Alan logo

Alan

Security Lead

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · Paris, France

Employer listed it 3 months ago · Added 4 days ago

Been open since 3 months ago. Long-running listings are sometimes left up after the role is filled.

Salary

Not stated

Location

Hybrid · Paris, France

Timezone

CET ±2

Contract

Full-time

Experience

Lead

Category

Software

This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 596 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around Paris, France, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "Paris, France, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Health can’t wait .

Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t.

Alan exists to end the wait.

Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way.

So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience.

We are on an incredible journey to build a global leading company, with a unique culture . We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR.

Prevention as the new norm. That's what we're building with our team of 1000+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond.

The team and your missions

You will lead Alan's Security team, a highly technical group operating across 10+ countries in a regulated health insurance environment. As Security Lead, your missions span four core areas:

Lead and grow the security team: Coach, structure, and elevate a team of security experts. Set clear priorities, define ownership, and create conditions for genuine professional growth.

Own security in the AI era: Define Alan's posture on AI-driven threats and opportunities. Build frameworks that let product and engineering teams ship AI-powered features safely and at speed.

Scale security across 10+ countries: Own the ISMS and certification programme (ISO 27001), navigate a complex multi-regulatory environment (DORA, HDS, RGPD, NIS2, PGSSI-S), and ensure Alan's security programme keeps pace with its geographic expansion.

Build and evolve Alan's security strategy: Position security as a long-term business asset and trust-builder for members, regulators, and partners. Align Legal, DPO, Risk, Engineering, and Product on security requirements, and build a security culture that empowers rather than restricts.

The challenge

Alan is a fast-growing health insurer operating in a uniquely complex environment. The challenges you will navigate include:

A shifting threat landscape: AI is reshaping both attack vectors and defensive possibilities. You will need a clear point of view on LLM security, agent risks, and AI governance, and the ability to translate that into concrete, actionable priorities.

Multi-country regulatory complexity: Operating across 10+ countries means managing a dense, evolving regulatory stack (DORA, HDS, RGPD, NIS2, PGSSI-S) while keeping the business moving. You will need to translate regulatory requirements into technical controls without creating bottlenecks.

Health sector specifics: Alan handles sensitive health data at scale. This comes with sector-specific requirements (ANS framework, CERT Santé, HDS) that demand both technical precision and operational rigor.

Influencing at scale without direct authority: Security touches every function. Your ability to align Legal, DPO, Risk, Engineering, Product, and Operations, and make them come to you early, will be as important as your technical depth.

Running security as a living programme, not a compliance exercise: The goal is not to pass audits. It is to build a programme that feeds real decisions, scales with the company, and earns genuine trust.

Who we are looking for

Proven experience leading a security (or security-adjacent) team, with concrete examples of people development and growth

At least one full ISO 27001 certification or recertification cycle led end-to-end

Solid understanding of the regulatory stack relevant to Alan's context: DORA, HDS, RGPD, NIS2, PGSSI-S

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Alan, mentioning your remote working experience and working hours (CET ±2).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $200k–$275k · You'll be taken to the employer's careers page.