Cyber GRC Specialist
Paris, FR, 75008
Who are we?
Sonepar is an independent family-owned group and a world leader in the distribution of electrical equipment, solutions and related services to the trade. In 2025, Sonepar generated a turnover of €33.6 billion. With a presence in 40 countries and an extensive network of retail outlets, the Group is undertaking an ambitious transformation to make life easier for its customers by offering them an omnichannel experience and a range of sustainable solutions for the industrial, construction and energy sectors. Our 46,000 employees are committed to the electrification of the world and united by a shared Purpose: “Power Progress for Future Generations.
How will you shape our tomorrow
As part of the strengthening of the Group’s cybersecurity governance, we are looking for a Cyber GRC Specialist with relevant initial experience in Governance, Risk & Compliance. Versatile, rigorous and proactive, you will contribute to a broad range of topics, including the cybersecurity documentation framework, risk assessments, controls, compliance, TPRM and awareness.
Reporting to the Cyber GRC Director within Sonepar Digital’s Cybersecurity & Infrastructure team, you will operate in an international, English-speaking environment. You will work with Group Cyber teams, the Regional Directors for the Americas, APAC and Europe, cross-functional teams including Enterprise Risk Management, Internal Control, Internal Audit and Legal, as well as Group entities.
Your role will be to contribute to the operational implementation of the Cyber GRC strategy and make cybersecurity requirements and risks clear and actionable. You will engage with Business teams, understand their constraints and support their decision-making by providing a clear view of risk.
You will progressively take ownership of end-to-end topics with a good level of autonomy, while receiving support from the Cyber GRC Director whenever needed.
What success looks like ?
-The Group Cyber GRC documentation framework is developed and maintained in collaboration with Domain and Regional Directors when required.
-Cyber risk assessments are completed, clearly presented and translated into actionable recommendations for decision-makers.
-Cybersecurity assessments of solutions and third parties provide a clear view of risks and required remediation actions.
-The implementation of Cyber requirements is effectively assessed with the relevant support functions, and identified gaps are appropriately followed up.
-Awareness initiatives are designed and delivered to strengthen the understanding of cyber risks and expected practices across the Group.
-Risk-based audit campaigns are defined and coordinated with the Cyber GRC Director, with clear findings and remediation priorities.
Profile
You are an experienced cybersecurity professional with a focus on Governance, Risk & Compliance. You have already contributed to several GRC topics and are looking to progressively broaden your scope in an international and evolving environment.
You are comfortable working with technical, Corporate and Business stakeholders. You can formalize a need, analyze a risk, propose an approach and produce clear deliverables. You know when to seek guidance, support or a decision.
You are comfortable translating a framework into operational implementation and explaining cyber issues in terms of business impacts and decisions.
The experience you bring
Technical Skills
• Good understanding of key cybersecurity and risk management frameworks, including NIST CSF, NIST 800-53 and ISO 27001/27002/27005.
• Experience in drafting or maintaining policies, standards, requirements, controls or evidence requirements.
• Practical experience in cyber risk assessments and the monitoring of risk treatment plans.
• Ability to produce clear, structured deliverables and reports tailored to their intended audience.
• Ability to work with global, regional and local teams in a matrix environment.
• Fluent French and English, both written and spoken.
Soft skills
• Autonomy and a proactive mindset, with the ability to seek support or escalation when required.
• Clear communication and the ability to adapt your message to technical, Business and management audiences.
• Analytical thinking, rigor and the ability to structure complex topics.
• Pragmatism and the ability to prioritize based on risk and operational considerations.
• Curiosity and adaptability in a transforming environment.
Work Mode & Location
- Hybrid: 3 days in Paris (8ème) after the trial period
Benefits that await you:
The role - Your daily activities will be interesting, stimulating and varied... No two days are alike!
The organisation - You'll be part of the Sonepar family and share the same values!
The culture - You'll be working in an international environment.
The team - Our dynamic, multidisciplinary, open-minded and talented team is eager to welcome additional skills to continue to meet the challenge.
75% reimbursement of your monthly or annual transport pass.
Swile Ticket restaurant card
Gym exclusively reserved for the company and made available to employees free of charge.
Sustainable mobility package
Health insurance & Welfare
Employee Savings Plan & Profit Sharing Bonus.
Recruitment process
- Call with a Talent Acquisition Manager
- Hiring manager's interview
- Final HR interview
We are interested in knowing you more. Start an exciting new career and enjoy many employee benefits by applying online. Sonepar HQ is thankful for your interest in joining the team, only individuals selected for interview will be contacted.
More information on Sonepar:
Website: www.sonepar.com
Twitter: @sonepar
LinkedIn: https://www.linkedin.com/company/sonepar/
Check out Sonepar on Facebook!
To apply, you must use a computer and one of the following browsers: Safari, Chrome, Mozilla Firefox or even EDGE.