GRC Specialist

Jobgether

España

A distancia

EUR 60.000 - 90.000

Jornada completa

Hace 5 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Remote work
Competitive salary
Equity
Development budget
Health insurance
Annual retreat
Home office budget
Mentorship network

Descripción de la vacante

Jobgether is seeking a GRC Specialist based in Spain for a high-impact, fully remote role focused on governance, risk, and compliance. You will expand and automate compliance across ISO 27001, TISAX, SOC 2, GDPR, NIS 2, and other frameworks while delivering practical guidance and content for customers and auditors.

You will lead internal audits, own compliance content, and partner with Product and Engineering to translate requirements into platform initiatives, shaping security offerings and

Formación

  • 3+ years of hands-on experience in information security, Governance, Risk, and Compliance or related field.
  • Experience leading ISO 27001 certification projects as implementer/auditor or equivalent.
  • Fluent English with strong written communication for auditors and executives.
  • Hands-on experience with a GRC platform or similar tooling.
  • Bachelor’s degree in Computer Science, Software Engineering, or related field.

Responsabilidades

  • Build and maintain compliance frameworks within the platform (ISO 27001, GDPR, SOC 2, NIS 2, DORA, etc.).
  • Lead internal audits from kickoff through final reporting.
  • Provide practical guidance for ISO 27001 certifications and enablement content.
  • Collaborate with Product and Engineering to translate gaps into product initiatives.
  • Own compliance content, templates, and training materials.
  • Support auditors and customers during audits and reviews.

Descripción del empleo

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Specialist based in Spain.

This is a high-impact Governance, Risk, and Compliance role within a fast-growing, fully remote environment focused on security and compliance automation. You’ll help expand and strengthen compliance offerings across frameworks such as ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, and others. The role combines hands-on compliance delivery, internal audits, content ownership, and customer support. You’ll work closely with Customer Success, Product, Engineering, and leadership to turn compliance requirements into practical solutions. With significant autonomy, you’ll have the opportunity to shape both customer-facing services and the compliance capabilities embedded within the platform. This is an ideal opportunity for an experienced GRC professional who enjoys ownership, variety, and measurable impact.

Accountabilities
  • Build, maintain, and continuously improve compliance frameworks within the platform, including ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and emerging frameworks.
  • Lead internal audits for customers from initial kickoff through final reporting, ensuring audits remain on schedule and meet expected quality standards.
  • Implement ISO 27001 and related security and compliance frameworks for customers, providing practical guidance throughout the certification journey.
  • Own the quality and breadth of compliance content, including policies, automated checks, evidence templates, enablement playbooks, security awareness training, and related materials.
  • Identify framework gaps and incorporate auditor feedback into compliance practices, customer delivery, and platform improvements.
  • Partner with Product and Engineering teams to translate compliance requirements and identified gaps into structured product initiatives.
  • Collaborate with Customer Success, Product, and leadership to align compliance priorities with customer needs and business objectives.
  • Maintain and strengthen relationships with certification partners and support auditors in using the platform effectively during customer audits.
  • Manage multiple audits and compliance initiatives simultaneously, prioritizing effectively and taking full ownership of delivery and outcomes.
Requirements:
  • 3+ years of hands-on experience in information security, Governance, Risk, and Compliance, or a closely related field.
  • Proven experience leading at least one successful ISO 27001 certification project as an implementer, auditor, or equivalent compliance professional within a startup or mid-market organization.
  • Experience conducting at least two internal audits from planning through completion.
  • Hands-on experience using a GRC platform or comparable compliance management technology.
  • Strong knowledge of at least one compliance framework beyond ISO 27001, such as TISAX, SOC 2, GDPR, NIS 2, or a similar standard.
  • Fluent English communication skills, with excellent written communication and the ability to produce clear, precise compliance content for auditors, executives, engineers, and customers.
  • Strong project management and organizational skills, with the ability to turn ambiguous initiatives into concrete deliverables, prioritize effectively, and drive execution independently.
  • A strong ownership mindset and the ability to operate effectively as an individual contributor without requiring constant direction.
  • Bachelor’s degree in Computer Science, Software Engineering, a related technical discipline, or equivalent practical technical experience.
  • Experience mentoring or coaching colleagues in compliance, audit, or GRC is a plus.
  • Previous experience working in a startup environment is advantageous.
  • PECB ISO 27001 Lead Auditor certification or an equivalent qualification is a bonus.
Benefits:
  • 100% remote work with a virtual office environment.
  • Competitive local salary aligned with or above relevant market rates.
  • Generous equity package with an opportunity to share in the organization’s long-term success.
  • Access to experienced mentors and a strong professional network.
  • €1,000 annual personal development budget.
  • Home office budget and access to coworking spaces.
  • 26 days of annual holiday plus local public holidays.
  • Comprehensive health insurance coverage.
  • Annual company retreat focused on collaboration, connection, and new ideas.
  • Company-wide events and opportunities to connect with colleagues across the organization.
  • Modern technology and equipment, including a MacBook, monitors, and headphones.
How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Remote GRC Specialist — ISO 27001 & GDPR Focus
Remote GRC Specialist — ISO 27001 & GDPR Focus

Jobgether • España

A distancia
EUR 60.000 - 90.000
Remote work
Competitive salary
Equity
+5
GRC Security Expert
GRC Security Expert

Leadtech Group • Barcelona

A distancia
EUR 30.000 - 54.000
Private health insurance
Flexible hours
Remote work option
+5
GRC Compliance Specialist
GRC Compliance Specialist

HappyRobot • Madrid

Presencial
EUR 55.000 - 85.000
Healthcare
Dental and vision
Equity
Senior / Lead Recruiter
Senior / Lead Recruiter

Jobgether • España

A distancia
EUR 70.000 - 100.000
Full-time employment
Fully remote work within Europe
Significant influence on recruitment策略
Senior Full-Stack Software Engineer
Senior Full-Stack Software Engineer

Jobgether • España

A distancia
EUR 65.000 - 74.000
Remote in Europe
Flexible schedule
Paid time off
+1
Remote GRC Security & Privacy Lead (ISO 27001/GDPR)
Remote GRC Security & Privacy Lead (ISO 27001/GDPR)

Leadtech Group • Barcelona

A distancia
EUR 30.000 - 54.000
Private health insurance
Flexible hours
Remote work option
+5
Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)
Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)

Montarelo Recruiting • Madrid

Híbrido
EUR 70.000 - 100.000
Governance risk and Compliance Technical Specialist - Hybrid Madrid
Governance risk and Compliance Technical Specialist - Hybrid Madrid

UST • Madrid

Híbrido
EUR 45.000 - 60.000
Annual Leave
Health Care Plan
Free training access
+1
Senior Compliance Analyst
Senior Compliance Analyst

TaxBit • Madrid

Presencial
EUR 70.000 - 95.000
Cybersecurity, Risk and Regulatory Compliance Consultant
Cybersecurity, Risk and Regulatory Compliance Consultant

GMV • Tres Cantos

Híbrido
EUR 60.000 - 90.000
Hybrid work model
Flexible working hours
Wellbeing program
+3