Join Amaris Consulting and manage cybersecurity risks across strategic digital projects (Salesforce, CRM, e‑commerce) for a leading international group in its sector. Be part of an international cybersecurity & GRC team, grow in a hybrid environment in Madrid, and develop your career within a global organization that values ownership, collaboration, and technical excellence.
As a Senior Cybersecurity Project Manager – GRC & Digital Platforms (Salesforce / CRM / e‑commerce), you will ensure that cybersecurity risks are identified, assessed, mitigated and monitored across key projects and platforms in an international environment. You will work closely with technical, security and business teams to coordinate mitigation plans, follow up on action plans and support security governance activities.
You will:
- Manage cybersecurity risks across projects involving Salesforce, CRM and e‑commerce platforms.
- Identify and assess implementation and operational risks throughout the project lifecycle.
- Coordinate mitigation actions with technical, security and business stakeholders.
- Monitor security controls, incidents and action plans, ensuring proper follow‑up and escalation when needed.
- Contribute to GRC activities: risk registers, control frameworks, policies, and compliance follow‑up.
- Support security governance: preparation of committees, reporting, and decision‑making support for management.
What we’re looking for
- 5–8 years of experience managing cybersecurity projects.
- Experience in GRC, cybersecurity risk management or security governance.
- Proven experience identifying, assessing and tracking project and implementation risks.
- Ability to coordinate mitigation plans with IT, security and business teams.
- Knowledge of CRM, e‑commerce or other business‑critical applications.
- Strong communication, organization and stakeholder management skills.
- Salesforce experience is a strong plus.
- High level of English for daily collaboration with international teams.
- A proactive, structured and autonomous mindset, able to drive risk remediation and follow‑up without constant supervision.
What you will do (day‑to‑day)
- Work with project managers and product owners to integrate cybersecurity requirements into project plans.
- Lead risk assessments for Salesforce, CRM and e‑commerce projects (design, implementation, run).
- Define and follow risk treatment plans: mitigation measures, responsible owners, deadlines and status.
- Coordinate with security architects, engineers and business stakeholders to ensure controls are implemented.
- Track and report on security incidents, non‑compliances and action plans related to your perimeter.
- Prepare and present risk dashboards and KPIs to steering committees and management.
- Contribute to policies, standards and procedures related to project security and application security governance.
- Support awareness and communication on cybersecurity risks to project and business teams.
- Strong analytical and problem‑solving skills, applied to cybersecurity risks and prioritization.
- Excellent stakeholder management: able to influence without direct authority and align diverse teams.
- Confident in leading meetings, challenging decisions when needed, and defending security priorities.
- Comfortable working in international and multicultural environments, adapting your communication to different audiences (technical, business, management).
- Proactive, structured and autonomous, with a strong sense of ownership and accountability.
- Hands‑on experience with Salesforce security or other major CRM / e‑commerce platforms.
- Experience with risk management frameworks or security standards (ISO 27001, NIST, etc.).
- Security or GRC certifications (e.g. CISM, CISSP, ISO 27005, ISO 27001 Lead Implementer/Auditor) are a plus.
- Experience in multinational or multi‑country environments.
- Join a fast‑growing global consulting group with strong cybersecurity and GRC practices.
- Work in a hybrid model in Madrid within an international environment (projects and teams across Europe and beyond).
- Develop your skills in cybersecurity risk management, GRC, Salesforce/CRM/e‑commerce security and security governance.
- Grow your career within Amaris Consulting and the Mantu Group, with access to international opportunities and continuous learning.
At Amaris Consulting, we are committed to creating an inclusive environment. We welcome all qualified applications regardless of gender, sexual orientation, race, ethnicity, age, or any other characteristic.
Who are we?
Job description
Join Amaris Consulting and manage cybersecurity risks across strategic digital projects (Salesforce, CRM, e‑commerce) for a leading international group in its sector. Be part of an international cybersecurity & GRC team, grow in a hybrid environment in Madrid, and develop your career within a global organization that values ownership, collaboration, and technical excellence.
As a Senior Cybersecurity Project Manager – GRC & Digital Platforms (Salesforce / CRM / e‑commerce), you will ensure that cybersecurity risks are identified, assessed, mitigated and monitored across key projects and platforms in an international environment. You will work closely with technical, security and business teams to coordinate mitigation plans, follow up on action plans and support security governance activities.
Your mission & impact
As a Senior Cybersecurity Project Manager – GRC & Digital Platforms (Salesforce / CRM / e‑commerce), you will ensure that cybersecurity risks are identified, assessed, mitigated and monitored across key projects and platforms in an international environment. You will work closely with technical, security and business teams to coordinate mitigation plans, follow up on action plans and support security governance activities.
Mission description
You will:
- Manage cybersecurity risks across projects involving Salesforce, CRM and e‑commerce platforms.
- Identify and assess implementation and operational risks throughout the project lifecycle.
- Coordinate mitigation actions with technical, security and business stakeholders.
- Monitor security controls, incidents and action plans, ensuring proper follow‑up and escalation when needed.
- Contribute to GRC activities: risk registers, control frameworks, policies, and compliance follow‑up.
- Support security governance: preparation of committees, reporting, and decision‑making support for management.
What we’re looking for
- 5–8 years of experience managing cybersecurity projects.
- Experience in GRC, cybersecurity risk management or security governance.
- Proven experience identifying, assessing and tracking project and implementation risks.
- Ability to coordinate mitigation plans with IT, security and business teams.
- Knowledge of CRM, e‑commerce or other business‑critical applications.
- Strong communication, organization and stakeholder management skills.
- Salesforce experience is a strong plus.
- High level of English for daily collaboration with international teams.
- A proactive, structured and autonomous mindset, able to drive risk remediation and follow‑up without constant supervision.
What you will do (day‑to‑day)
- Work with project managers and product owners to integrate cybersecurity requirements into project plans.
- Lead risk assessments for Salesforce, CRM and e‑commerce projects (design, implementation, run).
- Define and follow risk treatment plans: mitigation measures, responsible owners, deadlines and status.
- Coordinate with security architects, engineers and business stakeholders to ensure controls are implemented.
- Track and report on security incidents, non‑compliances and action plans related to your perimeter.
- Prepare and present risk dashboards and KPIs to steering committees and management.
- Contribute to policies, standards and procedures related to project security and application security governance.
- Support awareness and communication on cybersecurity risks to project and business teams.
Nice to have
- Hands‑on experience with Salesforce security or other major CRM / e‑commerce platforms.
- Experience with risk management frameworks or security standards (ISO 27001, NIST, etc.).
- Security or GRC certifications (e.g. CISM, CISSP, ISO 27005, ISO 27001 Lead Implementer/Auditor) are a plus.
- Experience in multinational or multi‑country environments.
Why join us?
- Join a fast‑growing global consulting group with strong cybersecurity and GRC practices.
- Work in a hybrid model in Madrid within an international environment (projects and teams across Europe and beyond).
- Develop your skills in cybersecurity risk management, GRC, Salesforce/CRM/e‑commerce security and security governance.
- Grow your career within Amaris Consulting and the Mantu Group, with access to international opportunities and continuous learning.
At Amaris Consulting, we are committed to creating an inclusive environment. We welcome all qualified applications regardless of gender, sexual orientation, race, ethnicity, age, or any other characteristic.
Who are we?
Amaris Consulting isan independent technologyconsulting firm providing guidance and solutions to businesses. With more than 1000 clients across the globe, we have been rolling out solutions in major projects for over a decade – this is made possible by an international team of7,600 people spread across 5 continents and more than 60countries. Our solutions focus on four different Business Lines: Information System & Digital, Telecom, Life Sciences and Engineering. We’re focused on building and nurturing a top talent community where all our team members can achieve their full potential. Amaris is your steppingstone to cross rivers of change, meet challenges and achieve all your projects with success.