Governance risk and Compliance Technical Specialist - Hybrid Madrid

UST

Madrid

Híbrido

EUR 45.000 - 60.000

Jornada completa

14 días+
Generador de candidaturas

No envíes un currículum genérico — crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Annual Leave
Health Care Plan
Free training access
Gym Access discounts

Descripción de la vacante

A multinational technology firm is seeking a Governance Risk and Compliance Technical Specialist, based in Madrid. The ideal candidate will have over 4 years of experience in audits and compliance, particularly with ISO27001 and cybersecurity standards. This mid-senior level position offers full-time employment and hybrid working arrangements, along with numerous benefits including annual leave, health care plans, and career growth opportunities. Join a progressive company focused on innovation and equal opportunities.

Formación

  • 4+ years of experience in audits, compliance, and assessments.
  • ISO27001 certification or equivalent knowledge.
  • Experience with cybersecurity technologies.

Responsabilidades

  • Conduct audits and ensure compliance with security standards.
  • Design and execute Cybersecurity activities.
  • Coordinate information security awareness training.

Conocimientos

Audits and compliance
Cybersecurity technologies
Risk assessment frameworks
Communication and analytical skills

Educación

Computer Engineering or Telecommunications degree
Master in Cybersecurity

Herramientas

ISO 27001
ISO 22301
NIST

Descripción del empleo

Governance risk and Compliance Technical Specialist - Hybrid Madrid

Get AI-powered advice on this job and more exclusive features.

🚀 UST is looking for the very Top Talent…and we would be delighted if you were to join our family!

More in detail, UST is a multinational company based in North America, certified as a Top Employer and Great Place to Work company with over 35.000 employees all over the world and a presence in more than 35 countries. We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies.

🔍 What are we looking for?

We are looking for a GRC Specialist contribute for a project with one of our global customers in the cybersecurity team.

Responsibilities
  • 4 years’ experience in audits and compliance and assessments based on national and international standards (ISO27001, ISO22301, ENS, NIST, DORA, NIS2)
  • Knowledge/certifications in ISO27001 is a must. It is also desirable knowledge in ENS, ISO 27005, ISO22301, ISO 42001, NIST CSF 2.0, NIST, SOC 2, GDPR, DORA, NIS2, CMMC 2.0
  • Proficiency with a variety of instruments for assessing and controlling risk (ex. ISO 31000, Magerit v3, COSO)
  • Experience in implementation of best practices, compliance with information security policies and standards.
  • Technical experience or applicable knowledge in security architectures for different environments.
  • Experience related to Cybersecurity ecosystem, deployment experience of security technologies.
  • Knowledge of different security solutions/technologies: FW, DLP, IDS/IPS, EDR…
  • Experience in incident response plans and exercises
  • Computer Engineering/Telecommunications and/or Master in Cybersecurity It is also desirable and will be considered to hold certifications such as CISM, CISSP, CISA, ISO/IEC 27001 Lead Auditor / Lead Implementer.
  • Handle the assigned tasks from the allocated domain with minimal guidance from the leads. (Domain Examples: BCMS, ISMS, Risk assessment (AARR & BIAs), GAP Analysis, Incident management, Awareness activities, Data Privacy, etc.)
  • Independently handle (with very minimal guidance from the supervisors) internal audits or GAP Analysis to ensure compliance with security standards (ex. ISO 27001/ISO 22301/ISO 27701, NIST CSF 2.0, ..) requirement as well as process specific requirements
  • Responsible for the effective documentation of projects individually.
  • Point out the non-conformance areas and suggest measures to improve the information security individually.
  • Ensure that risk management is effectively conducted across the organization, business processes and information systems.
  • Involve and contribute to customer assurance activities.
  • Coordinate information security awareness training programs for all the employees, contractors and approved system users.
  • Coordinate and Review the technical assessments of IT systems and processes to identify potential risks. Submit recommendations to mitigate any risks identified and ensure controls that they are implemented.
  • Design, plan and execute the Cybersecurity activities.
  • Directly Interact with customer and communicate detailed technical requirement to the team.
  • Use independent judgement and discretion to analyze the system security.
  • Prepare detailed description of user requirements and steps required to perform a compliance project in basis a standard or regulation.
  • Learn and understand existing regulations or standards requirements.
  • Independently handle the evidence collection from multiple teams as part of any internal audits.
  • Policy/Procedure creation activities and process improvement ideas to be implemented.
  • Research and analytical skills, including the ability to convert complex policy issues into simple briefings and communicate to the audience.
Qualifications
  • 4+ years of experience in audits, compliance, and assessments based on ISO27001, ISO22301, NIS2, DORA, etc.
  • ISO27001 certification or equivalent knowledge, plus familiarity with ENS, ISO 27005, ISO 42001, SOC 2, GDPR, CMMC 2.0.
  • Strong understanding of risk assessment frameworks (ISO 31000, Magerit, COSO).
  • Experience with cybersecurity technologies (FW, DLP, IDS/IPS, EDR) and incident response.
  • Relevant degree (Computer Engineering, Telecommunications, or Master in Cybersecurity); optional certifications: CISM, CISSP, CISA, ISO/IEC 27001 Lead Auditor / Lead Implementer.
Benefits
  • 23 days of Annual Leave plus the 24th and 31st of December as discretionary days!
  • Numerous benefits (Health Care Plan, Internet Connectivity, Life and Accident Insurances).
  • Free access to several training platforms.
  • Professional stability and career plans.
  • Referral program benefits.
  • Option to pick between 12 or 14 payments along the year.
  • Real Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime…).
  • UST Club Platform discounts and gym Access discounts.
Seniority level

Mid-Senior level

Employment type

Full-time

Job function

Consulting

Industries

IT Services and IT Consulting

📧 If you would like to know more, do not hesitate to apply and we’ll get in touch to fill you in details. UST is waiting for you!

In UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality. We have a special commitment to Disability & Inclusion, so we are interested in hiring people with disability certificate.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Consultant (Cloud Security) - Hybrid Madrid
Cybersecurity Consultant (Cloud Security) - Hybrid Madrid

UST • Madrid

Presencial
EUR 55.000 - 75.000
Healthcare plan
Life and accident insurances
Training platform access
+2
Cybersecurity Consultant (Cloud Security) - Hybrid Madrid
Cybersecurity Consultant (Cloud Security) - Hybrid Madrid

UST • Madrid

Presencial
EUR 70.000 - 95.000
Annual leave 23 days
Health care plan
Flexible benefits program
+4
Data Loss Prevention |100% Remote
Data Loss Prevention |100% Remote

UST • Madrid

Presencial
EUR 55.000 - 75.000
Health care plan
Teleworking compensation
Life and Accident Insurances
+2
Software developer (.NET + SQL) - Hybrid Madrid (3-2)
Software developer (.NET + SQL) - Hybrid Madrid (3-2)

UST • Madrid

Híbrido
EUR 42.000 - 65.000
23 days annual leave
Training platforms access
Career plans
+1
Senior Pentester | Madrid
Senior Pentester | Madrid

UST • Madrid

Presencial
EUR 60.000 - 90.000
Health care plan
Teleworking compensation
Life and accident insurances
+1
Support Engineer (.NET, SQL)- Hybrid Madrid
Support Engineer (.NET, SQL)- Hybrid Madrid

UST España & Latam • Madrid

Híbrido
EUR 60.000 - 90.000
Health care plan
Internet connectivity
Life and accident insurances
+7
Senior Presales / Solutions Specialist - Hybrid
Senior Presales / Solutions Specialist - Hybrid

UST • Madrid

Híbrido
EUR 70.000 - 110.000
Health insurance
Flexible hybrid model
23 days annual leave + discretionary 2
+4
Data Engineer Junior (Málaga Hybrid)
Data Engineer Junior (Málaga Hybrid)

UST • Málaga

Presencial
EUR 30.000 - 45.000
23 days Annual Leave
Health Care Plan
Internet Connectivity
+2
Senior Delivery Manager
Senior Delivery Manager

UST • Madrid

Híbrido
EUR 90.000 - 120.000
Annual leave
Health insurance
Flexible benefits
+5
OT Security Engineer- Hybrid (Madrid or Barcelona)
OT Security Engineer- Hybrid (Madrid or Barcelona)

UST • Barcelona

Presencial
EUR 45.000 - 65.000
Annual Leave
Health Care Plan
Flexible working hours
+2