
GRC Security Expert
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in Spain.
• Create cybersecurity policies, procedures, and methodologies
• Execute relevant standards and regulations
• Oversee ISO 27001 projects, manage vulnerability follow-ups, and conduct vendor evaluations
• Ensure security initiatives are in alignment with ISO 27001, GDPR, and NIS2 requirements
• Design data protection and privacy strategies
• Detect, troubleshoot, and resolve issues impacting both internal and external processes
• Handle multiple projects while ensuring quality and compliance with regulations
• Collaborate with product, engineering, marketing, and other stakeholders to collect requirements and assess options
• Create tools and processes that support organizational objectives
• Bachelor's degree in Computer Science, Telecommunications, Law, or equivalent practical experience
• 1 to 2 years of experience in governance, risk management, compliance (GRC), IT auditing, or related fields
• Proficient understanding of ISO 27001:2022, including its clause structure, Annex A controls, and Statement of Applicability (SoA)
• Background as an auditor, consultant, or implementation specialist
• Familiarity with data protection principles, including data retention, Privacy Impact Assessments (PIAs), and Risk Assessment Tools (RATs)
• Basic knowledge of AWS, GCP, or Azure and IAM concepts such as least privilege, multi-factor authentication (MFA), key rotation, and orphaned accounts
• Strong written communication skills in both English and Spanish
• Exceptional organizational abilities for managing findings, tickets, and evidence requests across teams
• Proactive in following up with teams, gathering evidence, identifying overdue deadlines, and driving tasks to completion with minimal supervision
• Capability to independently recognize gaps or discrepancies and escalate them promptly
• ISO 27001 Lead Implementer/Auditor, CompTIA Security+, CISA, or CISM certification either in progress or completed is viewed favorably
• Experience with NIS2 or other EU cybersecurity regulations
• Familiarity with GRC platforms like CISO Assistant or vulnerability management tools
• Previous experience in supporting vendor or third-party security assessments
• Competitive compensation package
• Flexible working hours and flextime options
• Health insurance coverage
• Training programs available
• Customized internal training sessions
• Annual budget allocated for external learning opportunities
• Option to work entirely remotely or from the Barcelona office
• Enjoy free Friday afternoons with a 7-hour workday
• 35-hour workweek during July and August
• Premium private health insurance, including dental and psychological services
• 25 vacation days
• Birthday off
• Flexible vacation policies with no blackout days
• Complimentary coffee, fresh fruit, snacks, a game room, and access to a rooftop terrace at the Barcelona office
• Restaurant ticket vouchers
• Nursery vouchers
• Full-time permanent contract
Intelance
OX Security
Cloudiax
Cisco
Get handpicked remote jobs straight to your inbox weekly.