Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)

Montarelo Recruiting

Madrid

Híbrido

EUR 70.000 - 100.000

Jornada completa

14 días+
Generador de candidaturas

Una candidatura hecha para este puesto de trabajo — un currículum y una carta de presentación adaptados que responden directamente a la oferta.

Supera los filtros ATS

Descripción de la vacante

A technology-based startup is seeking a Governance Risk & Compliance Lead in Madrid. This role involves implementing compliance frameworks and managing risk while ensuring regulatory readiness. The ideal candidate has over 5 years of experience in cybersecurity, specifically in a SaaS environment, and strong communication skills in both Spanish and English. This position offers a hybrid working model and requires a valid EU work permit.

Formación

  • 5+ years of experience in cybersecurity within cloud-first or SaaS organizations.
  • At least 2+ years in GRC roles.
  • Good knowledge of GDPR, ISO 27001, SOC 2, NIS 2, and NIST CSF.
  • Familiarity with compliance automation platforms such as Vanta and OneTrust.

Responsabilidades

  • Lead the implementation of GDPR, ISO 27001, SOC 2, and NIS 2 compliance.
  • Develop and maintain policies and procedures for certification and audit readiness.
  • Conduct regular risk assessments and maintain a centralized risk register.
  • Operationalize the NIST Cybersecurity Framework across the corporate, product and operational domains.
  • Conduct regular risk assessments and maintain a centralized risk register.
  • Collaborate with IT, Product and Legal teams to ensure risk mitigation strategies are prioritized.
  • Governance & Policy Enforcement: establish governance structures, run risk committees, maintain policies.
  • Reporting & Communication: provide updates to executives, develop dashboards, act as liaison for clients/regulators.

Conocimientos

Communication skills
Stakeholder management
Risk assessment
Governance frameworks

Educación

Bachelor's Degree in IT or related field

Herramientas

Compliance automation platforms
Azure cloud environments

Descripción del empleo

Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)

The company: Our customer is a technology-based startup with solid funding that is in the midst of expansion.

They will hire the selected candidate as an internal and permanent employee, based in Madrid, but providing services to their global organization.

Description of the position:

We’re looking for a Governance Risk & Compliance Lead for its global operations in Madrid. He/She will be responsible for designing and operationalizing the company’s governance, risk, and compliance framework. Reporting to the Head of Information Security, he/she will play a critical role in enabling company growth by ensuring regulatory readiness, managing risk, and embedding security and compliance into business and product operations.

Key Responsibilities and tasks:

  • Lead the implementation of GDPR, ISO 27001, SOC 2, and NIS 2 compliance programmes, with a roadmap aligned to business priorities and client expectations.
  • Develop and maintain policies, procedures, and controls that support certification and audit readiness.
  • Coordinate with external auditors, consultants, and vendors to streamline evidence collection and reporting.
  • Operationalize the NIST Cybersecurity Framework across the corporate, product and operational domains
  • Conduct regular risk assessments and maintain a centralized risk register.
  • Collaborate with IT, Product and Legal teams to ensure risk mitigation strategies are prioritized correctly.
  • Governance & Policy Enforcement:
    • Establish governance structures for security and compliance decision-making.
    • Run regular risk committees and track related actions.
    • Maintain and enforce policies such as password management, access control, and vendor risk.
  • Reporting & Communication:
    • Provide regular updates to executive leadership on compliance progress, risk posture, and audit outcomes.
    • Develop dashboards and visualizations to communicate timelines and milestones to stakeholders.
    • Act as the primary liaison for compliance-related queries from clients, partners, and regulators.

Working Experience:

  • 5+ years of proven experience in cybersecurity landscape within cloud-first or SaaS organisations.
  • At least 2+ years in GRC roles.
  • Working experience of GDPR, ISO 27001, SOC 2, NIS 2, and NIST CSF.
  • Familiarity with compliance automation platforms (e.g., Vanta, OneTrust).

Not mandatory but preferred:

  • Lead on ISO 27001, SOC2 or GDPR compliance implementation.
  • In-depth knowledge of the NIS2 directive.
  • Working knowledge of Azure cloud environments.
  • Working knowledge of OT security.
  • Excellent communication and stakeholder management skills.
  • International work experience working with international teams.

Education and Training:

  • Bachelor's Degree or vocational training qualification: In information technology, or a related field.

Certifications: Not mandatory but preferred

  • Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or ISO 27001 Lead Implementer.

Languages:

  • Spanish: Very good Business Spanish required (excellent communication skills). B2/C1 level.
  • English: Very good Business English required (excellent communication skills). B2/C1 level.

Job Conditions:

Job location: Tres Cantos (Madrid). EU nationality or valid EU/Spain work permit required.

Employment Type: Permanent Full Time, as internal employee.

Salary: Depending on qualification and experience.

Work from home: Hybrid working model including the possibility of working from home (70%) but according to the specific needs that may arise from the perspective of project development, department, clients, and/or partners.

How to apply: If you are interested, please apply here or email grc@montarelo.com with the subject Governance Risk & Compliance Lead and your English CV.

Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Information Technology
Industries
  • IT Services and IT Consulting and Space Research and Technology
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)
Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)

Montarelo • Madrid

Híbrido
EUR 60.000 - 90.000
GRC Lead, Cybersecurity & Compliance - Madrid (Hybrid)
GRC Lead, Cybersecurity & Compliance - Madrid (Hybrid)

Montarelo Recruiting • Madrid

Híbrido
EUR 70.000 - 100.000
Governance risk and Compliance Technical Specialist - Hybrid Madrid
Governance risk and Compliance Technical Specialist - Hybrid Madrid

UST • Madrid

Presencial
EUR 45.000 - 60.000
Annual Leave
Health Care Plan
Free training access
+1
GRC Security Expert
GRC Security Expert

Leadtech Group • Barcelona

A distancia
EUR 30.000 - 54.000
Private health insurance
Flexible hours
Remote work option
+5
GRC & Cybersecurity Lead - Hybrid Madrid
GRC & Cybersecurity Lead - Hybrid Madrid

Montarelo • Madrid

Híbrido
EUR 60.000 - 90.000
Senior Cybersecurity Regulatory Consultant
Senior Cybersecurity Regulatory Consultant

Gmv • Madrid

Híbrido
EUR 65.000 - 90.000
Hybrid work model
Relocation package
Career development support
Governance, Risk & Compliance Manager
Governance, Risk & Compliance Manager

coches.net • Barcelona

Híbrido
EUR 70.000 - 110.000
Hybrid work policy
Competitive salary
Cybersecurity, Risk and Regulatory Compliance Consultant
Cybersecurity, Risk and Regulatory Compliance Consultant

GMV Spain • Madrid

Híbrido
EUR 60.000 - 90.000
Hybrid work model
Remote work (8 weeks/yr)
Flexible hours
+4
Cybersecurity, Risk and Regulatory Compliance Consultant
Cybersecurity, Risk and Regulatory Compliance Consultant

GMV • Tres Cantos

Presencial
EUR 60.000 - 90.000
Hybrid work model
Flexible working hours
Wellbeing program
+3
Junior Cybersecurity, Risk and Regulatory Compliance Consultant
Junior Cybersecurity, Risk and Regulatory Compliance Consultant

GMV • Tres Cantos

Híbrido
EUR 38.000 - 60.000
Hybrid work model
Remote work 8 weeks/year outside usual
Relocation package
+2