Information Security Intern focusing on Governance, Risk, and Compliance at papernest. Involves compliance projects and security documentation in a tech environment.
Responsibilities
You will be the "guardian of the framework."
Help turn our security activities into a structured, audit-ready program, focusing heavily on Governance, Risk, and Compliance (GRC).
Assist in the NIS2 compliance project by helping map our current measures against essential entity obligations.
Support PCI-DSS oversight by collecting evidence (screenshots, logs, configs) and organizing them for external auditors.
Help manage our continuous compliance platforms to ensure we are always audit-ready.
Act as the librarian for our security knowledge.
Help centralize, format, and update our Security Policy Framework to ensure it is accessible to all employees.
Work on Internal audit preparation by ensuring all procedures are written down and up to date.
Assist in documenting security KPIs and preparing reports for leadership.
Take ownership of the Vendor security due diligence process.
Send out security questionnaires to new tools/partners and review their answers.
Maintain our register of third-party risk assessments and ensure contractual security clauses are tracked.
Assist the Senior Engineer in tracking vulnerability remediation by following up with developers to ensure tickets are closed on time.
Help organize security awareness campaigns (phishing simulations, training sessions) to boost our internal culture.
Requirements
Student in Business (IT Management), Computer Science, or Cybersecurity with a focus on GRC.
Detail-Oriented: You love checklists, organized folders, and clear documentation.
Strong Writing Skills: You can explain complex rules in simple, clear English.
Interest in Regulations: You are curious about GDPR, NIS2, and PCI-DSS and want to learn how they apply to a real tech scale-up.
Tech-Savvy: You don’t need to be a coder, but you are comfortable with tech tools (Jira, Notion, Excel) and understand the basics of how a SaaS company works.
Benefits
Evolve in an international and inclusive environment: everyone has a place at papernest, and with more than 46 different nationalities, it's not uncommon here to start a sentence in English and finish it en français o en español
Enjoy a competitive compensation for your internship. We value every contribution and are committed to offering attractive remuneration for your efforts and dedication.
A healthy and balanced breakfast is offered every Tuesday!
Interns are not just “photocopy-coffee” assistants! As a full-fledged team member, you're here to learn, but also to share your ideas and implement projects. You'll be supported throughout your journey to maximize your skills and prepare for your future.
Enjoy 1 day of remote work per week to optimize your focus and efficiency.
Information Security Specialist responsible for protecting systems and data at Ituran. Collaborating with teams and ensuring compliance with security measures and regulations.
Senior Cloud & Information Security Engineer responsible for EC Markets' technical security posture. Designing and operating secure systems while ensuring regulatory compliance and cloud infrastructure security.
Product Security Engineer focusing on ensuring software resilience against attacks during development phases. Collaborating with DevOps and Engineering teams to enhance security protocols.
IT audit specialist responsible for executing technology and cybersecurity audits at an international bank in Zurich. Collaborating with top management to enhance internal controls and efficiencies.
IT Systemadministrator focusing on Sophos Security at bauXpert GmbH. Responsible for IT infrastructure management and support tasks in a hybrid environment.
Cyber Security Specialist designing and implementing security controls for Squarcle clients. Supporting compliance with regulations and best practices in a digital environment.
Head of Security at Street Group managing organizational security and working with IT and Engineering teams. Leading security posture and compliance while mitigating emerging threat vectors.
Security Consultant providing technical leadership in electronic security systems engineering for complex built environments. Leading projects through all lifecycle stages while engaging with clients and contractors.