¡Activa las notificaciones laborales por email!

Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)

Montarelo Recruiting

Madrid

Híbrido

EUR 70.000 - 90.000

Jornada completa

Hace 13 días

Descripción de la vacante

A tech startup in Madrid seeks a Governance Risk & Compliance Lead. The role involves implementing compliance programmes, managing risks, and ensuring regulatory readiness. Ideal candidates will have over 5 years of experience in cybersecurity and strong communication skills in English and Spanish. This position offers a hybrid work model with up to 70% remote work.

Formación

  • 5+ years in the cybersecurity landscape, particularly in cloud-first or SaaS.
  • 2+ years in Governance, Risk, & Compliance roles.
  • Excellent English and Spanish communication skills at B2/C1 level.

Responsabilidades

  • Lead GDPR, ISO 27001, SOC 2, and NIS 2 compliance programmes.
  • Conduct regular risk assessments and maintain a risk register.
  • Provide updates to executive leadership on compliance progress.

Conocimientos

Cybersecurity experience
Stakeholder management
Communication skills

Educación

Bachelor’s Degree in information technology or related field

Herramientas

Compliance automation platforms (e.g., Vanta, OneTrust)
Azure cloud environments
Descripción del empleo
Overview

Our customer is a technology-based startup with solid funding that is in the midst of expansion. The selected candidate will be hired as an internal and permanent employee, based in Madrid, and will provide services to their global organization. We’re looking for a Governance Risk & Compliance Lead for its global operations in Madrid.

The role reports to the Head of Information Security and will play a critical part in enabling company growth by ensuring regulatory readiness, managing risk, and embedding security and compliance into business and product operations.

Responsibilities
  • Compliance Programme Development: Lead the implementation of GDPR, ISO 27001, SOC 2, and NIS 2 compliance programmes, with a roadmap aligned to business priorities and client expectations.
  • Develop and maintain policies, procedures, and controls that support certification and audit readiness.
  • Coordinate with external auditors, consultants, and vendors to streamline evidence collection and reporting.
  • Risk Management: Operationalize the NIST Cybersecurity Framework across the corporate, product and operational domains.
  • Conduct regular risk assessments and maintain a centralized risk register.
  • Collaborate with IT, Product and Legal teams to ensure risk mitigation strategies are prioritized correctly.
  • Governance & Policy Enforcement: Establish governance structures for security and compliance decision-making, run regular risk committees and track related actions.
  • Maintain and enforce policies such as password management, access control, and vendor risk.
  • Reporting & Communication: Provide regular updates to executive leadership on compliance progress, risk posture, and audit outcomes.
  • Develop dashboards and visualizations to communicate timelines and milestones to stakeholders.
  • Act as the primary liaison for compliance-related queries from clients, partners, and regulators.
Qualifications & Experience
  • Working Experience: 5+ years of proven experience in the cybersecurity landscape within cloud-first or SaaS organizations.
  • At least 2+ years in GRC roles.
  • Working experience of GDPR, ISO 27001, SOC 2, NIS 2, and NIST CSF.
  • Familiarity with compliance automation platforms (e.g., Vanta, OneTrust).
  • Preferred: Lead on ISO 27001, SOC2 or GDPR compliance implementation.
  • In-depth knowledge of the NIS2 directive.
  • Working knowledge of Azure cloud environments.
  • Working knowledge of OT security.
Soft Skills
  • Excellent communication and stakeholder management skills.
  • International work experience with international teams.
Education, Certifications & Languages
  • Education: Bachelor’s Degree or vocational training qualification in information technology or a related field.
  • Certifications: Not mandatory but preferred CISA, CRISC, or ISO 27001 Lead Implementer.
  • Languages: Spanish — very good business Spanish required; English — very good business English required. B2/C1 level for both.
Job Conditions
  • Job location: Tres Cantos (Madrid).
  • Citizenship/Work authorization: European Union nationality or Spain work permit required.
  • Employment Type: Permanent Full Time, internal employee.
  • Salary: Depending on qualification and experience.
  • Work from home: Hybrid model including up to 70% remote work, subject to project and client needs.
How to Apply

If you are interested, please apply here or send an email to grc@montarelo.com with the subject: Governance Risk & Compliance Lead and your English CV.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra un archivo en formato PDF, DOC, DOCX, ODT o PAGES de hasta 5 MB.