Are you applying to the internship?
Job Description
GRC and PMO Compliance Officer | Dassault Systemes
The Tone:
This is a full-time role at Dassault Systèmes, located in Paris, France. Dassault Systèmes is a global leader in Scientific Software Engineering. This role is crucial for ensuring the company consistently meets its regulatory and market-driven compliance obligations by defining and implementing a robust Third-Party Risk Management Program.
The TL;DR
• Role: Full Time
• Type: Full-time
• Location: In-person, France (Paris HQ)
• Team: Under the direction of the Compliance Program Office
• Mission: Define and implement a Third-Party Risk Management Program to efficiently and consistently meet regulatory and market-driven compliance obligations.
• Tech Stack: Microsoft Office (PowerPoint, Word, Excel, Outlook)
What You’ll Actually Do
• Define Requirements: Define third-party risk management requirements based on applicable regulations, standards, and internal policies such as ISO 9001, ISO 27×01, SOC 2, NIST, GDPR, NIS2, CRA, and FedRAMP.
• Design Framework: Design and implement a common risk management framework by assessing current supplier risk practices and facilitating working groups to build consensus on policy, risk appetite, and control ownership.
• Program Management: Build and manage a comprehensive program plan for the Third-Party Risk Management Program, overseeing objectives, scope, timeline, budget, workflow configuration, and integration with existing systems.
• Operational Oversight: Monitor ongoing third-party risk operations by tracking metrics, reporting on maturity, updating the framework based on regulatory changes, and supporting due diligence reviews and high-risk vendor escalations.
• Stakeholder Engagement: Serve as the primary point of contact for workstream leaders, key stakeholders, and internal/external compliance audits, providing training and guidance on third-party risk requirements and processes.
The Must-Haves
• Background: Bachelor’s or Master’s degree with core domain knowledge in compliance, risk management, or regulatory operations.
• Experience: 5+ years of relevant experience, including working with control frameworks tied to standards like ISO 27001, SOC 2, ISO 42001, and managing compliance requests or similar operational workflows end to end; experience with Process Management, Continuous Improvement, Change Management, and Stakeholder Management.
• Skills: Strong understanding of GRC frameworks and control models, including how new regulations map to existing controls; excellent English language communication skills, both verbal and written; proficient with Microsoft Office suite.
• Bonus: Relevant certifications (e.g., CRISC, CISA); familiarity with quality, security, and privacy standards and their control requirements (e.g., ISO 9001, 27001, SOC 2, GDPR, FedRAMP).