 2, etc.).
- Experience with vendor risk platforms or automation (workflows, evidence collection, dashboards).
- Familiarity with compliance as code concepts, continuous controls monitoring, or security tooling.
- Experience partnering with product/engineering teams on secure-by-design practices.
How we work
We value ownership, transparency, and pragmatism.
We prefer automation and repeatability over manual processes.
We challenge the old way when it's slow, fragile, or meaningless.
We aim to be a security team that teams want to work with.
Bienvenue chez Believe
Believe is a global artist development company. We empower local artists, labels andpublishers to grow their audiences at each stage of their careers with expertise, respect,fairness and transparency. Operating in 50+ countries, with more than 2,000 employees, Believe offers a full rangeof services including audience development, publishing, marketing and distribution,with a tailor-made approach to fit any artist, label or publisher.
Believe champions independence and innovation through a unique model thatcombines local expertise with a global tech platform, delivering exclusive solutions forartists to promote and monetize their music thanks to strategic partnerships withleading global digital service providers.With a leading portfolio of brands that includes Nuclear Blast, naïve, TuneCore, GrooveAttack, Sentric, AllPoints and Byond, Believe artists generated more than 800 billionstreams worldwide in 2024 across all genres, and were recognized with more than 70leading industry awards.
Believe is a simplified joint-stock company under French law.
Ready to set the tone with Believe ?
Publiée le 02/06/2026 - Réf : BLV_26_3202