Would you like to contribute to strengthening the security, resilience, and compliance of a healthcare information system?
At Oticon/ITSA Medical, we develop, manufacture, and market bone-anchored hearing systems within an international organization. The group has a presence in several countries, with its main offices located in France and Sweden. At our Vallauris site (Sophia Antipolis), in the south of France, we specialize in the production of active implantable Class III medical devices and manage the worldwide distribution of the company’s complete product portfolio. The site also hosts an R&D team and the French sales organization.
Although the position is based in France, its scope extends across all geographies where the group operates.
As part of the development and security enhancement of the organization’s information system, and in the context of a newly created position, we are looking for an Information Security & Compliance Manager to define, deploy, manage, and continuously improve the technical, organizational, and human measures required to ensure the security, availability, integrity, and confidentiality of information, particularly personal health data.
The role will support full alignment of the information system with ISO/IEC 27001, GDPR requirements, and health data hosting standards, including HDS certification where applicable.
Reporting to senior management, your main responsibility will be to lead the global organization’s cybersecurity strategy, risk management framework, compliance roadmap, and continuous improvement of the Information Security Management System.
Main Tasks:
• Define, maintain, and deploy the Information Systems Security Policy and the ISO 27001-based Information Security Management System. • Ensure alignment with GDPR, ISO 27001, HDS, and healthcare data protection requirements.
• Lead cybersecurity risk management, including asset and risk mapping, EBIOS RM analysis, Statement of Applicability, and risk treatment plans. • Report regularly to senior management on cybersecurity risks, compliance status, key indicators, dashboards, and roadmap progress.
• Define and oversee secure architecture, infrastructure, identity and access management, monitoring tools, encryption, and certificate management. • Supervise backup, business continuity, disaster recovery, incident response, and cyber crisis exercises, including ransomware and data exfiltration scenarios.
• Prepare and support audits, penetration tests, vulnerability scans, remediation plans, and threat monitoring activities.
• Deploy cybersecurity awareness initiatives and manage security requirements for suppliers and subcontractors, including contracts and audits.
Work closely with the DPO, IT, medical leadership, operations, and key stakeholders.
Profile:
Required Skills:
• Master's degree (Bac+5) in Engineering, Cybersecurity, or Information Systems Security, or equivalent
• 5–10 years of experience as a CISO or in a similar information security leadership role
• Proven hands-on experience leading an ISO 27001 Information Security Management System (ISMS), including full end-to-end project management responsibility
• Strong command of relevant frameworks and standards: GDPR, ISO 27001, HDS, EBIOS RM
• Solid technical expertise: secure architecture, IAM management, SOC/SIEM, PKI, vulnerability management and cyber crisis management
• Strong soft skills: leadership, executive-level communication, and the ability to translate complex technical topics for senior management/Executive Committee (COMEX)
• Knowledge of AI, generative AI security risks, AI governance, and responsible AI principles, with the ability to support secure and compliant adoption of AI solutions.
Desired Skills:
• ISO 27001 Lead Implementer and/or Lead Auditor certification.
• CISSP, CISM, CEH, EBIOS RM, or equivalent cybersecurity certification.
• Experience in healthcare, medical technologies, regulated environments, or health data protection.
• Knowledge of HDS requirements and healthcare cybersecurity constraints.
• Experience coordinating suppliers, audits, security committees, or cyber crisis exercises.

Demant is a world-leading hearing healthcare group built on a heritage of care, health and innovation since 1904. The Group offers solutions and services to help people connect and communicate with the world around them. For more than a century, the Demant Group has played a vital part in developing innovative technologies and gathering know-how to help improve people’s hearing and health. In every aspect, from providing hearing care to delivering hearing aids and diagnostic equipment and services to hearing care professionals and users all over the world, Demant is active and engaged.
The Demant Group operates in a global market with subsidiaries in more than 30 countries, employs more than 22,000 employees and generates annual revenue of more than DKK 22 billion. Our products are sold in more than 130 countries where we create life-changing differences through hearing health.
Listed on Nasdaq Copenhagen stock exchange as a blue chip stock, Demant is the parent company behind world-renowned and commercially successful brands as Oticon, Bernafon, Sonic, Philips Hearing Solutions, Audika, MAICO, Interacoustics, Amplivox, Grason-Stadler, MedRx and Audioscan. William Demant Foundation holds the majority of shares in Demant A/S, which is listed on Nasdaq Copenhagen and among the 25 most traded stocks.
If you want to know how we process your personal data on social media platforms, visit this site: https://www.demant.com/privacy-notice#some