Information Security Analyst, GRC & ISMS

GMV

España

On-site

PHP 600,000 - 800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working model
Flexible working hours
Competitive compensation
Wellbeing program with health insurance

Job summary

GMV is expanding its Corporate Cybersecurity Compliance team and seeking an Information Security Analyst to enhance its information protection and compliance frameworks. Your responsibilities will include evolving the ISMS, conducting audits, and managing risks associated with security regulations.

The ideal candidate will have experience in GRC and ISMS, along with certifications like CISM or CISSP. This position offers a hybrid working model and competitive compensation.

Qualifications

  • Experience in Governance, Risk & Compliance (GRC) and Information Security Management Systems (ISMS).
  • High level of English proficiency.
  • Knowledge of ISO/IEC 27001, ENS, NIS2.

Responsibilities

  • Maintain and evolve corporate Information Security Management System (ISMS).
  • Contribute to the processes for information protection and regulatory compliance.
  • Conduct audits related to applicable regulations and standards.

Skills

Governance, Risk & Compliance (GRC)
Information Security Management Systems (ISMS)
Risk assessment methodologies
Security regulations and standards

Education

Certifications such as CISM, CRISC, CISSP, CISA

Job description

Information Security Analyst, GRC & ISMS

We are expanding our Corporate Cybersecurity Compliance team to help manage risks, ensure regulatory compliance, and strengthen our security framework.

What challenge will you be taking on?

In collaboration with the team, you will be responsible for maintaining and evolving the corporate Information Security Management System (ISMS). You will also contribute to all the processes required to ensure and enhance information protection, resilience, and compliance with established requirements.

  • Activities related to regulations, standards, and frameworks applicable in the countries where GMV operates (ISO/IEC 27001, ENS, NIS2, etc.), including both internal and external audits.
  • Defining and monitoring metrics, indicators (KPIs/KRIs), and management dashboards.
  • Analyzing, assessing, and managing internal and third‑party risks, while promoting initiatives to prevent and mitigate them.
  • Developing and reviewing security and compliance policies, methodologies, and documentation.
    Supporting the preparation of security committees, management reviews, and ISMS governance activities.
What do we need in our team?

For this position, we are looking for a Compliance Cybersecurity Engineer with experience in Governance, Risk & Compliance (GRC), Information Security Management Systems (ISMS), audit processes, information security controls and risk treatment plans. You should also have knowledge of:

  • Security regulations and standards such as ISO/IEC 27001, ENS, NIS2, etc.
  • Risk assessment and risk management methodologies.
  • Security requirements for suppliers and third parties.

Additionally, the following will be considered a plus:

  • Certifications such as CISM, CRISC, CISSP, CISA, ISO/IEC 27001 Lead Auditor, or similar.
  • Knowledge of operational resilience and business continuity frameworks.
  • Experience working in regulated environments or critical infrastructure sectors.

A high level of English proficiency is required.

What do we offer?
  • Hybrid working model and 4 weeks per year of teleworking outside your usual geographical area.
  • Flexible start and finish times, and intensive working hours on Fridays and in summer.
  • Personalized career plan development, training and language learning support.
  • National and international mobility. If you come from another country, we can offer you a relocation package.
  • Competitive compensation with ongoing reviews, flexible compensation and discount on brands.
  • Wellbeing program: Health, dental and accident insurance; free fruit and coffee; physical, mental and financial health training, and much more!

In our recruitment processes you will always have telephone and personal contact, face‑to‑face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through any other process, please write to our team at privacy@gmv.com.

We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.

What are you waiting for? Join us

If you have any questions please do not hesitate to contact Pablo Durán Álvarez, in charge of this vacancy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid GRC & ISMS Information Security Analyst
Hybrid GRC & ISMS Information Security Analyst

GMV • España

Hybrid
PHP 600,000 - 800,000
Hybrid working model
Flexible working hours
Competitive compensation
+1
Cyber Governance, Risk and Compliance Specialist
Cyber Governance, Risk and Compliance Specialist

Virtual Business Partners Pty. Ltd. • Cebu City

On-site
PHP 800,000 - 1,200,000
HMO + Dental/Optical
Christmas vacation
Electricity & Data subsidies
+3
Specialist - Governance Risk and Compliance
Specialist - Governance Risk and Compliance

Concentrix • Morong

On-site
PHP 600,000 - 1,000,000
Senior Governance Risk and Compliance Analyst
Senior Governance Risk and Compliance Analyst

Permhunt • Metro Manila

On-site
Competitive salary
Benefit package
On-call support
Associate Specialist, GRC
Associate Specialist, GRC

Concentrix • Morong

On-site
PHP 500,000 - 1,200,000
GDS Consulting_Cyber Risk, Compliance & Resilience- Senior
GDS Consulting_Cyber Risk, Compliance & Resilience- Senior

Hammerjack Pty Ltd • Taguig

On-site
PHP 1,200,000 - 1,800,000
Coaching and feedback
Career development opportunities
Flexible work approach
Senior GRC Engineer
Senior GRC Engineer

Workstreet • Philippines

Remote
PHP 60,000 - 90,000
Career Development
Technical Training
Competitive Compensation
+2
Associate Specialist, Governance, Risk and Compliance
Associate Specialist, Governance, Risk and Compliance

Concentrix Philippines • Pampanga

On-site
PHP 900,000 - 1,500,000
IT Consultant Cybersecurity Governance ISMS
IT Consultant Cybersecurity Governance ISMS

Continental Industry • Philippines

On-site
PHP 1,200,000 - 1,800,000
Governance and Information Security Analyst
Governance and Information Security Analyst

InnovaThink Corporation • Metro Manila

On-site
PHP 800,000 - 1,200,000