Information Security Governance Specialist

ALS

Madrid

Presencial

EUR 65.000 - 95.000

Jornada completa

Hace 11 días

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

ALS is seeking an Information Security Governance Specialist to own the governance backbone of the security programme, translating strategy into auditable policies, control frameworks and audit programmes across the business.

You will develop, review, and map controls to ISO 27001, NIST CSF, GDPR, and other standards; manage the exception/waiver process; coordinate audits; and produce executive dashboards for boards and senior management.

Responsabilidades

  • Develop, maintain, and periodically review information security policies, standards, and procedures aligned to ISO 27001 and other recognised cybersecurity frameworks.
  • Maintain the security governance calendar (policy reviews, management reviews).
  • Support design and evolution of the organisation's security strategy and multi-year security programme roadmap.
  • Administer the security exception/waiver process end-to-end: intake, documentation, approval routing, and tracking of time-bound remediation commitments through to closure.
  • Maintain the control framework catalogue, mapping controls to ISO 27001 Annex A, NIST CSF, and CIS Controls, and flag control gaps for risk assessment by the Information Security Risk Specialist.
  • Partner with the Information Security Risk Specialist to ensure exceptions and control gaps are risk-assessed and formally risk-accepted by the appropriate owner before a waiver is granted.
  • Coordinate internal and external audits and certification cycles (e.g. ISO 27001), including evidence collection and remediation tracking.
  • Map controls to regulatory and contractual obligations (GDPR, PCI-DSS, HIPAA, sector-specific requirements as applicable).
  • Maintain a defensible audit trail for control operation and governance decisions.
  • Produce executive-ready reporting: governance and compliance dashboards, programme status updates, board and committee papers.
  • Act as a trusted point of contact for business units seeking governance guidance on new initiatives.
  • Contribute governance input to post-incident reviews and remediation programmes, ensuring lessons learned convert into control or policy change.
  • Support the broader team on cross-functional initiatives (e.g. data protection projects, security awareness) as priorities require.

Descripción del empleo

At ALS, we encourage you to dream big. When you join us, you’ll be part of a global team harnessing the power of scientific testing and data-driven insights to build a healthier future. The Information Security Governance Specialist owns the governance backbone of the security programme: policy, control framework design, compliance, and audit assurance. This role translates security strategy into structured, auditable, and operationally realistic governance artefacts (e.g.: exception registers, policy suites, control frameworks, audit programmes) and works across the business to embed them into everyday operation.

Key responsibilities
  • Develop, maintain, and periodically review information security policies, standards, and procedures aligned to ISO 27001 and other recognised cybersecurity frameworks.
  • Maintain the security governance calendar (policy reviews, management reviews).
  • Support design and evolution of the organisation's security strategy and multi-year security programme roadmap.
  • Administer the security exception/waiver process end-to-end: intake, documentation, approval routing, and tracking of time-bound remediation commitments through to closure.
  • Maintain the control framework catalogue, mapping controls to ISO 27001 Annex A, NIST CSF, and CIS Controls, and flag control gaps for risk assessment by the Information Security Risk Specialist.
  • Partner with the Information Security Risk Specialist to ensure exceptions and control gaps are risk-assessed and formally risk-accepted by the appropriate owner before a waiver is granted.
  • Coordinate internal and external audits and certification cycles (e.g. ISO 27001), including evidence collection and remediation tracking.
  • Map controls to regulatory and contractual obligations (GDPR, PCI-DSS, HIPAA, sector-specific requirements as applicable).
  • Maintain a defensible audit trail for control operation and governance decisions.
  • Produce executive-ready reporting: governance and compliance dashboards, programme status updates, board and committee papers.
  • Act as a trusted point of contact for business units seeking governance guidance on new initiatives.
  • Contribute governance input to post-incident reviews and remediation programmes, ensuring lessons learned convert into control or policy change.
  • Support the broader team on cross-functional initiatives (e.g. data protection projects, security awareness) as priorities require.
Working at ALS

The ALS team is a diverse and dedicated community united by our passion to make a difference in the world.

Our values are important to us, and shape how we work, how we treat each other and how we recognise excellence.

At ALS, you’ll be supported to develop new skills and reach your full potential. We invest in our people with programs and opportunities that help you build a diverse career with us.

We want everyone to have a safe, flexible and rewarding career that makes a positive impact on our people, the planet and our communities.

Everyone Matters

ALS is proud to be an equal opportunity employer and is committed to fostering an inclusive work environment where the strengths and perspectives of each employee are both recognised and valued.

ALS also welcomes applications from people with all levels of ability. Reasonable adjustments to support candidates throughout the recruitment process are available upon request.

Eligibility

To be eligible to work at ALS you must be a Citizen or Permanent Resident of the country you are applying for, or either hold or be able to obtain, a valid working visa.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Protection Specialist
Information Protection Specialist

ALS • Madrid

Presencial
EUR 60.000 - 90.000
Security Governance Architect: Policy & Compliance
Security Governance Architect: Policy & Compliance

ALS • Madrid

Presencial
EUR 65.000 - 95.000
Communications Advisor
Communications Advisor

ALS Limited • Madrid

Presencial
EUR 60.000 - 90.000
Global Commercial Manager Environmental
Global Commercial Manager Environmental

ALS Global • Madrid

Híbrido
EUR 90.000 - 150.000
Information Security Governance Product Owner (m/f/d)
Information Security Governance Product Owner (m/f/d)

Liebherr Group • Madrid

Híbrido
EUR 60.000 - 80.000
Flexible and hybrid working model
Creative freedom in processes and solutions
Continuous learning and development
+3
Global Cybersecurity Leader — Risk & Compliance
Global Cybersecurity Leader — Risk & Compliance

Jobtailor • Madrid

Híbrido
EUR 90.000 - 140.000
Information Security Program Manager_1570
Information Security Program Manager_1570

Allianz Technology • Barcelona

Híbrido
EUR 55.000 - 80.000
Hybrid work model
Company bonus scheme
Pension
+2
Senior Security Analyst
Senior Security Analyst

Camlin Group • Málaga

Presencial
EUR 60.000 - 90.000
Senior Data Governance Analyst
Senior Data Governance Analyst

SGS • España

Presencial
USD 52.000 - 94.000
Flexible schedule
Continuous learning opportunities
Comprehensive benefits platform
+1
Information Security Risk Management Lead (m/f/d)
Information Security Risk Management Lead (m/f/d)

Allianz Services • Barcelona

Híbrido
EUR 70.000 - 110.000
Hybrid work model
Bonus scheme
Pension
+3